Jump to content

resetting security permissions not working


Recommended Posts

Guest Akidd
Posted

I have two vista home premium machines. I was unable to browse between the

two on my home lan.

 

I found the kb article: http://support.microsoft.com/kb/313222

 

As it says I ran: secedit /configure /cfg %windir%\inf\defltbase.inf /db

defltbase.sdb /verbose

 

One machine completes fine, the other does not.

 

When I do so and I immediately get:

 

An extended error has occurred.

 

The task has completed with an error.

See log %windir%\security\logs\scesrv.log for detail info.

 

I am worried about this problem. What is wrong? Below is scesrv.log:

 

 

----Configure General Service Settings...

Configure sysmonlog.

Error 1060: The specified service does not exist as an installed service.

Error opening sysmonlog.

Configure SamSs.

Configure ntmssvc.

Error 1060: The specified service does not exist as an installed service.

Error opening ntmssvc.

Configure netddedsdm.

Error 1060: The specified service does not exist as an installed service.

Error opening netddedsdm.

Configure netdde.

Error 1060: The specified service does not exist as an installed service.

Error opening netdde.

Configure dmserver.

Error 1060: The specified service does not exist as an installed service.

Error opening dmserver.

Configure clipsrv.

Error 1060: The specified service does not exist as an installed service.

Error opening clipsrv.

Configure Browser.

 

General Service configuration was completed successfully.

 

 

----Configure available attachment engines...

 

Configuration of attachment engines was completed successfully.

 

 

----Configure Security Policy...

Configure password information.

Administrator account is disabled.

Guest account is disabled.

 

System Access configuration was completed successfully.

LSA anonymous lookup names setting : existing SD =

D:(D;;0x800;;;AN)(A;;0xf1fff;;;BA)(A;;0x20801;;;WD)(A;;0x801;;;AN)(A;;0x1000;;;LS)(A;;0x1000;;;NS)(A;;0x1000;;;S-1-5-17).

Configure LSA anonymous lookup setting.

Configure machine\software\microsoft\windows

nt\currentversion\setup\recoveryconsole\securitylevel.

Configure machine\software\microsoft\windows

nt\currentversion\setup\recoveryconsole\setcommand.

Configure machine\software\microsoft\windows

nt\currentversion\winlogon\cachedlogonscount.

Configure machine\software\microsoft\windows

nt\currentversion\winlogon\forceunlocklogon.

Configure machine\software\microsoft\windows

nt\currentversion\winlogon\passwordexpirywarning.

Configure machine\software\microsoft\windows

nt\currentversion\winlogon\scremoveoption.

Configure

machine\software\microsoft\windows\currentversion\policies\system\dontdisplaylastusername.

Configure

machine\software\microsoft\windows\currentversion\policies\system\legalnoticecaption.

Configure

machine\software\microsoft\windows\currentversion\policies\system\legalnoticetext.

Configure

machine\software\microsoft\windows\currentversion\policies\system\scforceoption.

Configure

machine\software\microsoft\windows\currentversion\policies\system\shutdownwithoutlogon.

Configure

machine\software\microsoft\windows\currentversion\policies\system\undockwithoutlogon.

Configure

machine\software\policies\microsoft\windows\safer\codeidentifiers\authenticodeenabled.

Configure machine\system\currentcontrolset\control\lsa\auditbaseobjects.

Configure machine\system\currentcontrolset\control\lsa\crashonauditfail.

Configure machine\system\currentcontrolset\control\lsa\disabledomaincreds.

Configure

machine\system\currentcontrolset\control\lsa\everyoneincludesanonymous.

Configure

machine\system\currentcontrolset\control\lsa\fipsalgorithmpolicy\enabled.

Configure machine\system\currentcontrolset\control\lsa\forceguest.

Configure machine\system\currentcontrolset\control\lsa\fullprivilegeauditing.

Configure machine\system\currentcontrolset\control\lsa\limitblankpassworduse.

Configure machine\system\currentcontrolset\control\lsa\lmcompatibilitylevel.

Configure

machine\system\currentcontrolset\control\lsa\msv1_0\ntlmminclientsec.

