Quantcast
Channel: Windows Server General Forum forum
Viewing all 24879 articles
Browse latest View live

Server 2012R2 and the dreaded "Please Wait for the System Event Notification Service ......" issue

$
0
0

Dear Microsoft,

This question has been asked countless times over the last nearly 5 years, but it STILL has never been answered as to why or how to fix it.  See this thread, amongst many others.  I chose it because it has the most useful information, and sometimes SOME of the suggestion in it DO actually work.  I opened a new thread because that one is so very long and has become hard to follow.  I'd like to apologize to everyone for the tone of this post, but the level of frustration (not to mention lack of sleep! :) is taking a major toll on us over the last 5 days.

https://social.technet.microsoft.com/Forums/windowsserver/en-US/65634267-8550-4b96-b6d1-6e020859aee7/please-wait-for-the-system-event-notification-service?forum=winservergen

Unfortunately in this particular case, none of them has worked.  The irony here is that we put up a temp server to migrate an old SBS2003 server for our client after migration kept failing, per Dell and Microsoft support escalation teams.  Since the failure, the MS technician said he cannot help us, since it is not related to the customer's purchase, but rather to a temporary server.  this would be the server that HE requested we build as a bridge to fix this failed migration, at OUR expense.  So, after 2 months of failed migrations, we bit the bullet and built a 2012R2 server, patched to current, added WSUS (to fix the fact that HE broke it on 2003 and couldn't fix it) and ported all of the data to it, so it's only being used for storage and WSUS.  It ran fine for 2 days.  We did an update that required a reboot, and voila'!  Now THIS server, like SO many others, has this dreaded error.  We've now spent 4 days, countless Google and Bing searches, hundreds of taskills and still here we are.

It has been nearly 5 years a 3 server version since this problem has been reported, and yet not one single thread has any response of any kind from any Microsoft employee that any of us can find anywhere.  Microsoft better darn well be ashamed of this kind of response to a SIGNIFICANT issue, but I really do believe, as do many of my counterparts here and everywhere, that MS has CHOSEN to ignore this issue.  So, we have decided that we will pursue it once and for all until there is both a formal response and a resolution, not just for us.  To that end, my first call was to Microsoft PSS; they absolutely incredulous amount they wanted to charge just to hear our question is far beyond what we can afford; we have spent a lot of man-hours and spent a lot of money already that we will never get back and just cannot afford such an enormous expense.  The Dell representative has tried everything to help us but told us today that the only thing he could do was try to escalate within MS and was declined for escalation.  He has been terrific, and kudos to Dell for allowing him to spend tremendous hours trying to help, both with the initial problem, and now even with this one.

The migration issue has a plan that we know works (we've had to do it before on "messed up" SBS2003 installs) and we are quite comfortable with it.  It just requires an intermediary to hold stuff so the clients can operate while we "fix" it to do the migration properly.  And we do understand that we can rebuild THIS server yet again; the time involved in doing so is far to great each time, especially when WSUS is involved, and it MUST be, unfortunately.

This is far from the first server we've experienced this one, and we've had it in 2008, 2008R2, 2012 and 2012R2 to date.  From the attached post it appears the same experience for nearly everyone.

This server is an older Intel QX6700 on an Intel Desktop board, 8 GB ram, SSD for boot, 2x1.5tb mirror for data all on the Intel SATA bus.  There is absolutely nothing remarkable about this machine; it was intended to house the data for about a week as an intermediary for the migration of their SBS2003 installation, and we have used this same box with many versions of Server (2008, R2, 2012, R2) in the past for testing and for tasks such as this without issue.  There is currently NO antivirus of any kind installed on it; this is on purpose.

Thanks to all who have responded in the past and have helped resolve many of these situations; we've re-installed 3 servers over the years because of it, and at our expense, which we just cannot afford.  But without your help we would have redone many more, and for that we are truly grateful.

So, after all of that ...........All I am asking for is for someone from MS to actually respond to this post and to get this ball rolling.  We just want to get this done for our customer, expeditiously and at a reasonable cost.  And we want to know why this has persisted for FIVE YEARS without any formal help.

