Link to home
Start Free TrialLog in
Avatar of fcourtaud
fcourtaudFlag for France

asked on

NTDS KCC event Id 1311

Hello experts,

We have a DC (PDCETRELLES) on one site that is not global catalog owner, AD is replicated with another DC (PDCHYDRA) located on another site.
Last monday a ntp error occured and the date on server PDCETRELLES was changed to 2001-01-01.
Before the date problem was fixed a replication occurred.
Since then replication does not work any longer.

In the PDCETRELLES logs we have
 - error : NTDS KCC event Id 1311
 - warning : NTDS KCC event Id 1865
 - error : Kerberos Event Id 4 --> Le client Kerberos a reçu une erreur KRB_AP_ERR_MODIFIED du serveur host/pdchydra.hydrachim.fr.

Last night I tried to reset the secure channel by disabling kdc, using netdom /resetpwd and rebooting. It did not solve my problem.

Any idea ?

Below are the results of dcdiag end netdiag

DCDIAG
-------------------------------------
Domain Controller Diagnosis

Performing initial setup:
   Done gathering initial info.

Doing initial required tests

   Testing server: Etrelles\PDCETRELLES
      Starting test: Connectivity
         ......................... PDCETRELLES passed test Connectivity

Doing primary tests

   Testing server: Etrelles\PDCETRELLES
      Starting test: Replications
         [Replications Check,PDCETRELLES] A recent replication attempt failed:
            From PDCHYDRA to PDCETRELLES
            Naming Context: DC=ForestDnsZones,DC=hydrachim,DC=fr
            The replication generated an error (1256):
            Le système distant n'est pas disponible. Pour obtenir des informatio
ns à propos du dépannage réseau, consulter l'Aide Windows.
            The failure occurred at 2008-10-31 06:54:15.
            The last success occurred at 2008-10-13 05:47:02.
            120 failures have occurred since the last success.
         [Replications Check,PDCETRELLES] A recent replication attempt failed:
            From PDCHYDRA to PDCETRELLES
            Naming Context: DC=DomainDnsZones,DC=hydrachim,DC=fr
            The replication generated an error (1256):
            Le système distant n'est pas disponible. Pour obtenir des informatio
ns à propos du dépannage réseau, consulter l'Aide Windows.
            The failure occurred at 2008-10-31 06:54:15.
            The last success occurred at 2008-10-13 05:47:02.
            120 failures have occurred since the last success.
         [Replications Check,PDCETRELLES] A recent replication attempt failed:
            From PDCHYDRA to PDCETRELLES
            Naming Context: CN=Schema,CN=Configuration,DC=hydrachim,DC=fr
            The replication generated an error (-2146893022):
            Le nom principal de la cible n'est pas correct.
            The failure occurred at 2008-10-31 06:54:15.
            The last success occurred at 2000-10-13 08:14:57.
            119 failures have occurred since the last success.
         [Replications Check,PDCETRELLES] A recent replication attempt failed:
            From PDCHYDRA to PDCETRELLES
            Naming Context: CN=Configuration,DC=hydrachim,DC=fr
            The replication generated an error (-2146893022):
            Le nom principal de la cible n'est pas correct.
            The failure occurred at 2008-10-31 06:54:15.
            The last success occurred at 2008-10-13 05:47:02.
            120 failures have occurred since the last success.
         [Replications Check,PDCETRELLES] A recent replication attempt failed:
            From PDCHYDRA to PDCETRELLES
            Naming Context: DC=hydrachim,DC=fr
            The replication generated an error (-2146893022):
            Le nom principal de la cible n'est pas correct.
            The failure occurred at 2008-10-31 06:54:15.
            The last success occurred at 2000-10-13 08:14:57.
            119 failures have occurred since the last success.
         REPLICATION-RECEIVED LATENCY WARNING
         PDCETRELLES:  Current time is 2008-10-31 09:43:42.
            DC=ForestDnsZones,DC=hydrachim,DC=fr
               Last replication recieved from PDCHYDRA at 2008-10-13 05:47:02.
            DC=DomainDnsZones,DC=hydrachim,DC=fr
               Last replication recieved from PDCHYDRA at 2008-10-13 05:47:02.
            CN=Schema,CN=Configuration,DC=hydrachim,DC=fr
               Last replication recieved from PDCHYDRA at 2000-10-13 08:14:57.
               WARNING:  This latency is over the Tombstone Lifetime of 60 days!