Configure

machine\system\currentcontrolset\control\lsa\msv1_0\ntlmminserversec.

Configure machine\system\currentcontrolset\control\lsa\nolmhash.

Configure machine\system\currentcontrolset\control\lsa\restrictanonymous.

Configure machine\system\currentcontrolset\control\lsa\restrictanonymoussam.

Configure machine\system\currentcontrolset\control\print\providers\lanman

print services\servers\addprinterdrivers.

Configure machine\system\currentcontrolset\control\session

manager\kernel\obcaseinsensitive.

Configure machine\system\currentcontrolset\control\session manager\memory

management\clearpagefileatshutdown.

Configure machine\system\currentcontrolset\control\session

manager\protectionmode.

Configure

machine\system\currentcontrolset\services\lanmanserver\parameters\autodisconnect.

Configure

machine\system\currentcontrolset\services\lanmanserver\parameters\enableforcedlogoff.

Configure

machine\system\currentcontrolset\services\lanmanserver\parameters\enablesecuritysignature.

Configure

machine\system\currentcontrolset\services\lanmanserver\parameters\nullsessionpipes.

Configure

machine\system\currentcontrolset\services\lanmanserver\parameters\requiresecuritysignature.

Configure

machine\system\currentcontrolset\services\lanmanserver\parameters\restrictnullsessaccess.

Configure

machine\system\currentcontrolset\services\lanmanworkstation\parameters\enableplaintextpassword.

Configure

machine\system\currentcontrolset\services\lanmanworkstation\parameters\enablesecuritysignature.

Configure

machine\system\currentcontrolset\services\lanmanworkstation\parameters\requiresecuritysignature.

Configure machine\system\currentcontrolset\services\ldap\ldapclientintegrity.

Configure

machine\system\currentcontrolset\services\netlogon\parameters\disablepasswordchange.

Configure

machine\system\currentcontrolset\services\netlogon\parameters\maximumpasswordage.

Configure

machine\system\currentcontrolset\services\netlogon\parameters\requiresignorseal.

Configure

machine\system\currentcontrolset\services\netlogon\parameters\requirestrongkey.

Configure

machine\system\currentcontrolset\services\netlogon\parameters\sealsecurechannel.

Configure

machine\system\currentcontrolset\services\netlogon\parameters\signsecurechannel.

 

Configuration of Registry Values was completed successfully.

Configure log settings.

 

Audit/Log configuration was completed successfully.

 

 

----Configure available attachment engines...

 

Configuration of attachment engines was completed successfully.

 

 

----Un-initialize configuration engine...

  • Replies 2
  • Created
  • Last Reply
Guest Mick Murphy
Posted

Here is how to Network them!

 

http://technet.microsoft.com/en-us/library/bb727037.aspx

 

Have a read of the above link re Vista File and Printer Sharing.

 

Permissions/Share info is there as well.

 

If using Norton, McAfee, Trend Micro I.S., make sure file and printer

sharing is enabled in THEIR firewall (or LAN allowed, depending on how their

Exceptions are worded in their Firewall)

 

1st thing to do is make sure that the Workgroup Name of ALL the computers is

the SAME.

 

In Vista Network and Sharing:

 

Network Discovery: ON (So it can see the other computers)

 

Network set to Private (Public is for hotspots, airports, etc)

 

File Sharing: ON

 

Public Folder Sharing: ON (Vista’s Public Folder is the same as XP’s Shared

Docs)

 

Password Protected: OFF (unless you want to set up identical usernames and

passwords (passwords can be different) on ALL computers in your Network) If

you have it ON, you will be asked for a username and password when you try to

access a Vista computer from an XP computer, or a Vista computer.

 

--

Mick Murphy - Qld - Australia

 

 

"Akidd" wrote:

<span style="color:blue">

> I have two vista home premium machines. I was unable to browse between the

> two on my home lan.

>

> I found the kb article: http://support.microsoft.com/kb/313222

>

> As it says I ran: secedit /configure /cfg %windir%infdefltbase.inf /db

> defltbase.sdb /verbose

>

> One machine completes fine, the other does not.

>

> When I do so and I immediately get:

>

> An extended error has occurred.

>

> The task has completed with an error.

> See log %windir%securitylogsscesrv.log for detail info.

>

> I am worried about this problem. What is wrong? Below is scesrv.log:

>

>

> ----Configure General Service Settings...

> Configure sysmonlog.

> Error 1060: The specified service does not exist as an installed service.

> Error opening sysmonlog.

> Configure SamSs.

> Configure ntmssvc.

> Error 1060: The specified service does not exist as an installed service.

> Error opening ntmssvc.

> Configure netddedsdm.

> Error 1060: The specified service does not exist as an installed service.

> Error opening netddedsdm.

> Configure netdde.

> Error 1060: The specified service does not exist as an installed service.

> Error opening netdde.

> Configure dmserver.

> Error 1060: The specified service does not exist as an installed service.

> Error opening dmserver.

> Configure clipsrv.

> Error 1060: The specified service does not exist as an installed service.

> Error opening clipsrv.

> Configure Browser.

>

> General Service configuration was completed successfully.

>

>

> ----Configure available attachment engines...

>

> Configuration of attachment engines was completed successfully.

>

>

> ----Configure Security Policy...

> Configure password information.

> Administrator account is disabled.

> Guest account is disabled.

>

> System Access configuration was completed successfully.

> LSA anonymous lookup names setting : existing SD =

> D:(D;;0x800;;;AN)(A;;0xf1fff;;;BA)(A;;0x20801;;;WD)(A;;0x801;;;AN)(A;;0x1000;;;LS)(A;;0x1000;;;NS)(A;;0x1000;;;S-1-5-17).

> Configure LSA anonymous lookup setting.

> Configure machinesoftwaremicrosoftwindows

> ntcurrentversionsetuprecoveryconsolesecuritylevel.

> Configure machinesoftwaremicrosoftwindows

> ntcurrentversionsetuprecoveryconsolesetcommand.

> Configure machinesoftwaremicrosoftwindows

> ntcurrentversionwinlogoncachedlogonscount.

> Configure machinesoftwaremicrosoftwindows

> ntcurrentversionwinlogonforceunlocklogon.

> Configure machinesoftwaremicrosoftwindows

> ntcurrentversionwinlogonpasswordexpirywarning.

> Configure machinesoftwaremicrosoftwindows

> ntcurrentversionwinlogonscremoveoption.

> Configure

> machinesoftwaremicrosoftwindowscurrentversionpoliciessystemdontdisplaylastusername.

> Configure

> machinesoftwaremicrosoftwindowscurrentversionpoliciessystemlegalnoticecaption.

> Configure

> machinesoftwaremicrosoftwindowscurrentversionpoliciessystemlegalnoticetext.

> Configure

> machinesoftwaremicrosoftwindowscurrentversionpoliciessystemscforceoption.

> Configure

> machinesoftwaremicrosoftwindowscurrentversionpoliciessystemshutdownwithoutlogon.

> Configure

> machinesoftwaremicrosoftwindowscurrentversionpoliciessystemundockwithoutlogon.

> Configure

> machinesoftwarepoliciesmicrosoftwindowssafercodeidentifiersauthenticodeenabled.

> Configure machinesystemcurrentcontrolsetcontrollsaauditbaseobjects.

> Configure machinesystemcurrentcontrolsetcontrollsacrashonauditfail.

> Configure machinesystemcurrentcontrolsetcontrollsadisabledomaincreds.

> Configure

> machinesystemcurrentcontrolsetcontrollsaeveryoneincludesanonymous.

> Configure

> machinesystemcurrentcontrolsetcontrollsafipsalgorithmpolicyenabled.

> Configure machinesystemcurrentcontrolsetcontrollsaforceguest.

> Configure machinesystemcurrentcontrolsetcontrollsafullprivilegeauditing.

> Configure machinesystemcurrentcontrolsetcontrollsalimitblankpassworduse.

> Configure machinesystemcurrentcontrolsetcontrollsalmcompatibilitylevel.

> Configure

> machinesystemcurrentcontrolsetcontrollsamsv1_0ntlmminclientsec.

