Kerberos error - EventID 4 on 1 server in forest
 




IT Certification FAQ

 
|
Home
|
Microsoft
|
CISCO
|
CompTIA
|
Exam/Study FAQ
|
Employment FAQ
| Links  | Forums  |
Book Reviews


FAQFAQ  SearchSearch  MemberlistMemberlist  UsergroupsUsergroups  RegisterRegister  ProfileProfile  Log in to check your private messagesPrivate messages  Log inLog in

Kerberos error - EventID 4 on 1 server in forest

 
Post new topic   Reply to topic    Forum Index -> microsoft.public.windows.server.active_directory
Author Message
Torsten
Guest





PostPosted: Thu May 18, 2006 3:15 pm    Post subject: Kerberos error - EventID 4 on 1 server in forest Reply with quote

"The kerberos client received a KRB_AP_ERR_MODIFIED error from the server
host/ADM1.loca1.deso1.com The target name used was
ldap/ADM2.loca1.deso1.com. This indicates that the password used to encrypt
the kerberos service ticket is different than that on the target server.
Commonly, this is due to identically named machine accounts in the target
realm (LOCA1.DESO1.COM), and the client realm. Please contact your system
administrator."

Does anybody can tell me, what I have to do on this DC.
Back to top
Paul Williams [MVP]
Guest





PostPosted: Thu May 18, 2006 4:45 pm    Post subject: Re: Kerberos error - EventID 4 on 1 server in forest Reply with quote

Looks like you are trying to access ADM1 with the hostname ADM2. If you
want to achieve this, Google strictnamechecking.

--
Paul Williams
Microsoft MVP - Windows Server - Directory Services
http://www.msresource.net | http://forums.msresource.net
Back to top
Torsten
Guest





PostPosted: Thu May 18, 2006 5:46 pm    Post subject: Re: Kerberos error - EventID 4 on 1 server in forest Reply with quote

Oh, sorry. It must be:

"The kerberos client received a KRB_AP_ERR_MODIFIED error from the server
host/ADM1.loca1.deso1.com The target name used was
ldap/ADM1.loca1.deso1.com. This indicates that the password used to encrypt
the kerberos service ticket is different than that on the target server.
Commonly, this is due to identically named machine accounts in the target
realm (LOCA1.DESO1.COM), and the client realm. Please contact your system
administrator."


"Paul Williams [MVP]" schrieb:

Quote:
Looks like you are trying to access ADM1 with the hostname ADM2. If you
want to achieve this, Google strictnamechecking.

--
Paul Williams
Microsoft MVP - Windows Server - Directory Services
http://www.msresource.net | http://forums.msresource.net


Back to top
Jorge Silva
Guest





PostPosted: Fri May 19, 2006 1:53 am    Post subject: Re: Kerberos error - EventID 4 on 1 server in forest Reply with quote

Hi

Possible Causes and Resolutions
Some encrypted Kerberos authentication data sent by the client did not
decrypt properly at the server because:

. A service ticket is issued to the local computer account, for which
a host/ SPN is automatically created, instead of to the service account, for
which no SPN has been created. The reason for this is that a service does
not register an SPN for itself, yet the service belongs to a service class
for which the computer will automatically map the SPN to a host/service
class. (Examples of this are the HTTP and Common Internet File System (CIFS)
service classes.) The result is that the service cannot decrypt the
resultant ticket.

Resolution

If the root cause appears to be that an SPN has not been set, verify
that each service running on the target computer has an SPN set. Those
services that do not have SPNs set might have had their SPNs remapped to the
computer's host SPN. For more information about SPNs and how to set them,
see Need an SPN Set earlier in this white paper.

. The authentication data was encrypted with the wrong key for the
intended server.

. The authentication data was modified in transit by a hardware or
software error, or by an attacker.

. The client sent the authentication data to the wrong server because
incorrect DNS data caused the client to send the request to the wrong
server.

Resolution


Verify that DNS is functioning properly.

. The client sent the authentication data to the wrong server because
DNS data was out-of-date on the client.

Resolution

Verify that DNS is functioning properly.

. Two computers in different domains have the same name and the client
sent the authentication data to the wrong computer.

Resolution

Verify that there are not multiple computers with the same name,
including NetBIOS names, anywhere on the network.



--
I hop that helps

Good Luck
Jorge Silva
MCSA
Systems Administrator





"Torsten" <Torsten@discussions.microsoft.com> wrote in message
news:E0166CE6-8F83-4236-BFC3-F95604116226@microsoft.com...
Quote:
Oh, sorry. It must be:

"The kerberos client received a KRB_AP_ERR_MODIFIED error from the server
host/ADM1.loca1.deso1.com The target name used was
ldap/ADM1.loca1.deso1.com. This indicates that the password used to
encrypt
the kerberos service ticket is different than that on the target server.
Commonly, this is due to identically named machine accounts in the target
realm (LOCA1.DESO1.COM), and the client realm. Please contact your
system
administrator."


"Paul Williams [MVP]" schrieb:

Looks like you are trying to access ADM1 with the hostname ADM2. If you
want to achieve this, Google strictnamechecking.

--
Paul Williams
Microsoft MVP - Windows Server - Directory Services
http://www.msresource.net | http://forums.msresource.net


Back to top
Display posts from previous:   
Post new topic   Reply to topic    Forum Index -> microsoft.public.windows.server.active_directory All times are GMT
Page 1 of 1

 

Copyright © 2002-2006 Web-S-Sense Pty. Ltd. All rights reserved.

Powered by phpBB
Advertising | Policies/Disclaimers | Contact us | Link to us


Featured Sites: Free Antivirus and Antispyware Info | Free PC Support | MCSE Directory