Windows 2008 R2 cross domain shared/security folder permissions

I have a Windows 2008 R2 server located in the example.com domain.  I have a folder that's shared out and it needs to be accessed by a group of machines that are not in the same domain, they are part of a different domain.
I made sure to give Everyone FULL Share and FULL NTFS Security permissions but that didn't make any difference.  This used to work fine on Windows 2003 server.  Something must have changed with the way that Windows 2008 handles share/security permissions.
A temporary workaround is to create a local user on the Windows 2008 R2 server and have the users access the share using those credentials. 
I need it to work without asking the users for any credentials. 

Hi,
Please enable Guest account, assign Everyone group the permission to access the sharing folder and then add the Anonymous SID to the Everyone access
token.
To enable anonymous access on a local workstation or server computer
1.Open Local Security Settings. Click
Start, click Control Panel, double-click
Administrative Tools, and then double-click Local Security Policy.
2.In the console tree, double-click Local Policies, and then click
Security Options.
3.In the details pane, right-click
Network access: Let Everyone permissions apply to anonymous users, and then click
Properties.
4.On the Local Security Settings tab, click
Enabled, and then click OK.
For more information, please refer to the following Microsoft TechNet article:
Anonymous user cannot access a shared folder
http://technet.microsoft.com/en-us/library/cc755781(WS.10).aspx
Regards,
Arthur Li
 TechNet
Subscriber Support 
If you are
TechNet Subscription 
user and have any feedback on our support quality, please send your feedback
here .
Arthur Li
TechNet Community Support

Similar Messages

  • Windows 2008 R2 SP1 (64bit) shared folders no longer work with Windows 7 Pro but do work with WindowsXP & Windows 2003

    As of last week, our Windows 7 Pro workstations can not map or browse the Windows 2008 Server shares. They can ping the Windows 2008 server. The Windows 7 Pro machines can still access the Windows 2003 Server Shares. The older workstations running Windows
    XP can still map to the both the Windows 2003 & Windows 2008 Servers. All the servers can browse to each others shared folders (2 windows 2003 server & 1 windows 2008 server). 

    Ok, now you're down to network or permissions issues. An unedited ipconfig /all
    of server and problem workstation may help. You could also try setting up some auditing.
    https://technet.microsoft.com/en-us/library/dn311489.aspx
    Regards, Dave Patrick ....
    Microsoft Certified Professional
    Microsoft MVP [Windows]
    Disclaimer: This posting is provided "AS IS" with no warranties or guarantees , and confers no rights.

  • Cross Domain user security Authentication in Oracle Weblogic Server 10.3.3

    Now i have configure the cross domain user configuration in the oracle weblogic 10.3.3 server. But i am not able to configure.
    I have mentioned the below oracle document to configure the cross domain configuration.
    http://download.oracle.com/docs/cd/E12840_01/wls/docs103/secmanage/domain.html#domain_interop
    http://download.oracle.com/docs/cd/E14571_01/web.1111/e13752/toc.htm#INTRO120
    http://download.oracle.com/docs/cd/E14571_01/apirefs.1111/e13952/taskhelp/security/EnableTrustBetweenDomains.html
    http://download.oracle.com/docs/cd/E12840_01/wls/docs103/ConsoleHelp/taskhelp/security/ConfigureConnectionFiltering.html
    http://download.oracle.com/docs/cd/E12840_01/wls/docs103/security/con_filtr.html#wp1030656
    Regards,
    S.Vinoth Babu

    sorry,wrong forum
    move to Weblogic Server Section
    Edited by: inchlin on Apr 1, 2009 9:39 AM

  • Multiple identical Windows 2008 Clusters for file sharing, how to create a failover, since DNS CNAME is not an option?