Please help us.  Happy Thanksgiving!

Jeff


WS 2016 slow and erratic performance compared to WS 2008

$
0
0
Hi.  I've been struggling to determine, and explain, why WS 2016 is at best 10% slower, and has very erratic performance compared to WS 2008 R2 on the same hardware.  I've come here hoping someone can point me to some avenues of investigation.

The setup:
Dedicated/isolated host server running WS 2016 Hyper-V with 16 cores/32 logical processors and 128 GB RAM.
VM1 = WS 2008 R2 allocated 8 logical processors and 16 GB RAM.  OS VHD uses IDE Controller and data VHD uses SCSI.
VM2 = WS 2016 allocated 8 logical processors and 16 GB RAM.  OS and data VHD's both use SCSI Controller.
The host and both VM's are up-to-date as of this posting.  All VHD's are on internal server drives.  Memory for the VM's is fixed, not dynamic.  These are the only two VM's running on this host.  AV disabled in both VM's.

The test case reads a 3.4 GB file from the data VHD into memory, performs a series of calculations on the in-memory content, then terminates (it does not write back the file, the memory contents are simply disposed).  The executable is single-threaded, so only 1 logical processor is busy for this test.  Physical memory consumption never appears to exceed 9 GB.
VM1 (WS2008)) performance for 6 runs of the test, all back-to-back, time in seconds:
Load file = 208.383, 209.964, 210.712, 206.086, 204,27, 209.984
Calculations = 216.432, 217.19, 217.047, 217.252, 216.335, 214.184
Total = 424.815, 427.054, 427.759, 423.338, 420.605, 424.168

VM2 (WS2016) for 6 runs of the same test, all back-to-back:
Load file = 519.741, 535.935, 526.229, 441.768, 400.882, 265.793
Calculations = 499.218, 540.003, 511.422, 449.961, 396.951, 354.703
Total = 1018.959, 1075.938, 1037.651, 891.729, 797.833, 620.496

This test case is a small subset of what we typically see for workloads.  Batch jobs that would reliably complete in 5 hours using the WS 2008 VM take anywhere between 6 and 10 hours on the WS 2016 VM.
I've tried the 7-Zip Benchmark tool test on both VM's, setting the CPU threads to 1, and the WS 2008 R2 VM handily beats the 2016 VM at that too.

I'm at a loss to explain why WS 2016 is so much slower on the same hardware, and erratic.  Any suggestions would be welcome.

Thanks.

Materials for MCSA windows server 2016

$
0
0
Dears,I have the desire to prepare for the MCSA windows server 2016 exam.. What are the best sources and books.

NPS machine certificate and user password

$
0
0

Hello, using a single NPS policy, is it possible to authenticate first the machine via EAP-TLS machine cert and then the user via username / password prompt ?

Thank you

Deleting the old machine certificate on Sub CA does not persist after restarting certsvc

$
0
0

When I delete the old machine certificate in cert:\localmachine\my it comes back after I restart certsvc. Where can I find out where this old certificate might be coming from? I've searched the registry and deleted all values that match the old cert ID. Is there a configuration file somewhere I need to modify?

Thanks

Some windows 10 clients does not download CRL from internal CA?

$
0
0

Hi,

First off all - this is not my expertise so have patience with me please :) Also, if this post should be published in another sub-forum - please advise.

Background:

I have configured a wireless network (EAP-TLS) which requests access via a NPS server. The clients are granted access via a AD security group and a machine certificate, which is published from our internal CA. For the majority of the clients there is no issues, but for some (maybe one in 20 machine) there is an error on the NPS server with event ID 6273.

"Network Policy Server denied access to a user.

.....

Reason: The revocation function was unable to check revocation because the revocation server was offline.

"

What I've looked in to:

From the client i checked the cached CRL with 'certutil -urlcache CRL' - but the http entry I am looking for is missing. I used an ethernet cable to connect to our corporate network and browsed the site from Edge manually - with success. However, when I restarted the machine the entry was still not on the machine.  I'm no PKI expert so perhaps you can enlight me what I am missing?

