Click here to get back home

Local account tries to authenticate to DC when service starts

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Local account tries to authenticate to DC when service starts robpimentel 08-14-2006
Posted by robpimentel on August 14, 2006, 10:09 am
Please log in for more thread options
Hi,

Windows Server 2003 Standard Edition SP1

We continue to receive the following errors on our domain controllers
(Security event log):

Event Type:        Failure Audit
Event Source:        Security
Event Category:        Logon/Logoff
Event ID:        529
Date:                8/6/2006
Time:                9:32:38 AM
User:                NT AUTHORITY\SYSTEM
Computer:        OURDC
Description:
Logon Failure:
Reason: Unknown user name or bad password
User Name: db2admin
Domain: Server A
Logon Type: 3
Logon Process: NtLmSsp
Authentication Package: NTLM
Workstation Name: Server A
Caller User Name: -
Caller Domain: -
Caller Logon ID: -
Caller Process ID: -
Transited Services: -
Source Network Address: Server A's IP
Source Port: 1032

Event Type:        Failure Audit
Event Source:        Security
Event Category:        Account Logon
Event ID:        680
Date:                8/6/2006
Time:                9:32:38 AM
User:                NT AUTHORITY\SYSTEM
Computer:        OURDC
Description:
Logon attempt by:        MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
Logon account:        db2admin
Source Workstation:        Server A
Error Code:        0xC0000064

I think that error code means "the specified user does not exist".

The errors appear on the domain controller anytime a particular service
(Db2 Administration
Server) is restarted. This service is run using a local admin account
(db2admin). My question is this, is it *normal* behavior for services
that are started with local accounts to attempt to authenticate to the
DC first? Is this entirely dependent on the service? Have you seen
similar behavior before?

I'm trying to find out if it's uniquely a db2 issue.

Thanks,
Rob


Posted by Roger Abell [MVP] on August 14, 2006, 10:22 am
Please log in for more thread options
> Hi,
>
> Windows Server 2003 Standard Edition SP1
>
> We continue to receive the following errors on our domain controllers
> (Security event log):
>
> Event Type: Failure Audit
> Event Source: Security
> Event Category: Logon/Logoff
> Event ID: 529
> Date: 8/6/2006
> Time: 9:32:38 AM
> User: NT AUTHORITY\SYSTEM
> Computer: OURDC
> Description:
> Logon Failure:
> Reason: Unknown user name or bad password
> User Name: db2admin
> Domain: Server A
> Logon Type: 3
> Logon Process: NtLmSsp
> Authentication Package: NTLM
> Workstation Name: Server A
> Caller User Name: -
> Caller Domain: -
> Caller Logon ID: -
> Caller Process ID: -
> Transited Services: -
> Source Network Address: Server A's IP
> Source Port: 1032
>
> Event Type: Failure Audit
> Event Source: Security
> Event Category: Account Logon
> Event ID: 680
> Date: 8/6/2006
> Time: 9:32:38 AM
> User: NT AUTHORITY\SYSTEM
> Computer: OURDC
> Description:
> Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
> Logon account: db2admin
> Source Workstation: Server A
> Error Code: 0xC0000064
>
> I think that error code means "the specified user does not exist".
>
> The errors appear on the domain controller anytime a particular service
> (Db2 Administration
> Server) is restarted. This service is run using a local admin account
> (db2admin). My question is this, is it *normal* behavior for services
> that are started with local accounts to attempt to authenticate to the
> DC first? Is this entirely dependent on the service? Have you seen
> similar behavior before?
>
> I'm trying to find out if it's uniquely a db2 issue.
>
> Thanks,
> Rob
>

No, that is not normal behavior.
It seems to indicate something misconfigured in the DB2 service or
mismatch with its prereqs, or in its design/implementation.



Similar ThreadsPosted
Local Administrator as service log on account January 11, 2006, 3:51 am
Allowing a local account to log on as batch/service? July 18, 2005, 2:15 am
Re: Remote Access Connection Manager auto-starts (and can't be stopped) July 6, 2006, 4:17 pm
Is local system account member of local Administrators group? June 21, 2005, 11:33 am
Service Account Passwords November 29, 2005, 12:32 am
'NT Authority\Network Service' Account July 26, 2005, 4:03 am
accessing HKCU of network service account December 21, 2005, 4:23 pm
Permissions required for the Cluster service account? July 7, 2006, 6:51 am
Authenticate USB PORT October 18, 2006, 6:49 am
Reading Security Event Logs with Service Account November 15, 2007, 7:36 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap