Replication Does Not Work When the Error "Replication Access Was Denied" Is Logged (297716)
The information in this article applies to:
- Microsoft Windows 2000 Server
- Microsoft Windows 2000 Advanced Server
This article was previously published under Q297716 SYMPTOMS
The following errors may be logged in the Directory Services log:
Event Type: Warning
Event Source: NTDS General
Event Category: Global Catalog
Event ID: 1655
Description: The attempt to communicate with global catalog
\\gc.domain.com failed with the following
status:
Replication access was denied.
The operation in progress might be unable to continue. The directory service will use the locator to try find an available global catalog server for the next operation that requires one.
Event Type: Warning
Event Source: NTDS KCC Event
Category: Knowledge Consistency Checker
Event ID: 1265
Description: The attempt to establish a replication link with parameters
Partition: DC=domain,DC=com
Source DSA DN: CN=NTDS
Settings,CN=DC01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=domain,DC=com
Source DSA Address:
7b7fa657-1925-457a-9e8c-ae167e40b669._msdcs.domain.com
Inter-site Transport (if any): CN=IP,CN=Inter-Site
Transports,CN=Sites,CN=Configuration,DC=domain,DC=com
failed with the following status:
Replication access was denied.
CAUSE
This behavior occurs because the Kerberos tickets in the domain controller are not valid on other domain controllers in the domain.
RESOLUTION
To resolve this behavior:
- Set the Startup type for the Kerberos Key Distribution Center service on the affected domain controller to Disabled.
- Restart the affected domain controller.
- Log on to the domain controller, and then force the replication with its replication partners by using the Active Directory Sites and Services snap-in.
- Check the replication status by typing the following command line from a command prompt:
Repadmin is available in Windows 2000 Support Tools.
- If replication is now successful, set Startup type for the Kerberos Key Distribution Center service on the affected domain controller back to Automatic.
- Restart the Kerberos Key Distribution Center service.
Modification Type: | Minor | Last Reviewed: | 1/27/2006 |
---|
Keywords: | kbenv kberrmsg kbprb KB297716 |
---|
|