In Windows Vista, you receive the following error message
when you try to use Remote Desktop Connection to connect to another Windows
Vista-based computer. Or, on a computer that is running Windows Server 2008 or Windows Vista with Service Pack 1 together with Hyper-V RSAT tools, you may receive the following error when you use VMConnect or Remote Desktop Connection to connect to a Hyper-V guest computer:
No authority could be contacted for
authentication. For assistance, contact your system administrator or technical
support.
And you receive the following error message when you use the System Center Virtual Machine Manager Admin Console to connect to a Hyper-V virtual machine:
An authentication error has occurred (Code: 0x80090303).
These problems occur if the following conditions are true:
- You try to connect by using a fully qualified domain name
(FQDN) or a NetBIOS name.
- Both computers are in a Windows Server 2003-based
domain.
- You have performed an authoritative restoration on the
Users container in the Active Directory directory service.
If Windows Server 2008 domain controllers exist in the domain,
Active Directory replication and Group Policy refresh may fail. Additionally,
you may receive the following event log messages:
Log
Name: System
Source: LsaSrv
Date:
Date
Event ID: 40961
Task Category: (3)
Level: Warning
User: N/A
Computer:
ComputerName
Description: The Security System
could not establish a secured connection with the server
ServerName. No authentication protocol was
available.
Log Name: System
Source:
Microsoft-Windows-GroupPolicy
Date: Date
Event ID: 1006
Task Category: None
Level: Error
User: SYSTEM
Computer: ComputerName
Description: The
processing of Group Policy failed. Windows could not authenticate to the Active
Directory service on a domain controller. (LDAP Bind function call failed).
Log Name: System
Source:
Microsoft-Windows-GroupPolicy
Date:
Date
Event ID: 1055
Task Category: None
Level: Error
User: SYSTEM
Computer:
ComputerName
Description: The processing of
Group Policy failed. Windows could not resolve the computer name.
Log Name: Directory Service
Source:
Microsoft-Windows-ActiveDirectory_DomainService
Date:
Date
Event ID: 1925
Task Category:
Knowledge Consistency Checker
Level: Warning
User: ANONYMOUS LOGON
Computer: ComputerName
Description:
The attempt to establish a replication link for the following writable
directory partition failed.
Directory partition:
CN=Schema,CN=Configuration,DC=Namespace,DC=Namespace
Source
directory service:
CN=NTDS
Settings,CN=DomainController,CN=Servers,CN=SiteName,CN=Sites,CN=Configuration,DC=Namespace,DC=Namespace
Source directory service address:
Address
This directory service will be
unable to replicate with the source directory service until this problem is
corrected.
Error value:
1396 Logon Failure: The target account name
is incorrect.
Log Name: Directory Service
Source: Microsoft-Windows-ActiveDirectory_DomainService
Date:
Date
Event ID: 1645
Task Category: DS RPC
Client
Level: Error
User: ANONYMOUS LOGON
Computer:
ComputerName
Description: Active Directory
Domain Services did not perform an authenticated remote procedure call (RPC) to
another directory server because the desired service principal name (SPN) for
the destination directory server is not registered on the Key Distribution
Center (KDC) domain controller that resolves the SPN.
WMI: Namespaces from a remote computer cannot be listed. You may encounter this situation when you use wmimgmt.msc to "connect to remote computer" and you select
Properties and then
Security. "Root" will not expand to show available namespaces.
When you use Hyper-V Remote Management, the Hyper-V management console stops responding when you try to create a fixed-size virtual hard drive (VHD) on a remote Hyper-V server.
Note These problems do not occur if one of the following conditions is
true:
- You connect by using the IP address of the remote computer
and by using a local user account on the remote computer.
- You connect from a Windows XP-based computer to a Windows
Vista-based computer.
- You connect from a Windows Vista-based computer to a
Windows XP-based computer.
These problems occur because the version number of the KRBTGT
account increases when you perform an authoritative restoration. The KRBTGT
account is a service account that is used by the Kerberos Key Distribution
Center (KDC) service.
To resolve this problem, apply this hotfix to all the
Windows Server 2003-based domain controllers in the domain. This hotfix
prevents the problem before you perform an authoritative restoration. This
hotfix also fixes the problem when you have already performed an authoritative
restoration.
Hotfix information
A
supported hotfix is available from Microsoft. However, this hotfix is intended
to correct only the problem that is described in this article. Apply this
hotfix only to systems that are experiencing the problem described in this
article. This hotfix might receive additional testing. Therefore, if you are
not severely affected by this problem, we recommend that you wait for the next
software update that contains this hotfix.
If the hotfix is available
for download, there is a "Hotfix download available" section at the top of this
Knowledge Base article. If this section does not appear, contact Microsoft
Customer Service and Support to obtain the hotfix.