The https extension is:

http://FQDN/CertEnroll/FakeName%20Root%20CA%202016.crl

CRL publishing paramters is 3 days and 12 hours for delta.

Also, there is no LDAP extention - even though there is one on the published machine certificate:

ldap:///CN=FakeName%20Issuing%20CA%202016,CN=hostname,CN=CDP,CN=Public%20Key%20Services,CN=Services,CN=Configuration,DC=FakeDomain,DC=no?certificateRevocationList?base?objectClass=cRLDistributionPoint.

For http extension:

Checked - 'Include in CRLs. Clients use this to find Delta CRL locations.'

Checked - 'Include in the CDP extension of issued certificates.'

Not checked - 'Include in IDP extension of issued CRLs.'

for ldap extension:

Checked - 'Publish CRLs to this location.'

Checked - 'Include in all CRLs. Specifies where to publish in the Active Directory when publishing manually.'

Checked - 'Include in CRLs. Clients use this to find Delta CRL locations.'

Checked - 'Include in the CDP extension of issued certificates.'

Checked - 'Publish Delta CRLs to this location'.

Not checked - 'Include in IDP extension of issued CRLs.'

Looking forward to you kind guidance,

with regards

ITB

cannot remove old domain controller

$
0
0

Hi,

I have installed a new 2019 domain controller into a 2008 r2 domain which had 1 2008 r2 server. I have moved the fsmo roles to the 2019 server, moved data and applications and also moved dhcp. I have switched the old server off for a week and all has been good. So today I went to remove the old server, I ran dcpromo but was unable to remove the old server due to an issue. i recieved event ids 1864, 2094, 2022 and 2091on the 2008 r2 server. 2091 seems to suggest that an old server still holds the fsmo role, this server no longer exists. This is strange as when a run netdom query fsmo on both servers they all come back with the new 2019 server as the holder. Any help on how to resolve this would be gratefully accepted.

Regards,

J

Log levels

$
0
0

Hello,

I learnt that there are 0-5 levels of logging in Windows Server.

What is the default level and how do I change it.

Thanks

Srinivasan


Importing Users with CSVDE

$
0
0

I have exported one of my test OU where I have one user to a csv file (users_test.csv) using CSVDE. The export went good, and I have changed one thing in the file, I've set the "flags" attribute from "0" to "1".

Then I'm trying to import it back to see if the changes are made into my test user by doing csvde -i -f c:\temp\users_test.csv

I get the following error:

C:\Users\cayyzalbe>csvde -i -f c:\temp\users_test.csv
Connecting to "(null)"
Logging in as current user using SSPI
Importing directory from file "c:\temp\users_test.csv"
Loading entries.
Add error on line 2: Unwilling To Perform
The server side error is "The modification was not permitted for security reason
s."
0 entries modified successfully.
An error has occurred in the program
No log files were written.  In order to generate a log file, please
specify the log file path via the -j option.

 

Server 2019 RDS Farm

$
0
0

Ave,

I operate some 20+ VM's with Server 2019, at the front of them there's a pair of IIS Gateway & Connection Broker servers that manage the remote desktop services collections and the login/traffic. All fairly normal.

I've just added a new server into the collections, and it appeared to deploy just fine. When I login to the gateway via browser, I can see the new VM's RDP link. However, when I download the RDP link, the server address hasn't been populated.

None of the other links have this issue.

Any thoughts on how to quickly debug / fix - I'd like to avoid having to undo/redo the whole collection if possible?

Cheers.

