|
Laptops & Tablets
|
Desktop & All-In-Ones
|
Servers
|
Workstations
|
Smartphones
|
Accessories & Upgrades
|
Monitors & Projectors
|
|
|||||
|
|||||
You may experience RPC Endpoint Mapper errors when you use specific tools and utilities that are available in the Support folder of the Microsoft Windows Server CD-ROM, available as part of a Windows Server Resource Kit, or available on the Microsoft Web site. These errors can help you troubleshoot RPC Endpoint Mapper issues.
The symptoms that are described in this article do not represent every possible scenario that may result when RPC does not function correctly. RPC is used by several components in Windows Server 2003 and Windows 2000 Server, such as the File Replication Service (FRS), Active Directory Replication, Certificate services, DCOM, Microsoft Message Queuing (also known as MSMQ), and MAPI. Therefore, a variety of errors and symptoms may occur when RPC does not function correctly.
Back to the top
This step-by-step article describes how to troubleshoot Remote Procedure Call (RPC) Endpoint Mapper errors in Windows Server 2003 and Windows 2000 Server by using tools and utilities that are available in the Support folder of the Windows Server 2003 or Windows 2000 Server CD-ROM or that are available as part of the Windows Server 2003 Resource Kit or the Windows 2000 Server Resource Kit. Remote Procedure Call is a protocol that is used by the Windows operating system. RPC provides an inter-process communication mechanism that allows a program running on one computer to run code on a remote system.
In certain situations, when you try to force Active Directory replication by using Active Directory Sites and Services, when you try to promote an additional domain controller by using the Dcpromo tool, or when you run netdom query fsmo from a command line, you may receive an error message that is similar to the following:There are no more endpoints available from the endpoint mapper.Other symptoms may include:
Note If you use a network capture program, such as Network Monitor, to capture network traffic, the computer may not receive a response when it tries to establish an RPC session to another computer by using any port greater than 1024. The sending computer uses the Universal Unique Identifier (UUID) for the RPC Endpoint Mapper. The UUID for the RPC Endpoint Mapper is E1AF8308-5D1F-11C9-91A4-08002B14A0FA.
Back to the top
Back to the topThe Dcdiag tool
The Dcdiag tool analyzes the state of domain controllers in a forest or in an enterprise and reports any problems to help in troubleshooting. You can use the Dcdiag tool to help troubleshoot RPC Endpoint Mapper errors when you run the Dcdiag tool. To do this, follow these steps:
If RPC Endpoint Mapper problems exist, the Dcdiag tool may respond with error messages that are similar to the following:The replication generated an error (1753): There are no more endpoints available from the endpoint mapper. DsBindWithSpnEx() failed with error 1753, There are no more endpoints available from the endpoint mapper. Directory Binding Error 1753: There are no more endpoints available from the endpoint mapper. DsBind() failed with error 1753, There are no more endpoints available from the endpoint mapper. DsBindWithSpnEx() failed with error 1722, The RPC server is unavailable. DsBindWithCred() failed with error 1753. There are no more endpoints available from the endpoint mapper. Status is 1722: The RPC server is unavailable.
Back to the top
You can use the Netdiag tool to help isolate networking and connectivity problems. You can use the Netdiag tool to help troubleshoot RPC Endpoint Mapper problems. To do this, follow these steps:
If RPC Endpoint Mapper problems exist, the Netdiag tool may respond with error messages that are similar to the following:
[WARNING] Failed to query SPN registration on DC domaincontroller. domainname.com.
Kerberos test. . . . . . . . . . . : Skipped Your logon domain isn't running Kerberos. (<Domainname>\Administrator) Kerberos cannot be tested. DC list test . . . . . . . . . . . : Failed [WARNING] Cannot call DsBind to domaincontroller. domainname.intranet (10.55.0.110). [EPT_S_NOT_REGISTERED]
Trust relationship test. . . . . . : Failed Test to ensure DomainSid of domain '<domainname>' is correct. [FATAL] Secure channel to domain '<domainname>' is broken. [ERROR_ACCESS_DENIED]
Back to the top
You can use the Repadmin tool for Active Directory replication, for troubleshooting Active Directory replication problems, and for troubleshooting RPC Endpoint Mapper problems. To do this, follow these steps:
If RPC Endpoint Mapper problems exist, the Repadmin tool may respond with an error message that is similar to the following:DsBindWithCred to localhost failed with status 1753 (0x6d9): There are no more endpoints available from the endpoint mapper.