Note If additional issues occur or if any troubleshooting is required,
you might have to create a separate service request. The usual support costs
will apply to additional support questions and issues that do not qualify for
this specific hotfix. For a complete list of Microsoft Customer Service and
Support telephone numbers or to create a separate service request, visit the
following Microsoft Web site:
Note The "Hotfix download available" form displays the languages for
which the hotfix is available. If you do not see your language, it is because a
hotfix is not available for that language.
Prerequisites
To apply this hotfix, you must have Windows Server 2003 Service
Pack 2 installed.
For more information, click the
following article number to view the article in the Microsoft Knowledge Base:
889100
(http://support.microsoft.com/kb/889100/
)
How to obtain the latest service pack for Windows Server 2003
Restart requirement
You must restart the computer after you apply this hotfix.
Hotfix replacement information
This hotfix does not replace any other hotfixes.
File information
The English version of this hotfix has the file
attributes (or later file attributes) that are listed in the following table.
The dates and times for these files are listed in Coordinated Universal Time
(UTC). When you view the file information, it is converted to local time. To
find the difference between UTC and local time, use the
Time
Zone tab in the
Date and Time item in Control
Panel.
Windows Server 2003 with Service Pack 2, x86-based versions
Collapse this tableExpand this table
| File name | File version | File size | Date | Time | Platform |
|---|
| Samsrv.dll | 5.2.3790.4250 | 454,656 | 11-Mar-2008 | 06:55 | x86 |
Windows Server 2003 with Service Pack 2, x64-based versions
Collapse this tableExpand this table
| File name | File version | File size | Date | Time | Platform |
|---|
| Samsrv.dll | 5.2.3790.4250 | 1,059,328 | 11-Mar-2008 | 09:39 | x64 |
Windows Server 2003 with Service Pack 2, Itanium-based versions
Collapse this tableExpand this table
| File name | File version | File size | Date | Time | Platform |
|---|
| Samsrv.dll | 5.2.3790.4250 | 1,140,224 | 11-Mar-2008 | 09:37 | IA-64 |
To work around this problem, disable the new Remote Desktop
Protocol (RDP) authentication functionality that Windows Vista provides. To do
this, follow these steps:
- Click Start, type
mstsc.exe in the Start Search box, and
then press ENTER.
- Click Options.
- On the General tab, click Save
As.
- In the Save As dialog box, specify a
location and a name for the file, and then click OK.
Note The saved file will have the .rdp file name extension. - Click Start, type
notepad in the Start Search box, and
then press ENTER.
- In Notepad, open the file that you saved in step
4.
- Locate the line that resembles the following:Note The x placeholder represents the
current authentication level.
- Change the authentication level to 0
so that the line becomes the following:Note When you set the authentication level to 0, RDP 6.0 does not
check for server authentication.
- Add the following line to the end of the file:Note When this line is present, users do not have to enter credentials
before they establish a remote desktop connection.
- Save the file.
- To connect by using Remote Desktop Connection, run the file
that you saved in step 10.
Note After you follow these steps, RDP 6.0 becomes incompatible with
Windows Vista-based computers that have the
Allow connections only from computers running Remote Desktop with Network Level Authentication option enabled in the system properties.
Microsoft
has confirmed that this is a problem in the Microsoft products that are listed
in the "Applies to" section.
The
hotfix package
also resolves the following issues :
- Hyper-V VM connection issue as described in KB961723.
For more information, click the following
article number to view the article in the Microsoft Knowledge Base:
961723
(http://support.microsoft.com/kb/961723/
)
Connection to a Virtual Machine running in Hyper-V fails
- Hyper-V Remote Management: Hyper-V Manager UI hangs when it
tries to create a fixed-size VHD on a remote Hype-V Server.
- The Root folder in the Security tab cannot be expanded to show available namespaces after you use
the Wmimgmt.msc tool to connect to a remote computer.
- Offer Remote Assistance fails between Windows 7 computers, and you receive the following error in System Log:
DCOM got error "%2147746132" from the computer COMPUTERNAME when attempting to activate the server: {833E4010-AFF7-4AC3-AAC2-9F24C1457BCE}
For more information about
software update terminology, click the following article number to view the
article in the Microsoft Knowledge Base:
824684
(http://support.microsoft.com/kb/824684/
)
Description of the standard terminology that is used to describe Microsoft software updates
Article ID: 939820 - Last Review: June 5, 2012 - Revision: 9.0
APPLIES TO
- Microsoft Windows Server 2003, Standard Edition (32-bit x86)
- Microsoft Windows Server 2003, Enterprise Edition (32-bit x86)
- Microsoft Windows Server 2003, Datacenter Edition (32-bit x86)
- Microsoft Windows Server 2003, Standard x64 Edition
- Microsoft Windows Server 2003, Enterprise x64 Edition
- Microsoft Windows Server 2003, Datacenter x64 Edition
- Microsoft Windows Server 2003, Enterprise Edition for Itanium-based Systems
- Microsoft Windows Server 2003, Datacenter Edition for Itanium-Based Systems
| kbautohotfix kbexpertiseinter kbwinserv2003postsp2fix kbbug kbfix kbhotfixserver kbqfe KB939820 |