Try our new Certificate Revocation List Check Tool
CRLcheck.exe is a tool developed to verify digital signatures of executable files. It collects files from known paths on your client, checks their signature, and checks Certificate Revocation Lists (CRL) and OCSP download. This helps avoid delays in launching files.
Category published:  Microsoft Server OS Server 2008 R2 Server 2012 R2 Server 2016 Uncategorized   Click on the Category button to get more articles regarding that product.

Event 10009 on Server 2008R2 Exchange 2010 Distributed COM

Posted by admin on 26.11.2018

Event 10009 on Server 2008R2 Exchange 2010 Distributed COM

If you RUN:

  • Exchange Analyser
  • Powershell command get-owavirtualdirectory (Or any other command the connects to CAS to enumerate values)

This OBSOLETE and you COULD leave it as it is. If people from Event or SIEM are nagging you could solve it. We recommend leaving it as it is.

Behaviour:

You will see an EVENT 10009, Distributed COM in SYSTEM Event.

DCOM was unable to communicate with the computer CAS123.EMEA.butsch.ch using any of the configured protocols.

 

https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2003/cc778012(v=ws.10)

https://social.technet.microsoft.com/Forums/en-US/0c21a35d-1b9a-4ec4-a81e-c0ba388718d4/dcom-10009-error-every-night-shortly-after-midnight?forum=exchange2010

Solution: On the CAS Servers and also on the Server your get the Error do following:

 

SOLUTION1: Create a registry key: IgnoreDelegationFailure

Applies To: Windows Server 2003, Windows Server 2003 R2, Windows Server 2003 with SP1, Windows Server 2003 with SP2 (remark Butsch also to Server 2008R2)

HKLM\Software\Policies\Microsoft\Windows NT\Rpc\IgnoreDelegationFailure (If IgnoreDelegationFailure is not there make a new DWORD)

Set the value to:

0 = TURNOFF (As it is without the SubKey)

1 = TURNON

Stores configuration data for the policy setting Ignore Delegation Failure.

Solution2: Change GPO which sets the same key

To change the value of this entry, use the Group Policy Object Editor (Gpedit.msc) to do this local. The corresponding policy is located in Administrative Templates\System\Remote Procedure Call.

You can SET this by GPO from Active Directory but we do not recommend doing that for all your Servers. I would do a separate GPO and ONLY apply that to the Exchange Servers.

https://getadmx.com/?Category=Windows_10_2016&Policy=Microsoft.Policies.RemoteProcedureCalls::RpcIgnoreDelegationFailure


 Category published:  Microsoft Server OS Server 2008 R2 Server 2012 R2 Server 2016 Uncategorized   Click on the Category button to get more articles regarding that product.