What does HRESULT 0xC00E0077 (MQ_ERROR_CANNOT_CREATE_ON_GC) mean?

 
Previous Next
MQ_ERROR_CANNOT_JOIN_DOMAIN MQ_ERROR_GUID_NOT_MATCHING

MQ_ERROR_CANNOT_CREATE_ON_GC

Interpretation

Applications should keep MQ_ERROR_CANNOT_CREATE_ON_GC attached to the exact MSMQ call that produced it; translating it immediately to “queue error” discards the diagnostic boundary. Its diagnostic boundary is write attempted against a global catalog endpoint. A GC is primarily used for forest-wide search and may not accept the requested object creation in that context.

For MQ_ERROR_CANNOT_CREATE_ON_GC, global catalog searches and writes to a writable domain naming context have different capabilities. When diagnosing MQ_ERROR_CANNOT_CREATE_ON_GC, record whether the operation was discovery, read, create, update, or delete before choosing a domain controller.

When diagnosing MQ_ERROR_CANNOT_CREATE_ON_GC, MSMQ uses directory services for public queues, machine configuration, security metadata, routing, aliases, and related enterprise objects. In the MQ_ERROR_CANNOT_CREATE_ON_GC path, private/direct queue operation can therefore succeed while a directory-dependent action fails.

Relevant API contract

SubsystemMSMQ integration with Active Directory Domain Services and the global catalog
Decisive boundarypublic queue metadata and MSMQ configuration objects depend on directory reachability, schema, class, ownership, and domain credentials
Code-specific focuswrite attempted against a global catalog endpoint
Primary recovery ruleTarget a writable domain controller for the object’s naming context.

When diagnosing MQ_ERROR_CANNOT_CREATE_ON_GC, A queue can exist locally while its public registration or MSMQ configuration object is absent, stale, wrong-class, or visible only on some domain controllers. For MQ_ERROR_CANNOT_CREATE_ON_GC, the code-specific boundary is write attempted against a global catalog endpoint.

Decisive observations

  • Dns and ldap reachability plus the distinguished name being accessed; associate it explicitly with MQ_ERROR_CANNOT_CREATE_ON_GC.
  • When diagnosing MQ_ERROR_CANNOT_CREATE_ON_GC, the directory object class, guid, owner, and replication state; capture the value before cleanup or retry changes it.
  • In the MQ_ERROR_CANNOT_CREATE_ON_GC path, domain/workgroup mode, forest and domain names, and selected domain controller; compare it with a known-good call using the same account and queue type.
  • For this MQ_ERROR_CANNOT_CREATE_ON_GC result, record the queue path or format name, local/remote placement, transactional flag, caller SID, process build, and UTC correlation ID when they apply.

For MQ_ERROR_CANNOT_CREATE_ON_GC, log certificate thumbprints, provider names, SIDs, GUIDs, lengths, and hashes where useful, but do not log private keys, symmetric keys, credentials, or confidential message bodies.

Troubleshooting workflow

  1. Record the unsigned HRESULT, MQ_ERROR_CANNOT_CREATE_ON_GC, and the native API or COM method before a framework replaces it with a generic exception.
  2. When diagnosing MQ_ERROR_CANNOT_CREATE_ON_GC, verify the postcondition after the failed call: queue existence, message presence, directory object state, transaction outcome, or generated output may differ by result.
  3. In the MQ_ERROR_CANNOT_CREATE_ON_GC path, capture DNS and LDAP reachability plus the distinguished name being accessed.
  4. For this MQ_ERROR_CANNOT_CREATE_ON_GC result, capture the directory object class, GUID, owner, and replication state.
  5. Reproduce with the smallest queue/message/property set that still returns MQ_ERROR_CANNOT_CREATE_ON_GC; change one precondition at a time.
  6. When diagnosing MQ_ERROR_CANNOT_CREATE_ON_GC, apply the code-specific recovery rule: Target a writable domain controller for the object’s naming context.

Recovery rules

Target a writable domain controller for the object’s naming context.

When diagnosing MQ_ERROR_CANNOT_CREATE_ON_GC, the retry decision must account for side effects that may already exist. In the MQ_ERROR_CANNOT_CREATE_ON_GC path, query queue, message, directory, or transaction state first whenever the result leaves completion uncertain.

Differences that matter

In the MQ_ERROR_CANNOT_CREATE_ON_GC path, local private-queue success does not prove that public-queue registration, global catalog discovery, or the required AD DS object is healthy. The specific focus for MQ_ERROR_CANNOT_CREATE_ON_GC remains write attempted against a global catalog endpoint.

  • In the MQ_ERROR_CANNOT_CREATE_ON_GC path, changing queue names, deleting directory objects, or recreating certificates without reconciliation can create a second object while callers still reference the first.
  • For this MQ_ERROR_CANNOT_CREATE_ON_GC result, A successful test under an interactive administrator account does not prove that the production service account has the same profile, token, directory access, or key permissions.

Practical scenario

A public-queue discovery service encounters MQ_ERROR_CANNOT_CREATE_ON_GC. For MQ_ERROR_CANNOT_CREATE_ON_GC, it compares DNS, LDAP bind, object class, and replication on the exact domain controller used by MSMQ. When diagnosing MQ_ERROR_CANNOT_CREATE_ON_GC, the acceptance test then changes only the decisive precondition and confirms both the HRESULT and the actual queue/message state.

For MQ_ERROR_CANNOT_CREATE_ON_GC, include a negative test for the nearest misleading diagnosis so monitoring and user guidance do not collapse distinct MSMQ failures into one alert.

Sources


Looking for a different code? Search another status or error code.