Enable Disabled domain accounts with powershell

$
0
0
I need to enable or disable account on active directory domain controller (Server 2012) through powershell wmi:
1. I tried using command: wmic useraccount where "name='myusername'" set disabled=true
It returns an error:
Updating property(s) of '\\MYDCONTROLLER\ROOT\CIMV2:Win32_UserAccount.Domain="
Mydomain",Name="myusername"'
ERROR:
Description = Generic failure


2. I tried using command:
PS C:\Windows\system32> Get-WmiObject Win32_UserAccount -filter "LocalAccount=False"|?{$_.name -eq "userName"} |%{$_.disabled=$true;$_.passwordChangeable=$true;$passwordrequired=$true;$disabled=$true;$_.put()}
This returns error:

Exception calling "Put" with "0" argument(s): "Generic failure "
At line:1 char:174
+ ... isabled=$false;$_.put()}
+                    ~~~~~~~~
    + CategoryInfo          : NotSpecified: (:) [], MethodInvocationException
    + FullyQualifiedErrorId : DotNetMethodException


I found this command in
https://www.experts-exchange.com/questions/27803796/Enable-Disabled-LOCAL-accounts-with-Powershell.html
Any ideas? I know how to use Get-aduser or other commands, but it needs to be done via wmi.

Event ID: 5011 - A process serving application pool 'name' suffered a fatal communication error - IIS

$
0
0

A website goes down daily around midnight for half an hour where tons of these warnings are recorded in System Log:

A process serving application pool 'NAME' suffered a fatal communication error with the Windows Process Activation Service. The process id was '5860'. The data field contains the error number.

Cannot seem to find out what is causing this?  Any pointers?  Much appreciated!

Thanks!

DNS Replication Problem

$
0
0

Hello

I have 2 Domain Controllers 2003 x64 and 2008 R2 x64. I want to demode 2003 but DNS can't replicate. The interesting is that i do changes on DNS 2008 R2 and they apeared again after a few minutes.. What can i do????

Powershell Script to ping the IIS site for every 5min

$
0
0

Hi,

I am trying to write a power shell script where in it need to ping the IIS site for every 5 min and if ping wont get the response then the App-pool of the IIS site need to be recycled.

Thanks in Advance.

Synchronizing time with external source on 2088 r2

$
0
0
My domain controller isn't synchronized to a valid time source.   In an attempt to follow some instructions I get the following error

C:\>w32tm /config /syncfromflags:manual /manualpeerlist: "0.ntp.pool.org, 1.ntp.pool.org, 2.ntp.pool.org"

The following arguments were unexpected:
 0.ntp.pool.org, 1.ntp.pool.org, 2.ntp.pool.org


C:\>

_Instructions I was following___________
  1. First, locate your PDC
  2.  Server. Open the command prompt and type: C:\>netdom /query fsmo
  3. Log in to your PDC Server and open the command prompt.
  4. Stop the W32Time service: C:\>net stop w32time
  5. Configure the external time sources, type: C:\> w32tm /config /syncfromflags:manual /manualpeerlist: “0.ntp.pool.org, 1.ntp.pool.org, 2.ntp.pool.org”
  6. Make your PDC a reliable time source for the clients. Type: C:\>w32tm /config /reliable:yes
  7. Start the w32time service: C:\>net start w32time
  8. The windows time service should begin synchronizing the time. You can check the external NTP servers in the time configuration by typing: C:\>w32tm /query /configuration
  9. Check the Event Viewer for any errors.

thx


windows server 2016 update

$
0
0

i have 2nos server 2016 version. recently i was update (primary) server-1 windows update successfully, at the same time secondary server we switch off. after server-1 updated then try server-2(secondary) we try update. due to some update not complete switch of cant able to turn on Dell sever. after we called Dell support, the told the hard disk detection card faulty ready,so they replace and now work it well.

But the secondary server-2 still update not yet complete, same as 49% only.our server use for BMS monitor NEVERFAIL ENGINE SUPPORT. So at the mean time anyone server only able to connect to internet. without server-1 switch off ,is it possible to connect server-2 connect with internet and update remaining update?

