Hi,
We are currently migrating the exchange infrastructure from Exchange 2003 to Exchange 2010 SP3. Unfortunately the domain controllers are still on Server 2003 SP2, and it is not possible to upgrade/replace the domain controllers (yet).
The problem we are experiencing is that since the user migrations have started there has been an increased number of random domain controller unplanned reboots. These occur immediately after some LDAP/AD communication with the new Exchange Servers.
The first sign of trouble is this message:
Event Type: Warning Event Source: NTDS General Event Category: Internal Processing Event ID: 1173 Date: 01/04/2016 Time: 10:22:21User: DOMAIN\EXCHANGESERVER2010$ Computer: DOMAINCONTROLLER2K3 Description: Internal event: Active Directory has encountered the following exception and associated parameters. Exception: c0000005 Parameter: 0 Additional Data Error value: 7c82a75f Internal ID: 0
this is then shortly followed by:
Event Type: Error Event Source: Winlogon Event Category: None Event ID: 1015 Date: 01/04/2016 Time: 10:22:58 User: N/A Computer: DOMAINCONTROLLER2K3 Description: A critical system process, C:\WINDOWS\system32\lsass.exe, failed with status code c0000005.
The machine must now be restarted. For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
I increased the logging of the NETLOGON service but there is nothing of any note from the exchange server prior to the exception. Once the domain controller restarts, the issue is then repeated on the next domain controller in the site, and then in some cases the PDC is then also affected as the Exchange Server connects to each in turn.
Admins also often receive a watson report message when logging onto the server:
HeaderText=LSA Shell encountered a problem and needed to close.
The versions are:
Exchange: Exchange 2010 SP3 RU12
DC: Windows Server 2003 SP2
lsass.exe version 5.2.3790.0 (srv03_rtm.030324-2048)
I appreciate Server 2003 is no longer in support however any advice, or known hotfixes would be appreciated (other than upgrade your domain controller).