    Hello,
    We have multiple SAN devices that expose block storage to multiple Windows 2008 Storage Edition clusters, which consume them via iSCSI. To simplify, here is what we have:
    machine1+machine2 --> cluster --> storage1 (accessible via
    \\storage1.domain.name\shares)
    machine3+machine4 --> cluster --> storage2 (accessible via
    \\storage2.domain.name\shares)
    The 2 clusters have replication from active (storage1) to standby (storage2), so in theory they both include pretty much all the files.
    We have hundreds of applications that are pointing to \\storage1\shares. In case of a disaster, however, it is an immensely laborious task to change all the end-points from
    \\storage1\shares to \\storage2\shares, and then back. 
    I was trying to declare a CNAME (\\activestorage)  in our internal DNS, and point it to the
    currently active storage system. I tried both an alias and an IP pointing to the cluster. However, when I try to access
    \\activestorage\shares, I got an error that the network share does not exist. I have been reading about this,  and now I understand that CNAMEs are not possible in 2008 and only allowed in 2012 for this particular purpose.
    I also understand that I may have to register a CAP (Client Access Point) to create an "alias" for my storage. However, the CAP approach does not seem to address (or does it?) my initial problem - I am not looking to create an alias just for a
    particular storage cluster, but rather for the
    active storage cluster. This way, if disaster strikes, I can simply go and change an IP somewhere, and all the applications will starting using the standby storage system.
    I realize that there is an extra administration of ensuring that the two clusters are identical from shares perspective, and that's something we are already doing. All I need is a clue into how to make this architecture work in a less painful way.
    Thank you for your help,
    Isaac

    I think you got confused between DFS and DFS replication. The primary use of DFS is namespace virtualization. It also has additional components which aid in real time replication. You can opt to use only the name space virtualization and not the replication.
    The following link may provide some detailed information about DFS in 2008 R2. As I said.. You may not want to sue DFS Replicaiton, but DFS Namespaces is a perfect fit for your requirement (and very simple to implement)
    http://technet.microsoft.com/en-us/library/cc732006.aspx
    Regards Sivakarthi

  • Window 2008 Server Core Domain Controller JRE 6u13 installation fails

    Installer used= jre-6u13-windows-x64-p.exe
    ERROR
    Installer : Wrapper.CreateFile failed with error 3: The system cannot find the path specified.
    I tried in safe mode too.
    Any ideas?
    It does work on a non-domain controller.
    Installer used = jre-6u13-windows-i586-p-iftw.exe
    ERROR
    Windows Installer: Error applying transforms. Verify that the specified transform paths are valid.
    I did not check this installer against a non-domain controller.
    Installer used = jre-6u13-windows-i586-p-s.exe
    INSTALLED SUCCESSFULLY
    I did not check this installer against a non-domain controller.
    Edited by: shinywindows on Apr 10, 2009 10:34 AM
    Edited by: shinywindows on Apr 10, 2009 10:41 AM

    I have exact the same issue with JRE 6u14 on Windows 2008. :(
    Any idea??

  • On a game website I keep getting a window that says cross domain receiver page and I cant get beyond it. What should I do?

    'I am trying to play games on a website that requires the use of pop0ups. I have attempted to allow pop0ups on that website and now I get a window named "Cross-Domain Receiver Page". Its a blank page and I cannot go any further on the web-site. It just freezes there. Could you tell me how to get past this annoyance?

    Having the same issue here. I unfortunately purchased a book on iTunes, then went to download iBooks, but can't due to their recent update/upgrade.  My kids iTouchs are all 6.1.5 , So I'm guessing that if you did not have iBooks previously purchased that you are now S.O.L. if you want to read a book on your iPod??
    I am rather frustrated that I spent money on a book that they can't read.
    Is there another app that will let them read it?

  • Cross domain network security

    Hi,
    I've never used Flash but wonder if it can help me with a
    project.
    Is it possible to serve a Flash application from one domain
    and have that Flash application connect to a different domain to
    access a web service end point?
    What will the user's experience involve? Security popups?
    Miserable failure? etc?
    What are the security constraints? Presume that the user will
    have to accept a security dialog or something?
    Many thanks,
    Tim

    This link may be helpful I hope :)
    http://kb.adobe.com/selfservice/viewContent.do?externalId=tn_16520&sliceId=2
    You may be able to use 2 SWF files...