            CN=Configuration,DC=hydrachim,DC=fr
               Last replication recieved from PDCHYDRA at 2008-10-15 22:55:54.
            DC=hydrachim,DC=fr
               Last replication recieved from PDCHYDRA at 2000-10-13 08:14:57.
               WARNING:  This latency is over the Tombstone Lifetime of 60 days!

         ......................... PDCETRELLES passed test Replications
      Starting test: NCSecDesc
         ......................... PDCETRELLES passed test NCSecDesc
      Starting test: NetLogons
         ......................... PDCETRELLES passed test NetLogons
      Starting test: Advertising
         ......................... PDCETRELLES passed test Advertising
      Starting test: KnowsOfRoleHolders
         [PDCHYDRA] DsBindWithSpnEx() failed with error -2146893022,
         Le nom principal de la cible n'est pas correct..
         Warning: PDCHYDRA is the Schema Owner, but is not responding to DS RPC
Bind.
         [PDCHYDRA] LDAP bind failed with error 8341,
         Une erreur de service d'annuaire s'est produite..
         Warning: PDCHYDRA is the Schema Owner, but is not responding to LDAP Bi
nd.
         Warning: PDCHYDRA is the Domain Owner, but is not responding to DS RPC
Bind.
         Warning: PDCHYDRA is the Domain Owner, but is not responding to LDAP Bi
nd.
         Warning: PDCHYDRA is the PDC Owner, but is not responding to DS RPC Bin
d.
         Warning: PDCHYDRA is the PDC Owner, but is not responding to LDAP Bind.

         Warning: PDCHYDRA is the Rid Owner, but is not responding to DS RPC Bin
d.
         Warning: PDCHYDRA is the Rid Owner, but is not responding to LDAP Bind.

         Warning: PDCHYDRA is the Infrastructure Update Owner, but is not respon
ding to DS RPC Bind.
         Warning: PDCHYDRA is the Infrastructure Update Owner, but is not respon
ding to LDAP Bind.
         ......................... PDCETRELLES failed test KnowsOfRoleHolders
      Starting test: RidManager
         ......................... PDCETRELLES failed test RidManager
      Starting test: MachineAccount
         * The current DC is not in the domain controller's OU
         ......................... PDCETRELLES failed test MachineAccount
      Starting test: Services
         ......................... PDCETRELLES passed test Services
      Starting test: ObjectsReplicated
         ......................... PDCETRELLES passed test ObjectsReplicated
      Starting test: frssysvol
         ......................... PDCETRELLES passed test frssysvol
      Starting test: frsevent
         There are warning or error events within the last 24 hours after the
         SYSVOL has been shared.  Failing SYSVOL replication problems may cause
         Group Policy problems.
         ......................... PDCETRELLES failed test frsevent
      Starting test: kccevent
         An Warning Event occured.  EventID: 0x8000061E
            Time Generated: 10/31/2008   09:29:21
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0xC000051F
            Time Generated: 10/31/2008   09:29:21
            (Event String could not be retrieved)
         An Warning Event occured.  EventID: 0x80000749
            Time Generated: 10/31/2008   09:29:21
            (Event String could not be retrieved)
         An Warning Event occured.  EventID: 0x8000061E
            Time Generated: 10/31/2008   09:29:21
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0xC000051F
            Time Generated: 10/31/2008   09:29:21
            (Event String could not be retrieved)
         An Warning Event occured.  EventID: 0x80000749
            Time Generated: 10/31/2008   09:29:21
            (Event String could not be retrieved)
         An Warning Event occured.  EventID: 0x8000061E
            Time Generated: 10/31/2008   09:29:21
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0xC000051F
            Time Generated: 10/31/2008   09:29:21
            (Event String could not be retrieved)
         An Warning Event occured.  EventID: 0x80000749
            Time Generated: 10/31/2008   09:29:21
            (Event String could not be retrieved)
         An Warning Event occured.  EventID: 0x8000061E
            Time Generated: 10/31/2008   09:29:21
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0xC000051F
            Time Generated: 10/31/2008   09:29:21
            (Event String could not be retrieved)
         An Warning Event occured.  EventID: 0x80000749
            Time Generated: 10/31/2008   09:29:21
            (Event String could not be retrieved)
         ......................... PDCETRELLES failed test kccevent
      Starting test: systemlog
         An Error Event occured.  EventID: 0x40000004
            Time Generated: 10/31/2008   09:14:09
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x40000004
            Time Generated: 10/31/2008   09:27:38
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x40000004
            Time Generated: 10/31/2008   09:35:16
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x40000004
            Time Generated: 10/31/2008   09:43:43
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0x40000004
            Time Generated: 10/31/2008   09:43:43
            (Event String could not be retrieved)
         ......................... PDCETRELLES failed test systemlog
      Starting test: VerifyReferences
         ......................... PDCETRELLES passed test VerifyReferences