Back to the top
Enterprise and domain administrators can use the Ntdsutil tool to manage and repair Active Directory, and to help troubleshoot RPC Endpoint Mapper problems. To help troubleshoot RPC Endpoint Mapper problems, follow these steps:
If RPC Endpoint Mapper Problems exist, the Ntdsutil tool may respond with an error message that is similar to the following:DsBindW error 0x6d9 (There are no more endpoints available from the endpoint mapper.)
Back to the top
You can use the Gpotool tool to check the consistency of Group Policy objects on domain controllers. The Gpotool tool is contained in the Windows Server 2003 Resource Kit. You can download the Windows Server 2003 Resource Kit by visiting the following Microsoft Web site: http://www.microsoft.com/downloads/details.aspx?FamilyID=9d467a69-57ff-4ae7-96ee-b18c4790cffd&DisplayLang=en (http://www.microsoft.com/downloads/details.aspx?FamilyID=9d467a69-57ff-4ae7-96ee-b18c4790cffd&DisplayLang=en)
After you have installed the Resource kit, you can use the Gpotool tool to help troubleshoot RPC Endpoint Mapper problems. To do this, follow these steps:
If RPC Endpoint Mapper Problems exist, the Gpotool tool may respond with an error messages that are similar to the following:GPOTOOL: e ERROR: GetDCList; DsBindW; hr=800706d9; There are no more endpoints available from the endpoint mapper. GPOTOOL: + File:d:\nt\private\ctpolprf\common\polutil\polutil.cxx; Line:728 GPOTOOL: e ERROR: GetDCList; GetDCList failed; hr=800706d9; There are no more endpoints available from the endpoint mapper.GPOTOOL: + File: d:\nt\private\ctpolprf\common\polutil\polutil.cxx; Line:644
Back to the top
The following events may be logged on a domain client, on a member server, or on a domain controller when RPC does not function correctly:
Event ID: 1053
Event Source: Userenv
Description: Windows cannot determine the user or computer name. (There are no more endpoints available from the endpoint mapper. ). Group Policy processing aborted.
Event ID: 1000
Event Source: Userenv
Description: Windows cannot determine the user or computer name. Return value (1753). :
Event ID: 1168
Source: NTDS General
Description: Error -1073741823(c0000001) has occurred (Internam ID 3000b35). Please contact Microsoft Product Support Services for assistance.
Event ID: 1265
Source: NTDS KCC
Description: The attempt to establish a replication link with parameters Partition: CN=Configuration,DC=contoso,DC=com Source DSA DN: CN=NTDS Settings,CN= ServerName,CN=Servers,CN= domainname,CN=Sites,CN=Configuration,DC=contoso,DC= com Source DSA Address: 70863dce-1031-47ea-a567-2f46212dd361._msdcs.securityroot.com Inter-site Transport (if any): CN=IP,CN=Inter-Site Transports,CN=Sites,CN=Configuration,DC=securityroot,DC=net failed with the following status: There are no more endpoints available from the endpoint mapper. The record data is the status code. This operation will be retried.
Event ID: 1656
Event Source: NTDS General Event
Description: The Directory Service was unable to find any RPC protocol sequences installed on this computer, failing with error 1719. The Directory Service will be unable to respond to any RPC requests as long as this condition persists.
Event ID: 10010
Event Source: DCOM
Description: The server {8BC3F05E-D86B-11D0-A075-00C04FB68820} did not register with DCOM within the required timeout.
Event ID: 4097
Event Source: EventSystem
Description: The COM+ Event System detected a bad return code during its internal processing. HRESULT was 80070005 from line 42 of .\eventsystemobj.cpp. Please contact Microsoft Product Support Services to report this error.
Event ID: 1012
Event Source: Winlogon
Description: The automatic certificate enrollment subsystem could not access local resources needed for enrollment. Enrollment will not be performed. (0x800706d9) There are no more endpoints available from the endpoint mapper.
On an enterprise certification authority server, or on a subordinate certification authority server, an event that is similar to the following may be logged: Event ID: 20
Event Source: KDC
Description: The currently selected KDC certificate was once valid, but now is invalid and no suitable replacement was found. Smartcard logon may not function correctly if this problem is not remedied. Have the system administrator check on the state of the domain's public key infrastructure. The chain status is in the error data.
Back to the top
The Active Directory Installation Wizard (Dcpromo.exe) promotes Windows Server-based computers to be domain controllers. When the Dcpromo tool fails because of RPC problems, error messages that are similar to the following may appear in the DCPromo.log file.
