| Previous | Next |
| MQ_ERROR_CANNOT_JOIN_DOMAIN | MQ_ERROR_GUID_NOT_MATCHING |
MQ_ERROR_CANNOT_CREATE_ON_GC
Interpretation
Applications should keep MQ_ERROR_CANNOT_CREATE_ON_GC attached to the exact MSMQ call that produced it; translating it immediately to “queue error” discards the diagnostic boundary. Its diagnostic boundary is write attempted against a global catalog endpoint. A GC is primarily used for forest-wide search and may not accept the requested object creation in that context.
For MQ_ERROR_CANNOT_CREATE_ON_GC, global catalog searches and writes to a writable domain naming context have different capabilities. When diagnosing MQ_ERROR_CANNOT_CREATE_ON_GC, record whether the operation was discovery, read, create, update, or delete before choosing a domain controller.
When diagnosing MQ_ERROR_CANNOT_CREATE_ON_GC, MSMQ uses directory services for public queues, machine configuration, security metadata, routing, aliases, and related enterprise objects. In the MQ_ERROR_CANNOT_CREATE_ON_GC path, private/direct queue operation can therefore succeed while a directory-dependent action fails.
Relevant API contract
| Subsystem | MSMQ integration with Active Directory Domain Services and the global catalog |
|---|---|
| Decisive boundary | public queue metadata and MSMQ configuration objects depend on directory reachability, schema, class, ownership, and domain credentials |
| Code-specific focus | write attempted against a global catalog endpoint |
| Primary recovery rule | Target a writable domain controller for the object’s naming context. |
When diagnosing MQ_ERROR_CANNOT_CREATE_ON_GC, A queue can exist locally while its public registration or MSMQ configuration object is absent, stale, wrong-class, or visible only on some domain controllers. For MQ_ERROR_CANNOT_CREATE_ON_GC, the code-specific boundary is write attempted against a global catalog endpoint.
Decisive observations
- Dns and ldap reachability plus the distinguished name being accessed; associate it explicitly with
MQ_ERROR_CANNOT_CREATE_ON_GC. - When diagnosing
MQ_ERROR_CANNOT_CREATE_ON_GC, the directory object class, guid, owner, and replication state; capture the value before cleanup or retry changes it. - In the
MQ_ERROR_CANNOT_CREATE_ON_GCpath, domain/workgroup mode, forest and domain names, and selected domain controller; compare it with a known-good call using the same account and queue type. - For this
MQ_ERROR_CANNOT_CREATE_ON_GCresult, record the queue path or format name, local/remote placement, transactional flag, caller SID, process build, and UTC correlation ID when they apply.
For MQ_ERROR_CANNOT_CREATE_ON_GC, log certificate thumbprints, provider names, SIDs, GUIDs, lengths, and hashes where useful, but do not log private keys, symmetric keys, credentials, or confidential message bodies.
Troubleshooting workflow
- Record the unsigned HRESULT,
MQ_ERROR_CANNOT_CREATE_ON_GC, and the native API or COM method before a framework replaces it with a generic exception. - When diagnosing
MQ_ERROR_CANNOT_CREATE_ON_GC, verify the postcondition after the failed call: queue existence, message presence, directory object state, transaction outcome, or generated output may differ by result. - In the
MQ_ERROR_CANNOT_CREATE_ON_GCpath, capture DNS and LDAP reachability plus the distinguished name being accessed. - For this
MQ_ERROR_CANNOT_CREATE_ON_GCresult, capture the directory object class, GUID, owner, and replication state. - Reproduce with the smallest queue/message/property set that still returns
MQ_ERROR_CANNOT_CREATE_ON_GC; change one precondition at a time. - When diagnosing
MQ_ERROR_CANNOT_CREATE_ON_GC, apply the code-specific recovery rule: Target a writable domain controller for the object’s naming context.
Recovery rules
Target a writable domain controller for the object’s naming context.
When diagnosing MQ_ERROR_CANNOT_CREATE_ON_GC, the retry decision must account for side effects that may already exist. In the MQ_ERROR_CANNOT_CREATE_ON_GC path, query queue, message, directory, or transaction state first whenever the result leaves completion uncertain.
Differences that matter
In the MQ_ERROR_CANNOT_CREATE_ON_GC path, local private-queue success does not prove that public-queue registration, global catalog discovery, or the required AD DS object is healthy. The specific focus for MQ_ERROR_CANNOT_CREATE_ON_GC remains write attempted against a global catalog endpoint.
- In the
MQ_ERROR_CANNOT_CREATE_ON_GCpath, changing queue names, deleting directory objects, or recreating certificates without reconciliation can create a second object while callers still reference the first. - For this
MQ_ERROR_CANNOT_CREATE_ON_GCresult, A successful test under an interactive administrator account does not prove that the production service account has the same profile, token, directory access, or key permissions.
Practical scenario
A public-queue discovery service encounters MQ_ERROR_CANNOT_CREATE_ON_GC. For MQ_ERROR_CANNOT_CREATE_ON_GC, it compares DNS, LDAP bind, object class, and replication on the exact domain controller used by MSMQ. When diagnosing MQ_ERROR_CANNOT_CREATE_ON_GC, the acceptance test then changes only the decisive precondition and confirms both the HRESULT and the actual queue/message state.
For MQ_ERROR_CANNOT_CREATE_ON_GC, include a negative test for the nearest misleading diagnosis so monitoring and user guidance do not collapse distinct MSMQ failures into one alert.
Sources
- IETF RFC 4511: LDAP protocol — source used for the
MQ_ERROR_CANNOT_CREATE_ON_GCanalysis. - Microsoft: destination queues — source used for the
MQ_ERROR_CANNOT_CREATE_ON_GCanalysis. - Microsoft: Message Queuing error and information codes — source used for the
MQ_ERROR_CANNOT_CREATE_ON_GCanalysis. - Microsoft Open Specifications: MSMQ and directory services — source used for the
MQ_ERROR_CANNOT_CREATE_ON_GCanalysis. - Microsoft Open Specifications: MSMQ protocols overview — source used for the
MQ_ERROR_CANNOT_CREATE_ON_GCanalysis.
Looking for a different code? Search another status or error code.