BDC Secure Channel May Fail If More Than 250 Computer Accounts (154398)
The information in this article applies to:
- Microsoft Windows NT Server 4.0 Terminal Server Edition
- Microsoft Windows NT Server 4.0
This article was previously published under Q154398 SYMPTOMS
The NetLogon service fails to start on a backup domain controller (BDC)
with NetLogon error 3210 or 5721, whereas, in the system event logs of the
primary domain controller (PDC) the NetLogon service logs errors 5722 or
5723.
This problem appears to be random and may occur on several BDCs. If you
remove the BDC computer account and synchronize the BDC with the PDC, the
problem is solved until the NetLogon service is restarted on the PDC.
CAUSE
When NetLogon starts on PDC, it enumerates all computer accounts and for
each BDC builds a structure that is used to establish the secure channel.
NetLogon enumerates a maximum of 250 accounts on each call to the SAM, but
due to a problem in NetLogon, NetLogon is missing one account between each
set of 250. If that account is a workstation account, you do not experience
any problems. However, if that account is a BDC account, you experience the
problem mentioned above.
RESOLUTIONTo resolve this problem, obtain the latest service pack for Windows NT 4.0 or Windows NT Server 4.0, Terminal Server Edition. For additional information, click the following article number to view the article in the
Microsoft Knowledge Base:
152734 How to Obtain the Latest Windows NT 4.0 Service Pack
STATUSMicrosoft has confirmed that this is a problem in Windows NT 4.0 and Windows NT Server 4.0, Terminal Server Edition. This problem was first corrected in Windows NT 4.0 Service Pack 4.0 and Windows NT Server 4.0, Terminal Server Edition Service Pack 4.
Modification Type: | Minor | Last Reviewed: | 9/23/2005 |
---|
Keywords: | kbHotfixServer kbQFE kbbug kbfix KB154398 |
---|
|