Note The Dcpromo.log file is located in the %windir%\Debug folder.
02/07 21:08:48 [INFO] Error - The Directory Service failed to create the object CN= Name,CN= Partitions,CN= Configuration,DC= domain,DC= com. Please check the event log for possible system errors. (1753) 02/07 21:08:49 [INFO] NtdsInstall for servername.domainname.com returned 1753 02/07 21:08:49 [INFO] DsRolepInstallDs returned 1753 02/07 21:08:49 [ERROR] Failed to install the directory service (1753)10/03 10:13:17 [INFO] Error - The Directory Service failed to create the server object for CN=NTDS Settings,CN= name,CN=Servers,CN= name,CN=Sites,CN=Configuration,DC= domainname ,DC= com on server servername.domainname.com. Please ensure the network credentials provided have sufficient access to add a replica. (1753) 10/03 10:13:17 [INFO] NtdsInstall for servername.domainname.com. returned 1753 10/03 10:13:17 [INFO] DsRolepInstallDs returned 1753 10/03 10:13:17 [ERROR] Failed to install to Directory Service (1753)06/20 16:41:27 [INFO] Error - The initial LDAP connection to server FQDNServerName failed. (58) 06/20 16:41:27 [INFO] NtdsInstall for servername.domainname.com. returned 58 06/20 16:41:27 [INFO] DsRolepInstallDs returned 58 06/20 16:41:27 [ERROR] Failed to install the directory service (58) 06/21 11:49:57 [INFO] Error - The Directory Service failed to replicate the partition CN=Schema,CN=Configuration,DC=... (1722) 06/21 11:49:59 [INFO] NtdsInstall for servername.domainname.com. returned 1722 06/21 11:49:59 [INFO] DsRolepInstallDs returned 1722 06/21 11:49:59 [ERROR] Failed to install the directory service (1722) 06/21 17:08:41 [INFO] NtdsInstall for servername.domainname.com. returned 1753 06/21 17:08:41 [INFO] DsRolepInstallDs returned 1753 06/21 17:08:41 [ERROR] Failed to install the directory service (1753)
Note These error codes represent the following:
Additionally, the DCPromoUI.log may report an error message that is similar to the following:dcpromoui t:0x0C4 01335 Enter State::SetFailureMessage The operation failed because: The Directory Service failed to create the object CN= Name,CN=Partitions,CN=Configuration,DC= Domainname,DC= com.
Back to the top
The Active Directory Migration Tool (ADMT) may generate events that are similar to the following in the Event Viewer on the computer where the ADMT is run:
Event ID: 1540
Event Source: NTDS Replication
Description: Error 1753, DSID 11a05b1, adding SID to object ?.
The log from Clonepr.vbs from %windir%\debug appears as follows:
clonepr t:0x5CC 00254 HRESULT = 0x800706D9 clonepr t:0x5CC 00255 Enter GetErrorMessage 800706D9 clonepr t:0x5CC 00256 Exit GetErrorMessage 800706D9 clonepr t:0x5CC 00257 Enter SetComError Failed to add the source SID to the destination object's SID history. The error was: "There are no more endpoints available from the endpoint mapper. " clonepr t:0x5CC 00258 Exit SetComError Failed to add the source SID to the destination object's SID history. The error was: "There are no more endpoints available from the endpoint mapper. "
Important This section, method, or task contains steps that tell you how to modify the registry. However, serious problems might occur if you modify the registry incorrectly. Therefore, make sure that you follow these steps carefully. For added protection, back up the registry before you modify it. Then, you can restore the registry if a problem occurs. For more information about how to back up and restore the registry, click the following article number to view the article in the Microsoft Knowledge Base: 322756 (http://support.microsoft.com/kb/322756/ ) How to back up and restore the registry in Windows
The "No more endpoints available" error message means the RPC Endpoint Mapper was not able to use a port greater than 1024 for a service that runs over RPC.
Note RPC Endpoint Mapper runs on port 135.