  • Windows 2008 (Not R2) Domain controllers Kerberos Errors

    We know the replication of the AD structure is working using repadmin /showREPL *
    Which I ran again this morning and all is fine.
    All 3 Domain Controllers are having Kerberos errors ?
    I tried to reset the Kerberos key but the problem still persists.
    This is exactly what I tried yesterday is there something I'm doing wrong ?
    We have 3 Domain controllers
    ch-dc1-2k8    (PDC)
    ch-dc2-2k8
    na-dc1-2k8
    1) I stopped the Kerberos Key Distribution Center service on all 3 servers and set them to manual
    2) I restarted ch-dc2-2k8 and na-dc1-2k8
    3) Then I did the KLIST PURGEon
    ch-dc2-2k8 and na-dc1-2k8
    4) Then on ch-dc1-2k8 (PDC) I did the
    netdom resetpwd /s:ch-dc1-2k8 /ud:companyname\administrator /pd:*
    5) Set Kerberos Key Distribution Center service to Automatic on ch-dc1-2k8 (PDC)
    6) Restarted ch-dc1-2k8 (PDC)
    7) After it restarted I logged in and let it settle for 5 Minutes
    8) Then I started the kerberos service on ch-dc2-2k8 and na-dc1-2k8
    Am I missing something ?

    Hi,
    I think I have already answer this in separate case you have raised in forum.

  • Disable EFS on Windows 2012 shared Network folder

    Hi,
    we have a Windows Server 2012 which is sharing a folder for all our domain users. We use EFS for some clients. If a client copies a file to the shared network folder, it should be automatically decrypted. But instead, the files are being copied with the
    encyrption, so that nobody else can open it. Clients should still be able to encrypt their files. 
    We've already disabled EFS on the Windows Server, but the files keep their encryption, after copying.
    Is there a way to disable EFS on a shared network folder?
    Best regards,
    Matthias

    There is no such option for EFS. If it is allowed, then all EFS operations are allowed.
    Vadims Podāns, aka PowerShell CryptoGuy
    My weblog: en-us.sysadmins.lv
    PowerShell PKI Module: pspki.codeplex.com
    PowerShell Cmdlet Help Editor pscmdlethelpeditor.codeplex.com
    Check out new: SSL Certificate Verifier
    Check out new:
    PowerShell File Checksum Integrity Verifier tool.

  • Windows 2008 and Tiger SMB Issues

    I've been pulling hair out all morning over this one.
    We have a new Windows 2008 server for file sharing. We are trying to connect to it via SMB on our network (with AD domain). Works great on PC, works on Leopard, does not work on Tiger.
    From connect I type “smb://xxxxxxxx” after a few minutes I get an error: “could not connect to the server because the name or password is not correct” which is odd because I haven’t entered any login credentials to begin with.
    I’ve been pouring over Google, Microsoft KB and anything else I can come across with no luck. Things I’ve tried.
    -Clearing keychain passwords for the server
    -Setting the digital signing on the server to disable (most cited fix, but no go for me)
    -Setting Sharing and Security model to “Classic – local users authenticate themselves”
    -Setting LAN Manager authentication to “Send LM & NTLM – use NTLMv2 session security if negotiated”
    -Editing the smb.conf file on the mac to no security
    -Created the nsmb.conf file on the mac with minauth=none.
    -Used Directory access on the mac to add the mac and bind it to the domain.
    -Many Many restarts of the server and clients (and running gpupdate.exe on the server)
    One thing that DOES work is a trial of ADmitmac… but this is not realistic for us if we have guest users needing to access the share.
    I’ve been able to use smb before with tiger and windows xp and windows 2003… but the mac is throwing a fit over the new windows 2008. Also, we can’t upgrade all of our machines to Leopard (which does work) because it will break Quark 6.5.

