Freigeben über


Event ID 8197 - MSExchangeFBPublish with error 0x80040111

There is an article out there that addresses the issue that some of our customers are seeing:
828764 "Event 8197" Error Message Is Logged Repeatedly in the Application Event
https://support.microsoft.com/?id=828764

It says that if you are getting this, there is a good chance that Exchange is trying to authenticate against a GC that doesn't have a trust with the domain that your Exchange 5.5 service account is in.  But...  How do you verify this?  Can you just look at the DSaccess tab on the Exchange server?  No.  As Jasper Kuria states in his post at https://blogs.technet.com/exchange/archive/2005/07/29/408394.aspx in this instance we don’t look at the output from DSAccess.  This is authentication, not an LDAP call.  In this case we look at the same GC that you would get if you were to run “nltest /dsgetdc: /gc”.  If you are getting 8197s on your Exchange servers, you can run this and see if you are getting a GC in another domain that doesn’t have an explicit trust with the domain that the Exchange 5.5 service account is in.  In fact if you have auditing on and look at the GC’s security logs you may see something similar to the following:

Event Type: Failure Audit
Event Source: Security
Event Category: Account Logon
Event ID: 680
Date:
Time:
User: NT AUTHORITY\SYSTEM
Computer: <GC Server Name>
Description:
Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
Logon account: <Exchange 5.5 Service Account>
Source Workstation: <Exchange 2003 server>
Error Code: 0xC0000064

At this moment there are currently two workarounds:

  •  Create a two-way trust with the two domains. 
  •  Move the GC in the other domain to another site. 

Hopefully this will help someone else who is seeing this...