Environment:
Ad:windows Server 2003 Upgrade for Windows server R2
Client: Windows 7+xp mode
Fault:
AD 2003 upgrade to R2 (System upgrade, other unchanged), resulting in the client Windows 7 XP mode login domain time is too long, in XP mode reconfigure user profile, landing normal.
See the log with Event40960 and 40961 warnings on ad:
EventID: 40960
Source: LsaSrv
Type:warning
Category: SPNEGO (negotiator)
Description: The Security System detected an attempted downgradeattack for server <server Name>. The failure code fromauthentication protocol Kerberos is "Thereare currently no logon servers available to service th e logon request. (0xc000005e) ".
EventID: 40691
Type:warning
Source: LSASRV
Category: SPNEGO (negotiator)
Description:
The Security System could not establish a securedconnection with the server ldap/xxxx.com. No authentication protocol was available.
Workaround:
Login in XP mode with local administrator, open the registry, in [Hkey_local_machine\system\currentcontrolset\control\lsa\kerberos\parameters]
Add Dword,dword named MaxPacketSize with a value of 1
This article from "Gs_hao" blog, declined reprint!
[Case sharing] AD 2003 Upgrade 2008 causes XP mode to log on domain for a long time