    Any relevant looking log messages if you browse in Console?
    - cfr

  • Cannot install SP1 on Windows 2008 R2 64bit 0x800f0826

    Hello,
    I'm having an error when I'm trying to deploy service pack 1 of Windows Server 2008 R2.
    I tryed install the SP1 in a workgroup machine and the results were successful.
    But when I'm trying to install in my Domain it doesn't work, I think that some GPO or registry keys are modified on their permission.
    So I removed the machine from the Domain and again try install the SP1 but doesn't work either.
    I think that some GPO removes permission on some files and folders.
    What permissions in files or folder should I have to successful deploy of Service Pack 1 on a Windows 2008 in my Domain?
    Thanks in advice.
    Manuel
    Manuel´s Microsoft Forums Threads

    Hi Ramesh,
    I followed your instructions and found that there are 2 updates that were not allowing the installation of several updates that were pending. 
    But the Service Pack 1 of Windows 2008 R2 does not install correctly either, I always get the same error described above. 
    I was reviewing the CBS.log I found this information:
    2014-01-23 16:06:17, Info                  CBS    Obtained poqexec from Cbs key. C:\Windows\System32\poqexec.exe
    /display_progress \SystemRoot\WinSxS\pending.xml
    2014-01-23 16:06:17, Info                  CBS    Startup: Processing non-critical driver operations queue, Count 118.
    2014-01-23 16:06:17, Info                  CBS    Doqe: Locking driver updates, Count 124
    2014-01-23 16:06:17, Info                  CSI    00000005 Performing 1 operations; 1 are not lock/unlock and follow:
      LockComponentPath (10): flags: 0 comp: {l:16 b:4428ce568718cf01010000006c032801} pathid: {l:16 b:4428ce568718cf01020000006c032801} path: [l:202{101}]"\SystemRoot\WinSxS\amd64_tsgenericusbdriver.inf_31bf3856ad364e35_6.1.7601.17514_none_9872c8452ac8f816"
    pid: 36c starttime: 130349883608612323 (0x01cf18874d013de3)
    2014-01-23 16:06:17, Info                  CSI    00000006 Performing 1 operations; 1 are not lock/unlock and follow:
      LockComponentPath (10): flags: 0 comp: {l:16 b:250fda568718cf01030000006c032801} pathid: {l:16 b:250fda568718cf01040000006c032801} path: [l:194{97}]"\SystemRoot\WinSxS\amd64_tsusbhubfilter.inf_31bf3856ad364e35_6.1.7601.17514_none_776b19f55ac34470" pid:
    36c starttime: 130349883608612323 (0x01cf18874d013de3)
    2014-01-23 16:06:17, Info                  CSI    00000007 Performing 1 operations; 1 are not lock/unlock and follow:
      LockComponentPath (10): flags: 0 comp: {l:16 b:250fda568718cf01050000006c032801} pathid: {l:16 b:250fda568718cf01060000006c032801} path: [l:178{89}]"\SystemRoot\WinSxS\amd64_rdmdrv.inf_31bf3856ad364e35_6.1.7601.17514_none_fe44596e331ef9d7" pid: 36c starttime:
    130349883608612323 (0x01cf18874d013de3)
    2014-01-23 16:06:17, Info                  CSI    00000008 Performing 1 operations; 1 are not lock/unlock and follow:
      LockComponentPath (10): flags: 0 comp: {l:16 b:250fda568718cf01070000006c032801} pathid: {l:16 b:250fda568718cf01080000006c032801} path: [l:180{90}]"\SystemRoot\WinSxS\amd64_tsprint.inf_31bf3856ad364e35_6.1.7601.17514_none_ca1bed7d5beee2f8" pid: 36c
    starttime: 130349883608612323 (0x01cf18874d013de3)