> Configure

> machinesystemcurrentcontrolsetcontrollsamsv1_0ntlmminserversec.

> Configure machinesystemcurrentcontrolsetcontrollsanolmhash.

> Configure machinesystemcurrentcontrolsetcontrollsarestrictanonymous.

> Configure machinesystemcurrentcontrolsetcontrollsarestrictanonymoussam.

> Configure machinesystemcurrentcontrolsetcontrolprintproviderslanman

> print servicesserversaddprinterdrivers.

> Configure machinesystemcurrentcontrolsetcontrolsession

> managerkernelobcaseinsensitive.

> Configure machinesystemcurrentcontrolsetcontrolsession managermemory

> managementclearpagefileatshutdown.

> Configure machinesystemcurrentcontrolsetcontrolsession

> managerprotectionmode.

> Configure

> machinesystemcurrentcontrolsetserviceslanmanserverparametersautodisconnect.

> Configure

> machinesystemcurrentcontrolsetserviceslanmanserverparametersenableforcedlogoff.

> Configure

> machinesystemcurrentcontrolsetserviceslanmanserverparametersenablesecuritysignature.

> Configure

> machinesystemcurrentcontrolsetserviceslanmanserverparametersnullsessionpipes.

> Configure

> machinesystemcurrentcontrolsetserviceslanmanserverparametersrequiresecuritysignature.

> Configure

> machinesystemcurrentcontrolsetserviceslanmanserverparametersrestrictnullsessaccess.

> Configure

> machinesystemcurrentcontrolsetserviceslanmanworkstationparametersenableplaintextpassword.

> Configure

> machinesystemcurrentcontrolsetserviceslanmanworkstationparametersenablesecuritysignature.

> Configure

> machinesystemcurrentcontrolsetserviceslanmanworkstationparametersrequiresecuritysignature.

> Configure machinesystemcurrentcontrolsetservicesldapldapclientintegrity.

> Configure

> machinesystemcurrentcontrolsetservicesnetlogonparametersdisablepasswordchange.

> Configure

> machinesystemcurrentcontrolsetservicesnetlogonparametersmaximumpasswordage.

> Configure

> machinesystemcurrentcontrolsetservicesnetlogonparametersrequiresignorseal.

> Configure

> machinesystemcurrentcontrolsetservicesnetlogonparametersrequirestrongkey.

> Configure

> machinesystemcurrentcontrolsetservicesnetlogonparameterssealsecurechannel.

> Configure

> machinesystemcurrentcontrolsetservicesnetlogonparameterssignsecurechannel.

>

> Configuration of Registry Values was completed successfully.

> Configure log settings.

>

> Audit/Log configuration was completed successfully.

>

>

> ----Configure available attachment engines...

>

> Configuration of attachment engines was completed successfully.

>

>

> ----Un-initialize configuration engine...</span>

Guest Akidd
Posted

Thanks for the post, but this doesn't solve my issue. I am having a problem

as a result of trying to share files. I am unable to run:

 

From the kb article: http://support.microsoft.com/kb/313222

 

As it says I ran: "secedit /configure /cfg %windir%\inf\defltbase.inf /db

defltbase.sdb /verbose"

 

One machine completes fine, the other does not.

 

On the machine that fails, upon running I immediately get:

"An extended error has occurred."

 

Help?

 

 

"Mick Murphy" wrote:

<span style="color:blue">

> Here is how to Network them!

>

> http://technet.microsoft.com/en-us/library/bb727037.aspx

>

> Have a read of the above link re Vista File and Printer Sharing.

>

> Permissions/Share info is there as well.

>

> If using Norton, McAfee, Trend Micro I.S., make sure file and printer

> sharing is enabled in THEIR firewall (or LAN allowed, depending on how their

> Exceptions are worded in their Firewall)

>

> 1st thing to do is make sure that the Workgroup Name of ALL the computers is

> the SAME.