RPC can use ports up to 65535. By default, all versions of Windows use only ports 1024-5000. To repair the RPC Endpoint Mapper, follow these steps:
| Type of computer | RPC service | RPC Locator service |
| Windows Server 2003-based domain controller | Started, Automatic | Stopped, Manual |
| Windows Server 2003-based member server | Started, Automatic | Stopped, Manual |
| Windows Server 2003-based standalone server | Started, Automatic | Stopped, Manual |
| Windows 2000 Server-based domain controller | Started, Automatic | Started, Automatic |
| Windows 2000 Server-based member server | Started, Automatic | Started, Manual |
| Windows 2000 Server-based standalone server | Started, Automatic | Stopped, Manual |
| Name | Type | Data |
| ncacn_http | REG_SZ | rpcrt4.dll |
| ncacn_ip_tcp | REG_SZ | rpcrt4.dll |
| ncacn_nb_tcp | REG_SZ | rpcrt4.dll |
| ncacn_np | REG_SZ | rpcrt4.dll |
| ncacn_ip_udp | REG_SZ | rpcrt4.dll |
| Name | Type | Data |
| ncacn_np | REG_SZ | rpcltcl.dll |
| ncalrpc | REG_SZ | ncalrpc |
| ncacn_ip_tcp | REG_SZ | RpcLtCcm.dll |
| ncadg_ip_udp | REG_SZ | RpcLtCcm.dll |
| ncadg_nb_tcp | REG_SZ | rpcltccm.dll |
| ncacn_http | REG_SZ | rpcltccm.dll |
| Name | Type | Data |
| ncacn_np | REG_SZ | rpcltcl.dll |
| ncalrpc | REG_SZ | ncalrpc |
| ncacn_ip_tcp | REG_SZ | rpcltc3.dll |
| ncacn_http | REG_SZ | rpcltccm.dll |
Querying target system called: problem_serverAttempting to resolve name to IP address... Name resolved to 169.254.1.1 querying... problem_serverTCP port 135 (epmap service): LISTENING Using ephemeral source port Querying Endpoint Mapper Database... Server's response: UUID: f5cc59b4-4264-101a-8c59-08002b2f8426 NtFrs Service ncacn_ip_tcp:65.53.63.16[1094] UUID: e3514235-4b06-11d1-ab04-00c04fc2dcd2 MS NT Directory DRS Interface ncacn_ip_tcp:65.53.63.16[1025] UUID: e3514235-4b06-11d1-ab04-00c04fc2dcd2 MS NT Directory DRS Interface ncacn_http:65.53.63.16[1029] UUID: e3514235-4b06-11d1-ab04-00c04fc2dcd2 MS NT Directory DRS Interface ncacn_http:65.53.63.16[6004]
TCP port 135 (epmap service): NOT LISTENING
Note Other software programs may also cause RPC Endpoint Mapper errors, such as the following:
Note If you do not want to continue troubleshooting, you might want to ask someone for help.Or, you might want to Contact Support (http://support.microsoft.com/contactus) .
Back to the top
For more information about configuring RPC dynamic port allocation with a firewall, click the following article number to view the article in the Microsoft Knowledge Base: 154596 (http://support.microsoft.com/kb/154596/ ) How to configure RPC dynamic port allocation to work with firewall
For more information about restricting the port FRS or Active Directory replication uses, click the following article number to view the article in the Microsoft Knowledge Base: 224196 (http://support.microsoft.com/kb/224196/ ) Restricting Active Directory replication traffic and client RPC traffic to a specific port
For more information about How to restricting FRS replication traffic to a static port, click the following article number to view the article in the Microsoft Knowledge Base: 319553 (http://support.microsoft.com/kb/319553/ ) How to restrict FRS replication traffic to a specific static port
For more information about port requirements for Windows Server systems, click the following article number to view the article in the Microsoft Knowledge Base: 832017 (http://support.microsoft.com/kb/832017/ ) Service overview and network port requirements for the Windows Server system
The third-party products that this article discusses are manufactured by companies that are independent of Microsoft. Microsoft makes no warranty, implied or otherwise, regarding the performance or reliability of these products.
If these articles do not help you resolve the problem, or if you experience symptoms that differ from those that are described in this article, search the Microsoft Knowledge Base for more information. To search the Microsoft Knowledge Base, visit the following Microsoft Web site: http://support.microsoft.com (http://support.microsoft.com/) . Then, type the text of the error message that you receive or type a description of the problem in the search field.
Back to the top Note This is a "FAST PUBLISH" article created directly from within the Microsoft support organization. The information contained herein is provided as-is in response to emerging issues. As a result of the speed in making it available, the materials may include typographical errors and may be revised at any time without notice. See Terms of Use (http://go.microsoft.com/fwlink/?LinkId=151500) for other considerations.
Back to the top

Article ID:
839880
Last Review:
July 2, 2010 - Revision: 13.0
| ADDITIONAL RESOURCES | ||||||||
|---|---|---|---|---|---|---|---|---|
|
||||||||
| Community | ||||||||
|