or all update download from website, use hard disk can install? future avoid this issue, any better solution have. first server-1 update finished the secondary server-2 can copy from server-1?

Windows suddenly says it is not valid - MGADT results posted below

$
0
0
Diagnostic Report (1.9.0027.0):
-----------------------------------------
Windows Validation Data-->

Validation Code: 50
Cached Online Validation Code: N/A, hr = 0xc004f012
Windows Product Key: *****-*****-*****-*****-827MH
Windows Product Key Hash: PKXrpMpZvcE59x/tlHigqRfNcyg=
Windows Product ID: 55041-014-1524432-84903
Windows Product ID Type: 6
Windows License Type: Volume MAK
Windows OS version: 6.1.7601.2.00030012.1.0.010
ID: {A789B632-583D-4E0B-82B5-82C2CCF83278}(1)
Is Admin: Yes
TestCab: 0x0
LegitcheckControl ActiveX: N/A, hr = 0x80070002
Signed By: N/A, hr = 0x80070002
Product Name: Windows Server 2008 R2 Enterprise
Architecture: 0x00000009
Build lab: 7601.win7sp1_ldr_escrow.190916-1700
TTS Error:
Validation Diagnostic:
Resolution Status: N/A

Vista WgaER Data-->
ThreatID(s): N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002

Windows XP Notifications Data-->
Cached Result: N/A, hr = 0x80070002
File Exists: No
Version: N/A, hr = 0x80070002
WgaTray.exe Signed By: N/A, hr = 0x80070002
WgaLogon.dll Signed By: N/A, hr = 0x80070002

OGA Notifications Data-->
Cached Result: N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
OGAExec.exe Signed By: N/A, hr = 0x80070002
OGAAddin.dll Signed By: N/A, hr = 0x80070002

OGA Data-->
Office Status: 109 N/A
OGA Version: N/A, 0x80070002
Signed By: N/A, hr = 0x80070002
Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3

Browser Data-->
Proxy settings: N/A
User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
Default Browser: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
Download signed ActiveX controls: Prompt
Download unsigned ActiveX controls: Disabled
Run ActiveX controls and plug-ins: Allowed
Initialize and script ActiveX controls not marked as safe: Disabled
Allow scripting of Internet Explorer Webbrowser control: Disabled
Active scripting: Allowed
Script ActiveX controls marked as safe for scripting: Allowed

File Scan Data-->
File Mismatch: C:\Windows\system32\wat\watadminsvc.exe[Hr = 0x80070003]
File Mismatch: C:\Windows\system32\wat\npwatweb.dll[Hr = 0x80070003]
File Mismatch: C:\Windows\system32\wat\watux.exe[Hr = 0x80070003]
File Mismatch: C:\Windows\system32\wat\watweb.dll[Hr = 0x80070003]

Other data-->
Office Details: <GenuineResults><MachineData><UGUID>{A789B632-583D-4E0B-82B5-82C2CCF83278}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00030012.1.0.010</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-BBBBB</PKey><PID>55041-014-1524432-84903</PID><PIDType>6</PIDType><SID>S-1-5-21-3131421439-3159242595-1108985637</SID><SYSTEM><Manufacturer>Microsoft Corporation</Manufacturer><Model>Virtual Machine</Model></SYSTEM><BIOS><Manufacturer>American Megatrends Inc.</Manufacturer><Version>090006 </Version><SMBIOSVersion major="2" minor="3"/><Date>20120523000000.000000+000</Date></BIOS><HWID>94ED3D07018400F4</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Eastern Standard Time(GMT-05:00)</TimeZone><iJoin>1</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>VRTUAL</OEMID><OEMTableID>MICROSFT</OEMTableID></OEM><GANotification/></MachineData><Software><Office><Result>109</Result><Products/><Applications/></Office></Software></GenuineResults> 

Spsys.log Content: 0x80070002

Licensing Data-->
Software licensing service version: 6.1.7601.17514

Name: Windows Server(R), ServerEnterprise edition
Description: Windows Operating System - Windows Server(R), VOLUME_MAK_B channel
Activation ID: 6a4bd364-4b60-4856-a727-efb59d94348e
Application ID: 55c92734-d682-4d71-983e-d6ec3f16059f
Extended PID: 55041-00168-014-152443-03-1033-7601.0000-1282012
Installation ID: 005764562053490905349685981913078953942786346084390445
Processor Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88342
Machine Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88343
Use License URL: http://go.microsoft.com/fwlink/?LinkID=88345
Product Key Certificate URL: http://go.microsoft.com/fwlink/?LinkID=88344
Partial Product Key: 827MH
License Status: Notification
Notification Reason: 0xC004F00F.
Remaining Windows rearm count: 3
