Provisioning Task fails with Event ID 41110

Article:TECH75522  |  Created: 2009-01-13  |  Updated: 2011-06-01  |  Article URL http://www.symantec.com/docs/TECH75522
Article Type
Technical Solution


Environment

Problem



Provisioning Task fails with Event ID 41110


Solution



Issue : Provisioning Task fails with event ID 41110
 
Details
 
Event ID
 
Event Type : Error
 
Event Source : Enterprise Vault
 
Event Category : Exchange Provisioning Task
 
Event ID : 41110
 
Date : 08-10-2009
 
Time : 03:27:11
 
User : N/A
 
Computer : EV
 
Description :
 
The Exchange mailbox provisioning task failed during provisioning group processing. The task has stopped.
 
Task: Exchange Provisioning Task for domain.com
 
Domain: domain.com
 
Provisioning group: <none>
 
Group member: <none>
 
Error: Failed to determine DCs for domains in the forest. Reason for error: No domains/domain controllers were found in the forest
 
Trace: at KVS.EnterpriseVault.ExchangePolicySync.ExchangePolicySynchronization.InitializeDomainControllerCache()
 
at KVS.EnterpriseVault.ExchangePolicySync.ExchangePolicySynchronization.Initialize()
 
at KVS.EnterpriseVault.ExchangePolicySync.ExchangePolicySynchronization.RunSynchronization(ExchangePolicySyncTaskEntry taskEntry, CheckControlEventsDelegate checkControlEvents, Boolean reportMode)
 

 
Dtrace
 

 
The Dtrace for ExchangePolicySync and mmc processes show the following information
 

 
127 07:25:10.914 [5164] (mmc) <5152> EV:M Leaving function VACOpenSCManager() with status: Success ; bsDirIP = 10.0.0.1
 
128 07:25:11.180 [5180] (EvExchangePolicySyncTask) <1296> EV:M DirectoryHelper::CrackDsName() - Method failed with error [14]
 
129 07:25:11.180 [5180] (EvExchangePolicySyncTask) <1296> EV:M CDirectoryHelper::GetDomainsInForest() - Failed to translate domain [DOMAIN\] to FQDN with DC [\\DC.domain.com], err [14]
 
130 07:25:11.180 [5180] (EvExchangePolicySyncTask) <1296> EV:M CDirectoryHelper::NameToFQDN() - Calling CrackDsName() with NT4 to FQDN
 
131 07:25:11.180 [5180] (EvExchangePolicySyncTask) <1296> EV:M DirectoryHelper::CrackDsName() - DC = [\\domain.com], NameToCrack = [DOMAIN\]
 
132 07:25:11.180 [5180] (EvExchangePolicySyncTask) <1296> EV:M DirectoryHelper::CrackDsName() - Calling DsBind()
 
133 07:25:11.211 [5180] (EvExchangePolicySyncTask) <1296> EV:M DirectoryHelper::CrackDsName() - Method failed with error [14]
 
134 07:25:11.242 [5180] (EvExchangePolicySyncTask) <1296> EV:M CDirectoryHelper::GetDomainsInForest() - Failed to translate domain [DOMAIN\] to FQDN with DC [\\ev.domain.com], err [14]
 
135 07:25:11.242 [5180] (EvExchangePolicySyncTask) <1296> EV-H {EXCHANGEPOLICYSYNCHRONIZATION.EN_US} Fatal exception raised while processing provisioning group [<none>] / [<none>] - Failed to determine DCs for domains in the forest. Reason for error: No domains/domain controllers were found in the forest. Stack trace: at KVS.EnterpriseVault.ExchangePolicySync.ExchangePolicySynchronization.InitializeDomainControllerCache()| at KVS.EnterpriseVault.ExchangePolicySync.ExchangePolicySynchronization.Initialize()| at KVS.EnterpriseVault.ExchangePolicySync.ExchangePolicySynchronization.RunSynchronization(ExchangePolicySyncTaskEntry taskEntry, CheckControlEventsDelegate checkControlEvents, Boolean reportMode)
 
136 07:25:11.242 [5180] (EvExchangePolicySyncTask) <1296> EV~E |Event ID: 41110 The Exchange mailbox provisioning task failed during provisioning group processing. The task has stopped.|Task: Exchange Provisioning Task for DOMAIN.COM|Domain: DOMAIN.COM|Provisioning group: <none>|Group member: <none>|Error: Failed to determine DCs for domains in the forest. Reason for error: No domains/domain controllers were found in the forest|Trace: at KVS.EnterpriseVault.ExchangePolicySync.ExchangePolicySynchronization.InitializeDomainControllerCache()|
 

 
Workaround
 

 
The error "Failed to translate domain" indicates that it was not able to get the Netbios name from the FQDN
 
The error DirectoryHelper::CrackDsName() - Method failed with error [14] indicates the failure to get the domains and domain controllers in the forest
 
These errors refer to failure of Kerberos authentication due to limitation on Token Size.
 

 
Please take a backup of the registry before making any changes.
 

 
1) On the Enterprise Vault Server, Click Start, click Run, type regedit, and then click OK.
 
2) Locate and then click the following subkey:
 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos
 
Note If the Parameters subkey is not listed under the Kerberos subkey, follow these steps:
 
3) Right-click Kerberos, point to New, and then click Key.
 
4) Type Parameters, and then press ENTER.
 
5) Right-click the Parameters subkey, point to New, click DWORD Value, and then type MaxTokenSize.
 
6) Double-click MaxTokenSize, set the decimal value to 65535, and then click OK.
 
Note The default decimal value for the MaxTokenSize registry value is 12000. Microsoft recommends that you set this decimal value to 65535 or that you set the hexadecimal value to FFFF. If you incorrectly set this value to 65535 hexadecimal, Kerberos authentication operations may fail. Additionally, programs may return errors. The 65535 hexadecimal value is an extremely large value.
 
7) Quit Registry Editor.
 
8) After you set the MaxTokenSize registry value, and after the computer is updated, restart the computer.
 

 


Legacy ID



335018


Article URL http://www.symantec.com/docs/TECH75522


Terms of use for this information are found in Legal Notices