>

> In Vista Network and Sharing:

>

> Network Discovery: ON (So it can see the other computers)

>

> Network set to Private (Public is for hotspots, airports, etc)

>

> File Sharing: ON

>

> Public Folder Sharing: ON (Vista’s Public Folder is the same as XP’s Shared

> Docs)

>

> Password Protected: OFF (unless you want to set up identical usernames and

> passwords (passwords can be different) on ALL computers in your Network) If

> you have it ON, you will be asked for a username and password when you try to

> access a Vista computer from an XP computer, or a Vista computer.

>

> --

> Mick Murphy - Qld - Australia

>

>

> "Akidd" wrote:

> <span style="color:green">

> > I have two vista home premium machines. I was unable to browse between the

> > two on my home lan.

> >

> > I found the kb article: http://support.microsoft.com/kb/313222

> >

> > As it says I ran: secedit /configure /cfg %windir%infdefltbase.inf /db

> > defltbase.sdb /verbose

> >

> > One machine completes fine, the other does not.

> >

> > When I do so and I immediately get:

> >

> > An extended error has occurred.

> >

> > The task has completed with an error.

> > See log %windir%securitylogsscesrv.log for detail info.

> >

> > I am worried about this problem. What is wrong? Below is scesrv.log:

> >

> >

> > ----Configure General Service Settings...

> > Configure sysmonlog.

> > Error 1060: The specified service does not exist as an installed service.

> > Error opening sysmonlog.

> > Configure SamSs.

> > Configure ntmssvc.

> > Error 1060: The specified service does not exist as an installed service.

> > Error opening ntmssvc.

> > Configure netddedsdm.

> > Error 1060: The specified service does not exist as an installed service.

> > Error opening netddedsdm.

> > Configure netdde.

> > Error 1060: The specified service does not exist as an installed service.

> > Error opening netdde.

> > Configure dmserver.

> > Error 1060: The specified service does not exist as an installed service.

> > Error opening dmserver.

> > Configure clipsrv.

> > Error 1060: The specified service does not exist as an installed service.

> > Error opening clipsrv.

> > Configure Browser.

> >

> > General Service configuration was completed successfully.

> >

> >

> > ----Configure available attachment engines...

> >

> > Configuration of attachment engines was completed successfully.

> >

> >

> > ----Configure Security Policy...

> > Configure password information.

> > Administrator account is disabled.

> > Guest account is disabled.

> >

> > System Access configuration was completed successfully.

> > LSA anonymous lookup names setting : existing SD =

> > D:(D;;0x800;;;AN)(A;;0xf1fff;;;BA)(A;;0x20801;;;WD)(A;;0x801;;;AN)(A;;0x1000;;;LS)(A;;0x1000;;;NS)(A;;0x1000;;;S-1-5-17).

> > Configure LSA anonymous lookup setting.

> > Configure machinesoftwaremicrosoftwindows

> > ntcurrentversionsetuprecoveryconsolesecuritylevel.

> > Configure machinesoftwaremicrosoftwindows

> > ntcurrentversionsetuprecoveryconsolesetcommand.

> > Configure machinesoftwaremicrosoftwindows

> > ntcurrentversionwinlogoncachedlogonscount.

> > Configure machinesoftwaremicrosoftwindows

> > ntcurrentversionwinlogonforceunlocklogon.

> > Configure machinesoftwaremicrosoftwindows

> > ntcurrentversionwinlogonpasswordexpirywarning.

> > Configure machinesoftwaremicrosoftwindows

> > ntcurrentversionwinlogonscremoveoption.

> > Configure

> > machinesoftwaremicrosoftwindowscurrentversionpoliciessystemdontdisplaylastusername.

> > Configure

> > machinesoftwaremicrosoftwindowscurrentversionpoliciessystemlegalnoticecaption.

> > Configure

> > machinesoftwaremicrosoftwindowscurrentversionpoliciessystemlegalnoticetext.

> > Configure

> > machinesoftwaremicrosoftwindowscurrentversionpoliciessystemscforceoption.

> > Configure

> > machinesoftwaremicrosoftwindowscurrentversionpoliciessystemshutdownwithoutlogon.

> > Configure

> > machinesoftwaremicrosoftwindowscurrentversionpoliciessystemundockwithoutlogon.