    2014-01-23 16:06:17, Info                  CSI    00000009 Performing 1 operations; 1 are not lock/unlock and follow:
      LockComponentPath (10): flags: 0 comp: {l:16 b:250fda568718cf01090000006c032801} pathid: {l:16 b:250fda568718cf010a0000006c032801} path: [l:178{89}]"\SystemRoot\WinSxS\amd64_winusb.inf_31bf3856ad364e35_6.1.7601.17514_none_561ae9f52c40e492" pid: 36c starttime:
    130349883608612323 (0x01cf18874d013de3)
    2014-01-23 16:06:17, Info                  CSI    0000000a Performing 1 operations; 1 are not lock/unlock and follow:
      LockComponentPath (10): flags: 0 comp: {l:16 b:250fda568718cf010b0000006c032801} pathid: {l:16 b:250fda568718cf010c0000006c032801} path: [l:180{90}]"\SystemRoot\WinSxS\amd64_hdaudio.inf_31bf3856ad364e35_6.1.7601.17514_none_73863b3e7e0f937c" pid: 36c
    starttime: 130349883608612323 (0x01cf18874d013de3)
    2014-01-23 16:06:17, Info                  CSI    0000000b Performing 1 operations; 1 are not lock/unlock and follow:
      LockComponentPath (10): flags: 0 comp: {l:16 b:250fda568718cf010d0000006c032801} pathid: {l:16 b:250fda568718cf010e0000006c032801} path: [l:180{90}]"\SystemRoot\WinSxS\amd64_dot4prt.inf_31bf3856ad364e35_6.1.7601.17514_none_cb6128e5835622ff" pid: 36c
    starttime: 130349883608612323 (0x01cf18874d013de3)
    2014-01-23 16:06:17, Info                  CSI    0000000c Performing 1 operations; 1 are not lock/unlock and follow:
      LockComponentPath (10): flags: 0 comp: {l:16 b:250fda568718cf010f0000006c032801} pathid: {l:16 b:250fda568718cf01100000006c032801} path: [l:182{91}]"\SystemRoot\WinSxS\amd64_clusdisk.inf_31bf3856ad364e35_6.1.7601.17514_none_4bba4b401aee436c" pid: 36c
    starttime: 130349883608612323 (0x01cf18874d013de3)
    2014-01-23 16:06:17, Info                  CSI    0000000d Performing 1 operations; 1 are not lock/unlock and follow:
      LockComponentPath (10): flags: 0 comp: {l:16 b:250fda568718cf01110000006c032801} pathid: {l:16 b:250fda568718cf01120000006c032801} path: [l:182{91}]"\SystemRoot\WinSxS\amd64_modemcsa.inf_31bf3856ad364e35_6.1.7601.17514_none_78520ca36170c34f" pid: 36c
    starttime: 130349883608612323 (0x01cf18874d013de3)
    2014-01-23 16:06:17, Info                  CSI    0000000e Performing 1 operations; 1 are not lock/unlock and follow:
      LockComponentPath (10): flags: 0 comp: {l:16 b:250fda568718cf01130000006c032801} pathid: {l:16 b:250fda568718cf01140000006c032801} path: [l:180{90}]"\SystemRoot\WinSxS\amd64_sffdisk.inf_31bf3856ad364e35_6.1.7601.17514_none_02618e7200897e0a" pid: 36c
    starttime: 130349883608612323 (0x01cf18874d013de3)
    2014-01-23 16:06:17, Info                  CSI    0000000f Performing 1 operations; 1 are not lock/unlock and follow:
      LockComponentPath (10): flags: 0 comp: {l:16 b:250fda568718cf01150000006c032801} pathid: {l:16 b:250fda568718cf01160000006c032801} path: [l:176{88}]"\SystemRoot\WinSxS\amd64_msdsm.inf_31bf3856ad364e35_6.1.7601.17514_none_286d4823f22b1bbe" pid: 36c starttime:
    130349883608612323 (0x01cf18874d013de3)<o:p></o:p>
    It appears the driver may be any device or update any software installed that is causing the problem. 
    We have uninstalled. Net Framework but the behavior is the same, you can not install SP1. 
    Thanks in advance for your help. 
    Best Regards
    Manuel
    Manuel´s Microsoft Forums Threads

