event ID 40961

G

GADavies

I have a web server that has started to lock up and has to be rebooted every morning. Looking in the event logs I see a number of warnings and errors, these repeat throughout the day but the lockup always seems to happen just after one of these string of warnings and errors.

I am not the usual administrator for this server, the usual guy is not available for the entire month of July so I am struggling a little to get to grips with this.

The events I see are as follows:

Warning: Source - LSA (Lsasrv): Event ID 40961: General - The Security System could not establish a secured connection with the server LDAP/readonlyDC.domain.com/domain.com@DOMAIN.COM. No authentication protocol was available.

The warning is duplicated, time is exactly the same as the first instance. Next there is:

Error: Source GroupPolicy (Microsoft Windows Group Policy): Event ID 1030: General - The processing of Group Policy failed. Windows attempted to retrieve new Group Policy settings for this user or computer. Look in the details tab for error code and description. Windows will automatically retry this operation at the next refresh cycle. Computers joined to the domain must have proper name resolution and network connectivity to a domain controller for discovery of new Group Policy objects and settings. An event will be logged when Group Policy is successful.

Details show this:

+ System

-Provider
[ Name] Microsoft-Windows-GroupPolicy
[ Guid] {AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9}

EventID1030

Version0

Level2

Task0

Opcode1

Keywords0x8000000000000000

-TimeCreated
[ SystemTime] 2019-07-02T11:32:28.036748900Z

EventRecordID823208

-Correlation
[ ActivityID] {39409819-8736-4E7F-BB39-7F968A9E7623}

-Execution
[ ProcessID] 736
[ ThreadID] 1156

ChannelSystem

Computervpw1202web04.bellevue.edu

-Security
[ UserID] S-1-5-18
- EventData
SupportInfo11
SupportInfo22950
ProcessingMode0
ProcessingTimeInMilliseconds937
ErrorCode1326
ErrorDescriptionThe user name or password is incorrect.
DCName
\\ReadonlyDC.domain.com




So my question is what could be causing this and where do I look for the issue? The server was working fine until last week, no changes were made at the hardware or OS level so I am confused by the sudden issues

Continue reading...
 
Back
Top Bottom