The Domain does not Enumerate Within the Citrix Management Console

Citrix states in their article: CTX881878

CTX881878 - The Domain does not Enumerate Within the Citrix Management Console

This document was published at: http://support.citrix.com/kb/entry.jspa?externalID=CTX881878

Document ID: CTX881878, Created on: Sep 13, 2001, Updated: Sep 8, 2003

Products: Citrix MetaFrame XP 1.0 for Microsoft NT 4.0 Server Terminal Server Edition, Citrix MetaFrame XP 1.0 for Microsoft Windows 2000

Symptom

When attempting to publish an application to domain user or groups, or when attempting to add a Citrix administrator from the domain, the domain does not appear on the list.

Cause

When the IMA service starts it tries to create a list of domains trusted by the server, which includes:

• The server name

• BUILTIN

• The server's primary domain

• The domains trusted by the primary domain. Ensure User Manager for Domains or Active Directory Domain and Trusts contain correct and active trusts. Below is excerpt of a ctxtrace log that came from an environment in which a non-existent domain was still configured in a trusting relationship. The computer was unable to see the domain under Network Neighborhood > Directory.

MFSrvSs, Info] GetUIDByHostID: hidServer= 0x00001adc

[MFApp, Info] MFAppCache_Initialize called

[WinDrvSS, Info] QueryTrustInfoThread::QueryTrustedInstances() - DsEnumerateDomainTrusts(DS_DOMAIN_PRIMARY) FAILURE or returned no primary domain. The Server must be in a Workgroup. Value = 51f

[WinDrvSS, Info] QueryTrustInfoThread::QueryTrustedInstances() - Primary Domain Name Follows:

[WinDrvSS, Info]

[WinDrvSS, Info] QueryTrustInfoThread::QueryTrustedInstances() - For NT5 - End Value = 0

• MetaFrame XP also tries to find out the type of a domain; that is, whether it is Windows NT 4.0 or Active Directory. No API calls are available for this on Windows Terminal Server. Therefore, MetaFrame XP tries to find the primary domain controller (PDC) for the domain and then checks the operating system version of the PDC. If the PDC operating system version is Windows 2000, it is known to be an Active Directory domain.

To find the operating system version of a PDC, MetaFrame XP calls the Win32 GeWindows Terminal ServerrverGetInfo API. This API may fail with an ACCESS_DENIED error because the PDC is not allowing anonymous connections.

Below is a sample log when the IMA service starts and fails under this condition:

[WinDrvSS, Error] WinDrvHelper::_GeWindows Terminal ServerrverInfo(). Failed. Value = 5
[WinDrvSS, Error] WinDrvHelper::GetDomainType(). _GetDCName(PDC) Failed. Value = 80000001
[MFSrvSs, Info] QueryMFCompatibilityMode: DISABLED.
[WinDrvSS, Error] WinDrvHelper::_GeWindows Terminal ServerrverInfo(). Failed. Value = 5
[MFApp, Error] RemoveAppsFromRegistry: RegOpenKeyEx(hMF20AppsKey) failed. Error: 0x2.
[WinDrvSS, Error] WinDrvHelper::GetDomainType(). _GetDCName(Any DC) Failed. Value = 80000001

• Does Q310611 apply?

WARNING: Using Registry Editor incorrectly can cause serious problems that may require you to reinstall your operating system. Microsoft cannot guarantee that problems resulting from the incorrect use of Registry Editor can be solved. Use Registry Editor at your own risk. For information about how to edit the registry, view the "Changing Keys and Values" Help topic in Registry Editor (Regedit.exe) or the "Add and Delete Information in the Registry" and "Edit Registry Data" Help topics in Regedt32.exe. Make sure you back up the registry before you edit it. If you are running Windows NT, also update your Emergency Repair Disk (ERD).

There is a registry value called "RestrictAnonymous" under HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA key. If this value is set to 1 on the PDC, the API call fails. Possible solutions:

1. Set the "RestrictAnonymous" value to zero on the PDC (you may need to reboot).

2. Windows Terminal Server servers treat Active Directory domains as Windows NT 4.0 domains, unless at least one Windows 2000 server joins the farm and updates the data store to indicate the correct domain type.



Primary links

Custom Search

Who's new

  • Cachleferah
  • Weedbacuupe
  • vororourn
  • vDonellaCandrah
  • SnnaSusi

Who's online

There are currently 0 users and 4 guests online.

KrissysCorner.com RuthSwensonLaw.com CreativeLizardProductions.com

DISCLAIMER:

None of this has anything to do with us, someone else is responsible for the entire thing, and we have no idea who or why. We do not know anything about it. It may be alien life forms for all we know: we haven't a clue. You cannot blame us for anything that may result from your visit. That was entirely your own personal choice, made by you of your own volition, and without our knowledge. We do not, after all, have any control over you and cannot by any stretch of the imagination be expected to accept or acknowledge, be it legally or morally, any accountability for decisions made by you on an independent basis, utilizing your own free will, and without our intervention. We are therefore in no way, shape, or form answerable to anyone for any consequences arising from the aforementioned or indeed any other actions, similar or otherwise, because it was not us that did, or did not do anything. It is not even remotely our fault, and we are in no way prepared or willing to accept any liability, not even slightly, ever. We are, in fact completely and utterly blameless, in that it is definitely not our concern, and no blame can possibly be laid at our doorstep, even if we had one, the possession of which we hereby reserve as being entirely our own free choice. The onus is not on us at all, and furthermore, never has been. The entire matter is wholly beyond our control, and completely out of our hands, each of which are washed scrupulously clean of the whole business. We are not accountable for anything at all, and we hereby categorically deny all responsibility for all that has ever, or will ever happen. Our innocence is therefore wholly beyond doubt and absolutely unimpeachable, and so cannot, under even the remotest or unlikeliest circumstances, be brought into question. By clicking either on a link on this site, clicking on a link that leads to this site, or by arriving at this site by natural or supernatural means, you are in effect accepting responsibility for the fact that it is all entirely your own fault, down to the most miniscule detail, and that you are wholly accountable for whatever outcome may arise as a consequence of the aforementioned action or actions insofar as they were undertaken personally by you on an entirely voluntary basis and without any persuasion, coercion or influence from any party or parties other than yourself. Don't come sniveling to us, we are only figments of your imagination. I also agree that if I am ever with a contributor to this website during mealtimes I agree to pay for any super-sizing of their meal, or at least a nice dessert or one of those foo-foo drinks with an umbrella or a monkey. By admitting to have seen the worthless spineless drivel on this website (also known as content)

I Agree Wholeheartedly and Without Reservation to the above. (Except maybe for that part about the monkey.)

All Your Base Are Belong To Us.

Soylent Green Is People!

Never make a bet with a Sicilian when Death is on the Line!

No. Really, I do agree.