Article ID: 942564 - Last Review: September 1, 2009 - Revision: 2.0 The Net Logon service on Windows Server 2008 and on Windows Server 2008 R2 domain controllers does not allow the use of older cryptography algorithms that are compatible with Windows NT 4.0 by defaultImportant This article contains information about how to modify the registry. Make sure that you back up the registry before you modify it. Make sure that you know how to restore the registry if a problem occurs. For more information about how to back up, restore, and modify the registry, click the following article number to view the article in the Microsoft Knowledge Base: 322756
(http://support.microsoft.com/kb/322756/
)
How to back up and restore the registry in Windows On This PageSYMPTOMSNote Windows NT 4.0 is past the Microsoft support life cycle period. Scenarios that are relevant to Windows NT 4.0 have not been tested and are not officially supported. The following information is informational only and is provided to facilitate an easier transition from Windows NT 4.0 systems.
For more information about the Microsoft support life cycle policy, visit the following Microsoft Web site: http://support.microsoft.com/lifecycle
(http://support.microsoft.com/lifecycle)
When a Windows NT 4.0-based computer tries to use the NETLOGON service to establish a security channel to a Windows Server 2008-based domain controller, the operation may fail. Hardware or software may be unable to establish a security channel to a Windows Server 2008-based domain controller if the hardware or the software uses the cryptography algorithms that are used in Windows NT 4.0.In this scenario, you may experience the following symptoms. Symptom 1You cannot log on to a domain from a Windows NT 4.0-based computer that is serviced by a Windows Server 2008-based domain controller. Depending on whether the credentials of the domain logon account are cached on the Windows NT 4.0-based computer, you may receive one of the following error messages:Error message 1 The system cannot log you on now because the domain DomainName is not available. A domain controller for your domain could not be contacted. You have been logged on using cached account information. Changes to your profile since you last logged on may not be available. Symptom 2Trusts that exist between Windows NT 4.0 domains and Windows Server 2008 domains may not work. You may successfully create the initial trust. However, when you try to validate the trust by using the Domain.msc Microsoft Management Console (MMC) snap-in, the validation may fail. Additionally, you receive the following error message:The operation failed with error code 317 (0x0000013d) Symptom 3A SAMBA SMB client cannot perform a domain join operation to a Windows Server 2008-based domain controller. Or, a SAMBA Server Message Block (SMB) client cannot establish a security channel to a Windows Server 2008-based domain controller.Additionally, the Windows Server 2008-based domain controller that processes the security channel request returns the following error code: Hex: 0x4F1h Decimal: 1265 Symbolic Error: ERROR_DOWNGRADE_DETECTED Short Error: "STATUS_DOWNGRADE_DETECTED" Friendly Error: The system detected a possible attempt to compromise security. Please ensure that you can contact the server that authenticated you. Symptom 4A SMB storage device may be unable to use weak cryptography algorithms to establish a security channel to a Windows Server 2008-based domain controller.Note SMB storage devices are also known as IP storage devices. On the authenticating domain controller, the following errors are logged in the System log: Error 1 Log Name: System Source: NETLOGON Date: Date: Time Event ID: 5805 Task Category: None Level: Error User: N/A Computer: AuDomainName Description: The session setup from the computer <client computer> failed to authenticate. The following error occurred: Access is denied. Error 2 Log Name: System Source: NETLOGON Date: Date: Time Event ID: 5722 Task Category: None Level: Error Keywords: Classic User: N/A Computer: AuDomainName Description: The session setup from the computer ClientComputerName failed to authenticate. The name(s) of the account(s) referenced in the security database is ClientComputerName$. The following error occurred: The system detected a possible attempt to compromise security. Please ensure that you can contact the server that authenticated you. Currently, you experience symptom 4 on the following SMB storage device:
Additionally, you may be unable to establish a security channel from Hewlett-Packard (HP) Advanced Server for OpenVMS to a Windows Server 2008-based domain controller. Specifically, the Windows Server 2008-based domain controller returns the following error code to the OpenVMS NetrServerAuthenticate request: Hex: 0x4F1h Decimal: 1265 Symbolic Error: ERROR_DOWNGRADE_DETECTED Short Error: "STATUS_DOWNGRADE_DETECTED" Friendly Error: The system detected a possible attempt to compromise security. Please ensure that you can contact the server that authenticated you. CAUSEThis problem occurs because of the default behavior of the Allow cryptography algorithms compatible with Windows NT 4.0 policy on Windows Server 2008-based domain controllers. This policy is configured to prevent Windows operating systems and third-party clients from using weak cryptography algorithms to establish NETLOGON security channels to Windows Server 2008-based domain controllers. WORKAROUNDTo work around this problem, make sure that client computers use the cryptography algorithms that are compatible with Windows Server 2008. You may have to request software updates from the product vendors. If you cannot install software updates because a service outage will occur, follow these steps:
STATUS
This behavior is by design. MORE INFORMATIONA related problem on computers that are running Windows 2000 or later versions of WindowsThe ability of client computers that are running Windows 2000 or later versions of Windows to establish security channels to Windows Server 2008-based domain controllers will not be affected by the Allow cryptography algorithms compatible with Windows NT 4.0 policy. However, when these client computers use the NetJoinDomain function together with the NETSETUP_JOIN_UNSECURE join option against a Windows Server 2008-based domain controller, the domain controller returns the following error code:Hex: 0x4F1h Decimal: 1265 Symbolic Error: ERROR_DOWNGRADE_DETECTED Short Error: "STATUS_DOWNGRADE_DETECTED" Friendly Error: The system detected a possible attempt to compromise security. Please ensure that you can contact the server that authenticated you. Note The "STATUS_DOWNGRADE_DETECTED" error has multiple root causes. Therefore, this error does not necessarily indicate that you are experiencing this problem. You may experience this problem on computers that are running the following operating systems:
The NetJoinDomain function is used together with the NETSETUP_JOIN_UNSECURE option in the following scenarios. (This function is also used in other scenarios.)
944043
(http://support.microsoft.com/kb/944043/
)
Description of the Windows Server 2008 read-only domain controller compatibility pack for Windows Server 2003 clients and for Windows XP clients and for Windows Vista
How to troubleshoot these problemsWhen you cannot establish a security channel from a client computer to a Windows Server 2008-based domain controller, follow these steps to troubleshoot the problem:
REFERENCES
For more information about how to enable debug logging for the NETLOGON service, click the following article number to view the article in the Microsoft Knowledge Base:
109626
(http://support.microsoft.com/kb/109626/
)
Enabling debug logging for the Net Logon service
For more information about the NetJoinDomain function, visit the following Microsoft Web site: http://msdn2.microsoft.com/En-US/library/aa370433.aspx
(http://msdn2.microsoft.com/En-US/library/aa370433.aspx)
The third-party products that this article discusses are manufactured by companies that are independent of Microsoft. Microsoft makes no warranty, implied or otherwise, about the performance or reliability of these products.APPLIES TO
| Article Translations
|
Back to the top