   Running partition tests on : ForestDnsZones
      Starting test: CrossRefValidation
         ......................... ForestDnsZones passed test CrossRefValidation

      Starting test: CheckSDRefDom
         ......................... ForestDnsZones passed test CheckSDRefDom

   Running partition tests on : DomainDnsZones
      Starting test: CrossRefValidation
         ......................... DomainDnsZones passed test CrossRefValidation

      Starting test: CheckSDRefDom
         ......................... DomainDnsZones passed test CheckSDRefDom

   Running partition tests on : Schema
      Starting test: CrossRefValidation
         ......................... Schema passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... Schema passed test CheckSDRefDom

   Running partition tests on : Configuration
      Starting test: CrossRefValidation
         ......................... Configuration passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... Configuration passed test CheckSDRefDom

   Running partition tests on : hydrachim
      Starting test: CrossRefValidation
         ......................... hydrachim passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... hydrachim passed test CheckSDRefDom

   Running enterprise tests on : hydrachim.fr
      Starting test: Intersite
         ......................... hydrachim.fr passed test Intersite
      Starting test: FsmoCheck
         ......................... hydrachim.fr passed test FsmoCheck

--------------------------------------------------------------------------------------
NETDIAG


    Computer Name: PDCETRELLES
    DNS Host Name: pdcetrelles.hydrachim.fr
    System info : Microsoft Windows Server 2003 R2 (Build 3790)
    Processor : x86 Family 15 Model 2 Stepping 5, GenuineIntel
    List of installed hotfixes :
        KB909520
        KB921503
        KB925398_WMP64
        KB925902
        KB926122
        KB927891
        KB928090-IE7
        KB929123
        KB929969
        KB930178
        KB931768-IE7
        KB931784
        KB931836
        KB932168
        KB933360
        KB933566-IE7
        KB933729
        KB933854
        KB935839
        KB935840
        KB935966
        KB936021
        KB936357
        KB936782
        KB937143-IE7
        KB938127-IE7
        KB938464
        KB939653-IE7
        KB941202
        KB941568
        KB941569
        KB941644
        KB941672
        KB941693
        KB942615-IE7
        KB942763
        KB942830
        KB942831
        KB943055
        KB943460
        KB943484
        KB943485
        KB944533-IE7
        KB944653
        KB945553
        KB946026
        KB947864-IE7
        KB948496
        KB948590
        KB948881
        KB949014
        KB950759-IE7
        KB950760
        KB950762
        KB950974
        KB951066
        KB951072-v2
        KB951698
        KB951746
        KB951748
        KB952954
        KB953838-IE7
        KB953839
        KB954211
        KB956390-IE7
        KB956391
        KB956803
        KB956841
        KB957095
        KB958644
        Q147222


