Provisioning Task fails with Event ID 41110

Article:TECH75522  |  Created: 2009-01-13  |  Updated: 2014-03-24  |  Article URL http://www.symantec.com/docs/TECH75522
Article Type
Technical Solution

Product(s)

Issue



Provisioning Task fails with Event ID 41110:


Error



Event Type : Error
Event Source : Enterprise Vault
Event Category : Exchange Provisioning Task
Event ID : 41110
Date : 08-10-2009
Time : 03:27:11
User : N/A
Computer : EV
Description :
The Exchange mailbox provisioning task failed during provisioning group processing. The task has stopped.
Task: Exchange Provisioning Task for domain.com
Domain: domain.com
Provisioning group: <none>
Group member: <none>
Error: Failed to determine DCs for domains in the forest. Reason for error: No domains/domain controllers were found in the forest
Trace: at KVS.EnterpriseVault.ExchangePolicySync.ExchangePolicySynchronization.InitializeDomainControllerCache()
at KVS.EnterpriseVault.ExchangePolicySync.ExchangePolicySynchronization.Initialize()
at KVS.EnterpriseVault.ExchangePolicySync.ExchangePolicySynchronization.RunSynchronization(ExchangePolicySyncTaskEntry taskEntry, CheckControlEventsDelegate
checkControlEvents, Boolean reportMode)
V-437-41110

The Dtrace for ExchangePolicySync and mmc processes show the following information
 


127 07:25:10.914 [5164] (mmc) <5152> EV:M Leaving function VACOpenSCManager() with status: Success ; bsDirIP = 10.0.0.1
128 07:25:11.180 [5180] (EvExchangePolicySyncTask) <1296> EV:M DirectoryHelper::CrackDsName() - Method failed with error [14]
129 07:25:11.180 [5180] (EvExchangePolicySyncTask) <1296> EV:M CDirectoryHelper::GetDomainsInForest() - Failed to translate domain [DOMAIN\] to FQDN with DC [\\DC.domain.com], err [14]
130 07:25:11.180 [5180] (EvExchangePolicySyncTask) <1296> EV:M CDirectoryHelper::NameToFQDN() - Calling CrackDsName() with NT4 to FQDN
131 07:25:11.180 [5180] (EvExchangePolicySyncTask) <1296> EV:M DirectoryHelper::CrackDsName() - DC = [\\domain.com], NameToCrack = [DOMAIN\]
132 07:25:11.180 [5180] (EvExchangePolicySyncTask) <1296> EV:M DirectoryHelper::CrackDsName() - Calling DsBind()
133 07:25:11.211 [5180] (EvExchangePolicySyncTask) <1296> EV:M DirectoryHelper::CrackDsName() - Method failed with error [14]
134 07:25:11.242 [5180] (EvExchangePolicySyncTask) <1296> EV:M CDirectoryHelper::GetDomainsInForest() - Failed to translate domain [DOMAIN\] to FQDN with DC [\\ev.domain.com], err [14]
135 07:25:11.242 [5180] (EvExchangePolicySyncTask) <1296> EV-H {EXCHANGEPOLICYSYNCHRONIZATION.EN_US} Fatal exception raised while processing provisioning group [<none>] / [<none>] - Failed to determine DCs for domains in the forest. Reason for error: No domains/domain controllers were found in the forest. Stack trace: at KVS.EnterpriseVault.ExchangePolicySync.ExchangePolicySynchronization.InitializeDomainControllerCache()| at KVS.EnterpriseVault.ExchangePolicySync.ExchangePolicySynchronization.Initialize()| at KVS.EnterpriseVault.ExchangePolicySync.ExchangePolicySynchronization.RunSynchronization(ExchangePolicySyncTaskEntry taskEntry, CheckControlEventsDelegate checkControlEvents, Boolean reportMode)


Cause



The error "Failed to translate domain" indicates that it was not able to obtain the Netbios name from the FQDN

The error DirectoryHelper::CrackDsName() - Method failed with error [14] indicates the failure to obtain the domains and domain controllers in the forest

These errors refer to failure of Kerberos authentication due to limitation on Token Size.


Solution



Backup the registry before making any changes.
 

1) On the Enterprise Vault Server, Click Start, click Run, type regedit, and then click OK.

2) Locate and then click the following subkey:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos

Note: If the Parameters subkey is not listed under the Kerberos subkey, follow these steps:

3) Right-click Kerberos, point to New, and then click Key.

4) Type Parameters, and then press ENTER.

5) Right-click the Parameters subkey, point to New, click DWORD Value, and then type MaxTokenSize.

6) Double-click MaxTokenSize, set the decimal value to 65535, and then click OK.

Note The default decimal value for the MaxTokenSize registry value is 12000. Microsoft recommends that you set this decimal value to 65535 or that you set the hexadecimal value to FFFF. If you incorrectly set this value to 65535 hexadecimal, Kerberos authentication operations may fail. Additionally, programs may return errors. The 65535 hexadecimal value is an extremely large value.

7) Quit Registry Editor.

8) After setting the MaxTokenSize registry value, and after the computer is updated, restart the computer.
 


Supplemental Materials

SourceEvent ID
Value41110
Description

The Exchange mailbox provisioning task failed during provisioning group processing. The task has stopped.
 


Legacy ID



335018


Article URL http://www.symantec.com/docs/TECH75522


Terms of use for this information are found in Legal Notices