Trusted time: 11/5/2019 2:53:34 PM

Windows Activation Technologies-->
HrOffline: 0x00000000
HrOnline: N/A
HealthStatus: 0x0000000000000000
Event Time Stamp: N/A
ActiveX: Not Registered - 0x80040154
Admin Service: Not Registered - 0x80040154
HealthStatus Bitmask Output:


HWID Data-->
HWID Hash Current: LAAAAAEAAgABAAEAAQAAAAAAAQABAAEAHKIcUbal5rckZjhKZN6yfWjJpGQ=

OEM Activation 1.0 Data-->
N/A

OEM Activation 2.0 Data-->
BIOS valid for OA 2.0: yes
Windows marker version: 0x0
OEMID and OEMTableID Consistent: yes
BIOS Information:
  ACPI Table Name    OEMID Value    OEMTableID Value
  APIC            VRTUAL        MICROSFT
  FACP            VRTUAL        MICROSFT
  SRAT            VRTUAL        MICROSFT
  WAET            VRTUAL        MICROSFT
  SLIC            VRTUAL        MICROSFT
  OEM0            VRTUAL        MICROSFT
  OEMB            VRTUAL        MICROSFT

How do you remove a DHCP failover in Windows Server 2012 when the DHCP manager and powershell commands fail?

$
0
0

Hello Everyone

We have two domain controllers running Windows Server 2012.

Both of them had DHCP installed and we configured a normal load balancing failover between the two servers for a IPV4 scope. This have been working really good for quite some time now. But after some recent security updates all of a suddan the primary DHCP controller is unable to communicate with the other DHCP server. If it had anything to do with the updates I do not know.

But in the eventviewer of the primary DHCP controller the following two error messages was written.Both of the servers are using an external NTP pool that works well they are at the exact same time.

The server detected that it is out of time synchronization with partner server: dc04 for failover relationship: 169.254.153.80-dc04.  The time is out of sync by: 480 seconds .

The failover state of server: 169.254.153.80 for failover relationship: 169.254.153.80-dc04 changed from: NORMAL to COMMUNICATION_INT.

I tried to remove the failover configuration but the primary DHCP controller won't let me. I tried a few different scenarions.

But if i choose deconfigure Failover this is what happens.

Check status of the failover relationship..............Failed.
The DHCP Server service is not running on the target computer.
Deconfigure failover failed. Error 1722. The DHPC server is not running on the target computer.

I then tried to change the status of the failover server to Partner downto be able to remove it. But the primary DHCP server cannot even change that. It replies with.

The DHCP service is not running on the target computer.

At this point DHCP service was running fine on both servers and both used the same timeservers and the time matched correctly. After this I tried to remove my DHCP scope to create it again but it says I cannot remove it as long as I got a failover configured.

The last thing we tried was removing the DHCP failover from the secondary DHCP server and that worked. However our primary DHCP server still thinks it has a failover setup with the secondary DHCP server. We uninstalled the DHCP server role from the secondary DHCP server and still no luck.

Anyone know how to force a removal of an old failover configuration so we can set up a new one and maybe someone understand the time difference it mentions?

Thanks.

Kind Regards!


WHS11 Launchpad.exe won't run after 1/5/19 windows 10 pro update.

$
0
0

Microsoft stopped support of Windows Home Server 11 but it continued to function until last night.   Took an update to Windows 10 Professional on 1/5/19 and after that update the Launchpad program will not run.    Without Launchpad, connection to the server is limited.

When Launchpad.exe is double clicked in its folder, it will show in Task Manager for a second or two then disappear.

I renamed Launchpad to Launchpd.exe and then it runs and performs as normal.

I believe the offending update is KB4023057, but I am not sure. 

Why did Microsoft specifically block the execution of LAUNCHPAD.EXE?  

Windows Server 2012 DC Password Reset

$
0
0

Dear All,

Can anybody tell me, If i reset the Dc Administrator Password it will Impact on Exchange Server.

Viewing all 24879 articles
Browse latest View live