Netcard queries test . . . . . . . : Passed
    GetStats failed for 'ParallÞle direct'. [ERROR_NOT_SUPPORTED]
    [WARNING] The net card 'Miniport rÚseau Útendu WAN (PPTP)' may not be workin
g because it has not received any packets.
    [WARNING] The net card 'Miniport WAN (PPPOE)' may not be working because it
has not received any packets.
    [WARNING] The net card 'Miniport WAN (IP)' may not be working because it has
 not received any packets.
    [WARNING] The net card 'Miniport rÚseau Útendu (AppleTalk)' may not be worki
ng because it has not received any packets.
    GetStats failed for 'Miniport rÚseau Útendu WAN (L2TP)'. [ERROR_NOT_SUPPORTE
D]



Per interface results:

    Adapter : Connexion au rÚseau local 2

        Netcard queries test . . . : Passed

        Host Name. . . . . . . . . : pdcetrelles
        IP Address . . . . . . . . : 192.168.2.1
        Subnet Mask. . . . . . . . : 255.255.255.0
        Default Gateway. . . . . . : 192.168.2.252
        Dns Servers. . . . . . . . : 192.168.2.1


        AutoConfiguration results. . . . . . : Passed

        Default gateway test . . . : Passed

        NetBT name test. . . . . . : Passed
        [WARNING] At least one of the <00> 'WorkStation Service', <03> 'Messenge
r Service', <20> 'WINS' names is missing.

        WINS service test. . . . . : Skipped
            There are no WINS servers configured for this interface.


Global results:


Domain membership test . . . . . . : Passed


NetBT transports test. . . . . . . : Passed
    List of NetBt transports currently configured:
        NetBT_Tcpip_{68C91627-7154-4A0C-9299-6911F4A3D977}
    1 NetBt transport currently configured.


Autonet address test . . . . . . . : Passed


IP loopback ping test. . . . . . . : Passed


Default gateway test . . . . . . . : Passed


NetBT name test. . . . . . . . . . : Passed
    [WARNING] You don't have a single interface with the <00> 'WorkStation Servi
ce', <03> 'Messenger Service', <20> 'WINS' names defined.


Winsock test . . . . . . . . . . . : Passed


DNS test . . . . . . . . . . . . . : Passed
    PASS - All the DNS entries for DC are registered on DNS server '192.168.2.1'
 and other DCs also have some of the names registered.


Redir and Browser test . . . . . . : Passed
    List of NetBt transports currently bound to the Redir
        NetBT_Tcpip_{68C91627-7154-4A0C-9299-6911F4A3D977}
    The redir is bound to 1 NetBt transport.

    List of NetBt transports currently bound to the browser
        NetBT_Tcpip_{68C91627-7154-4A0C-9299-6911F4A3D977}
    The browser is bound to 1 NetBt transport.


DC discovery test. . . . . . . . . : Passed


DC list test . . . . . . . . . . . : Passed


Trust relationship test. . . . . . : Passed
    Secure channel for domain 'HYDRACHIM' is to '\\pdchydra.hydrachim.fr'.


Kerberos test. . . . . . . . . . . : Passed


LDAP test. . . . . . . . . . . . . : Passed
    [WARNING] Failed to query SPN registration on DC 'pdchydra.hydrachim.fr'.


Bindings test. . . . . . . . . . . : Passed


WAN configuration test . . . . . . : Skipped
    No active remote access connections.


Modem diagnostics test . . . . . . : Passed

IP Security test . . . . . . . . . : Skipped

    Note: run "netsh ipsec dynamic show /?" for more detailed information


The command completed successfully
SOLUTION
Avatar of Dusan_Bajic
Dusan_Bajic
Flag of Serbia image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
ASKER CERTIFIED SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Actually, few  months ago I had almost the same problem as yours. Procedure I suggested is recommended by Microsoft (among many others) and it did not help me. At the end, I did the same thing as you.