Results 1 to 4 of 4

Thread: Event ID : 40960 LSAsrv / SPNego

  1. #1
    Join Date
    Oct 2005
    Posts
    12

    Event ID : 40960 LSAsrv / SPNego

    I’m running Windows 2003 Server DC with Service Pack 1. Recently I created an AD domain in the forest, but whenever I restart the DC I use to get an error message in the root DC of this Forest which as follows:

    Event ID : 40960 LSAsrv / SPNego
    The Security System detected an authentication error for the server ldap/mrkdc1.test.com. The failure code from authentication protocol Kerberos was "There are currently no logon servers available to service the logon request.
    (0xc000005e)".

    Event ID : 40960 LSAsrv / SPNego
    The Security System detected an authentication error for the server LDAP/MRKDC1. The failure code from authentication protocol Kerberos was "There are currently no logon servers available to service the logon request.
    (0xc000005e)".

    Event ID : 1059 DHCPserver
    The DHCP service failed to see a directory server for authorization.

    Can anyone please help me out?

  2. #2
    Join Date
    Oct 2005
    Posts
    12

    Re: Event ID : 40960 LSAsrv / SPNego

    Anyways, seems like I fixed the problem myself. While troubleshooting I just demoted the child DC and everything got fixed. Now there is no more errors.

    But I would like to know what was causing the error? Any idea?

  3. #3
    Join Date
    Sep 2004
    Posts
    129

    Re: Event ID : 40960 LSAsrv / SPNego

    Most probably there would be any service running in the background which would be trying to authenticate before the DC starts properly. Anyways, Microsoft has knowledge base articles describing the same. You can check out here:

    Event IDs 40960 and 40961 in the System Event Log When You Restart Windows Server 2003 After You Run Dcpromo.exe http://support.microsoft.com/kb/823712/en-us

    LSASRV Event IDs 40960 and 40961 When You Promote a Server to a Domain Controller Role http://support.microsoft.com/kb/824217/en-us

  4. #4
    Join Date
    Nov 2009
    Posts
    1

    Re: Event ID : 40960 LSAsrv / SPNego

    Have you reviewed in your firewalls the dropped and rejected traffic?
    Surely all rpc dynamic ports are denied from 1024 to 65535.
    I had the same problem and I had to add this rule between dc on both domain of the trust and also between a web server where the trusted accounts have to logon.
    IF you want to use fixed tcp ports to avoid open the whole range, read this KB article:
    http://support.microsoft.com/kb/224196

Similar Threads

  1. Event ID 40960 LSASRV SPNEGO
    By SB in forum Windows Server Help
    Replies: 1
    Last Post: 01-03-2007, 03:01 PM
  2. LsaSrv 40960
    By Drewski in forum Active Directory
    Replies: 3
    Last Post: 25-01-2007, 12:06 AM
  3. Event ID 40960 + 40961 / SPNEGO
    By Spencer in forum Windows XP Support
    Replies: 3
    Last Post: 15-11-2006, 08:47 PM
  4. Event ID: 40960 SPNEGO (Negotiator) authentication error
    By Mauricio Reyes in forum Windows Security
    Replies: 1
    Last Post: 07-04-2006, 11:47 PM
  5. LsaSrv Event ID 40960 and 40961
    By G-Man in forum Windows Security
    Replies: 2
    Last Post: 15-02-2005, 03:55 AM

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
Page generated in 1,709,651,169.35902 seconds with 17 queries