• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 303
  • Last Modified:

KDC 11 single-lable domain

Hi,

I'm getting serveral instances of this event daily.

I have researched the matter here and elsewhere.
Basically everyone says to look up the double SPN and remove the unnecessary instance of it.
http://support.microsoft.com/kb/321044

I have done this but the error is stil logged.
I didn't have doulbe instances of the same name, but the admin and admin2 accounts had the same SPN as the server.

Event Type:      Error
Event Source:      KDC
Event Category:      None
Event ID:      11
Date:            08-11-06
Time:            10:34:46
User:            N/A
Computer:      <Servername>
Description:
There are multiple accounts with name MSSQLSvc/<servername>.<Domain>:2388 of type 10.

Event Type:      Error
Event Source:      KDC
Event Category:      None
Event ID:      11
Date:            08-11-06
Time:            10:33:59
User:            N/A
Computer:      <Servername>
Description:
There are multiple accounts with name MSSQLSvc/<SERVERNAME>.<Domain>:2388 of type 10.

I also tried ntdsutil / security account manager / check duplitace SIDs at the command prompt.
None were found.

This maybe completely irrelavant but ,<Servername> is in capitals in one error and in lowercase the next.
Is this some kind of unknown issue with having a single-label domain name??

Any idea's ?
How I can find the double name?

Cheers

0
DennisPost
Asked:
DennisPost
  • 2
  • 2
1 Solution
 
Nirmal SharmaSolution ArchitectCommented:
Did you restart the server?
0
 
DennisPostAuthor Commented:
Ha ha, that would have been quick points for you! :-)
But yeah, many times.
I've also check the service accounts for MSSQLServer & ServerAgent, both run under the local system account.
0
 
Nirmal SharmaSolution ArchitectCommented:
Would you mind sharing the solution please? I don't that single label domain generates these errors.

Thanks!
0
 
DennisPostAuthor Commented:
Sure.

MS KB 321044 gives 2 methods of finding the duplicate SPN name.
The first method is using LPD. This method didn't return anything  (Single label domain problem??)

Method 2 uses ldifde.
MS says type : ldifde -f domain.txt DNDomain (I took DNDomain literally)

After changing DNDomain to DC=<Domain> (No .com or anything after it) I finally got the output
text working. Searched and found 2 items with the double SPN. One being the enterprise admin account, the DC machine name.

I figured out how to found and remove the admin spn using ADSIEdit.

Pretty much as the KB says really....

Since then no more problems. Well at least no more KDC 11 events.

0
 
DarthModCommented:
PAQd, 250 points refunded.

DarthMod
CS Moderator
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Free Tool: IP Lookup

Get more info about an IP address or domain name, such as organization, abuse contacts and geolocation.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

  • 2
  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now