> > Configure

> > machinesoftwarepoliciesmicrosoftwindowssafercodeidentifiersauthenticodeenabled.

> > Configure machinesystemcurrentcontrolsetcontrollsaauditbaseobjects.

> > Configure machinesystemcurrentcontrolsetcontrollsacrashonauditfail.

> > Configure machinesystemcurrentcontrolsetcontrollsadisabledomaincreds.

> > Configure

> > machinesystemcurrentcontrolsetcontrollsaeveryoneincludesanonymous.

> > Configure

> > machinesystemcurrentcontrolsetcontrollsafipsalgorithmpolicyenabled.

> > Configure machinesystemcurrentcontrolsetcontrollsaforceguest.

> > Configure machinesystemcurrentcontrolsetcontrollsafullprivilegeauditing.

> > Configure machinesystemcurrentcontrolsetcontrollsalimitblankpassworduse.

> > Configure machinesystemcurrentcontrolsetcontrollsalmcompatibilitylevel.

> > Configure

> > machinesystemcurrentcontrolsetcontrollsamsv1_0ntlmminclientsec.

> > Configure

> > machinesystemcurrentcontrolsetcontrollsamsv1_0ntlmminserversec.

> > Configure machinesystemcurrentcontrolsetcontrollsanolmhash.

> > Configure machinesystemcurrentcontrolsetcontrollsarestrictanonymous.

> > Configure machinesystemcurrentcontrolsetcontrollsarestrictanonymoussam.

> > Configure machinesystemcurrentcontrolsetcontrolprintproviderslanman

> > print servicesserversaddprinterdrivers.

> > Configure machinesystemcurrentcontrolsetcontrolsession

> > managerkernelobcaseinsensitive.

> > Configure machinesystemcurrentcontrolsetcontrolsession managermemory

> > managementclearpagefileatshutdown.

> > Configure machinesystemcurrentcontrolsetcontrolsession

> > managerprotectionmode.

> > Configure

> > machinesystemcurrentcontrolsetserviceslanmanserverparametersautodisconnect.

> > Configure

> > machinesystemcurrentcontrolsetserviceslanmanserverparametersenableforcedlogoff.

> > Configure

> > machinesystemcurrentcontrolsetserviceslanmanserverparametersenablesecuritysignature.

> > Configure

> > machinesystemcurrentcontrolsetserviceslanmanserverparametersnullsessionpipes.

> > Configure

> > machinesystemcurrentcontrolsetserviceslanmanserverparametersrequiresecuritysignature.

> > Configure

> > machinesystemcurrentcontrolsetserviceslanmanserverparametersrestrictnullsessaccess.

> > Configure

> > machinesystemcurrentcontrolsetserviceslanmanworkstationparametersenableplaintextpassword.

> > Configure

> > machinesystemcurrentcontrolsetserviceslanmanworkstationparametersenablesecuritysignature.

> > Configure

> > machinesystemcurrentcontrolsetserviceslanmanworkstationparametersrequiresecuritysignature.

> > Configure machinesystemcurrentcontrolsetservicesldapldapclientintegrity.

> > Configure

> > machinesystemcurrentcontrolsetservicesnetlogonparametersdisablepasswordchange.

> > Configure

> > machinesystemcurrentcontrolsetservicesnetlogonparametersmaximumpasswordage.

> > Configure

> > machinesystemcurrentcontrolsetservicesnetlogonparametersrequiresignorseal.

> > Configure

> > machinesystemcurrentcontrolsetservicesnetlogonparametersrequirestrongkey.

> > Configure

> > machinesystemcurrentcontrolsetservicesnetlogonparameterssealsecurechannel.

> > Configure

> > machinesystemcurrentcontrolsetservicesnetlogonparameterssignsecurechannel.

> >

> > Configuration of Registry Values was completed successfully.

> > Configure log settings.

> >

> > Audit/Log configuration was completed successfully.

> >

> >

> > ----Configure available attachment engines...

> >

> > Configuration of attachment engines was completed successfully.

> >

> >

> > ----Un-initialize configuration engine...</span></span>

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.


×
×
  • Create New...