  • Migrating Certificate Services to Server 2012 in a 2008 R2 AD Domain

    We have a Windows 2008 R2 SP1 Active Directory domain. Our Enterprise Certificate server is running on Windows 2003 R2. We'd like to introduce a Windows 2012 server into our existing domain and migrate the Certificate Services to that new box. Are there
    any 'gotchas' to implementing Certificate Cervices on a Windows Server 2012 system in a Windows 2008 R2 SP1 domain that we should be concerned with?
    Orange County District Attorney

    Hi,
    You can migrate Certificate Services to another server but server name should be same. Also changing the server name which has CA role installed is not recommended.
    AD CS Migration: Preparing to Migrate
    Applies To: Windows Server 2003, Windows Server 2003 R2, Windows Server 2008, Windows Server 2008 R2, Windows Server 2012
    http://technet.microsoft.com/en-us/library/ee126102(v=ws.10).aspx
    Also I would request to post this question in security forum :
    http://social.technet.microsoft.com/Forums/en-US/winserversecurity/threads
    Also you consider, Windows Server 2012 General forum :
    http://social.technet.microsoft.com/Forums/en-US/winserver8gen/thread
    Best regards,
    Abhijit Waikar.
    MCSA | MCSA:Messaging | MCITP:SA | MCC:2012
    Blog: http://abhijitw.wordpress.com
    Disclaimer: This posting is provided "AS IS" with no warranties or guarantees and confers no rights.

  • Mac OSX file copy to Windows Share folder permissions

    We'd got a few Mac's, one is snow leopard and the other is Lion.  The scenario is:
    Mac:
    Go > Connect to server > smb://servernamehere > Connect > select your share
    The authentication box then pops up, they've been typing in a username and password to connect to Server 2008 (Active Directory here by the way).  I don't think it matters if they type in "DOMAIN\username" and the password or just "username" and the password.
    They try to copy files around but they get this wacky -xx number and their Macs lock up.
    On the Windows Server Side I look at the folder permissions and the users they're using are all golden, full permissions.  I look at a test folder I create and it too looks good.
    The weird thing is this:
    If I look at the folders on Windows it looks normal but if I open the command line on a Mac, do:
    cd /
    cd Volumes
    ls
    cd Folder_I'm_Connected_To
    ls -la | grep testfolder_I_made
    I get these results...
    drwx------ 1 Their_Username_Here  staff  --> Some other stuff here like a folder size, date, time and the folder name
    My question is this I guess.
    Do I have to join these Macs to the Windows domain for the permissions and folder views on the Mac to look right AND to have them funtion properly?  The user of the other Mac says she never types in any authentication stuff, she just clicks a folder shortcut on her Mac ans she's in.
    I would expect the permissions to at least say something like:
    drwxdrwx---
    The Windows server doesn't have the group "staff" which makes it seem the Mac isn't looking at the mounted volume in the same way Windows is.  They also had this problem on AFP and SMB shares directly on a FreeNAS box which is also BSD like a Mac.
    As a result of the Macs behaving similarly on both Windows and BSD (FreeNAS) I think this seems to be some wacky Mac behavior and I just can't figure it out.
    Any help would be appreciated.
    Thanks.

    Hi, same results at the terminal command on a SMB share, observed here with mac computers running with OsX 10.8 with Windows 2008 R2 SMB shares. My issue is that theses computers need to copy files on theses shares with Chronosync or Carbon Copy and this is not working due to an "modify file attributes permissions" error. But if I copy the files using "Finder" it works great.
    You don't need to join your computers to your domain to get it to work. The error that you are talking about is the -5000 error ???

  • Cross-domain service script

    I am working on a site which is utilizing some plug-ins from a another company. An item this other company is providing is a link to an XML file which is generated/updated daily. The owner of the site I am working on wants to have the information within this file visible on his home page in a side bar. If I save the XML file within his site and create the Spry data set, everything works beautifully, but if I create the data set linking to the XML file url, it doesn't work. Because this is information updated daily, I do not want to have to go into this site, save a new XML file and upload it daily. Within the Spry Framework Help in Dreamweaver, I found this:
    "The URL you decide to use (whether absolute or relative) is subject to the browser’s security model, which means that you can only load data from an XML source that is on the same server domain as the HTML page you’re linking from. You can avoid this limitation by providing a cross-domain service script. For more information, consult your server administrator."
    I contacted the other company about this cross-domain service script, but they didn't seem to have a solution. I have no idea where to begin or what to do to resolve this. Any suggestions are most appreciated.
    Thanks,
    A

    crossdomain script might be wrong term for your solution here. What 
    you basically need a script on your server, that does request to the 
    crossdomain server. This script will get / read / your required xml 
    file and just prints its contents with the correct header. These 
    scripts are also known as proxy scripts. For example a script like 
    this: http://www.phpfour.com/blog/2008/03/cross-domain-ajax-using-php/
    hopes this helps.

  • USN rollback on Windows 2008 R2 DC

    Hi All,<o:p></o:p>
    I need an urgent advice on an issue, <o:p></o:p>
    I have 4 DC’s, all running Windows 2008 R2 -Forest /domain functional level is Windows 2008.<o:p></o:p>
    Totally we have 3 site, 2 sites has 1 DC each and another site has 2 DC's.<o:p></o:p>
    On 3rd site where i have 2 DC’s, 1 DC is on VMware VM.<o:p></o:p>
    On Virtual Domain controller, my colleague has restored VM snapshot after failing to add vCPU (he got Windows error recovery).<o:p></o:p>
    On the same day it’s found that inbound and outbound replication is disabled on that DC.
    “DSA Not writable” is set to 4 in registry.<o:p></o:p>
    My colleague enabled replication with below commands and replication seems to be ok now.<o:p></o:p>
    repadmin /options servername -DISABLE_OUTBOUND_REPL<o:p></o:p>
    repadmin /options servername -DISABLE_INBOUND_REPL<o:p></o:p>
    My question is  <o:p></o:p>
    Is it ok to leave the DC just the way as it is now? Will there be any problem in future because of this?<o:p></o:p>
    “DSA Not writable” key still set to 4 in registry.<o:p></o:p>
    Thank you in advance.<o:p></o:p>

    Correct, its been done without contacting me.. :(
    1. Does it still makes a diference if i i do authoritative restore now? because the replication is
    already started from the the DC which had issue. 
    2. Right now i tried password reset, RADIUS authentication and users authentication is working fine from that DC, if i leave the DC as it is will there be any issue? i ll check the event as you mentioned.
    3. Will there be an issue if i leave the registry entry as it is? i know i can delete the “DSA Not
    writable” key and reboot, however just want to know if i am missing anything.
    Thanks again..

Maybe you are looking for

  • Device not recognized in itunes

    After latest update my idevices are not being recognized by itunes. I have reset both devices and my mac mini I have used an apple cable to sync and approved both devices then they just dont show up but bpth show a charge. I have an ipad mini and an

  • Photoshop CC crashes and doesn't recognize display drivers.

    I just built this brand new computer and everytime I open up Photoshop CC it first promps me with a message that 3d features require a minimum of 512mb of vRam and it has detected less on my system. I then go into Edit>Preference>Performance and unde

  • Additional Payment terms

    Dear's, How to get additional payment terms data from the customer master data. Kindly let me know the tables or any other way to get the details. Thanks ! Edited by: Mohammad Irfan on May 28, 2011 7:25 PM

  • Trying to deploy OIM on WebLogic 11g

    I'm trying to deploy OIM into a WebLogic 11g server (specifically, Oracle Internet Directory) running on RedHat 64 bit. The purpose of this is to support a Discoverer deployment. When trying to install Oracle Internet Directory, I am stuck on the scr

  • PHP Code, Variables & CSS. Would this work?

    Hello, I am new to PHP, this is my first script I have made without any help, I am using xammp to test my site, but the basics of the code is this. I am adding an include code into the navigation menu and in the CSS I have defined certain rules for t