Which account should I delete after finding duplicate SPN of MSSQLSvc/LPZ-Tickets.LowryParkZoo.com:1433

Posted on 2008-11-15
Medium Priority
Last Modified: 2012-05-05
Based on others I used the following command to export 2 entries:

ldifde -d dc=lowryparkzoo,dc=com -r "(serviceprincipalname=mssqlsvc/lpz-tickets*)" -l dn,serviceprincipalname -f CG.txt

Here are the results:

dn: CN=Administrator,CN=Users,DC=LowryParkZoo,DC=com
changetype: add
servicePrincipalName: MSSQLSvc/lpz-backup1.LowryParkZoo.com:1137
servicePrincipalName: MSSQLSvc/lpz-accounting.LowryParkZoo.com:1433
servicePrincipalName: MSSQLSvc/lpz-backup.LowryParkZoo.com:1511
servicePrincipalName: MSSQLSvc/lpz-tickets.LowryParkZoo.com:1433

dn: CN=LPZ-TICKETS,CN=Computers,DC=LowryParkZoo,DC=com
changetype: add
servicePrincipalName: MSSQLSvc/lpz-tickets.LowryParkZoo.com:1433
servicePrincipalName: DNS/lpz-tickets.LowryParkZoo.com
servicePrincipalName: HOST/lpz-tickets.LowryParkZoo.com/LowryParkZoo.com
servicePrincipalName: HOST/lpz-tickets.LowryParkZoo.com/LOWRYPARKZOO
servicePrincipalName: HOST/LPZ-TICKETS
servicePrincipalName: HOST/lpz-tickets.LowryParkZoo.com

I looked at the  MSSQLSERVER service in LPZ-Tickets and it uses the Local System Account to Log On.

I noted that the CN=Administrator and CN=LPZ-Tickets both have the same MSSQLSvc serviceprincipalname.  

In MS article http://support.microsoft.com/kb/321044 it has as the resolution:
To resolve this problem, locate the computer accounts that have the duplicate SPNs. When you have located the computers that have the duplicate SPNs, you can either delete the computer account from the domain, disjoin and rejoin the computer to the domain, or you can use ADSIEdit to correct the SPN on the computer that has the incorrect SPN.

So I need to figure out which one to remove and how to use adsiedit to remove or fix the incorrect entry, so the SQL service stays running and the Event Error 11 in Source KDC is eliminated.

Thanks in advance.

Question by:tfcmarty
  • 3

Author Comment

ID: 22967572
I have ADSI edit working and can highlight servicePrincipalName = MSSQLSvc in both the Administrator account and LPZ-Tickets, I'm still struggling as to which one to remove.
LVL 31

Accepted Solution

Henrik Johansson earned 2000 total points
ID: 22970332
You nead to remove the SPN that isn't used. As you've found that SQL is running as Local System and is by that reason using SPN on computer account, you shall remove the SPN from Administrator account.

To increase security, you should create a dedicated service account instead of running SQL as LocalSystem or Administrator (both gives to much permissions).

Instead of using ADSIedit, you can use setspn-command to delete the SPNs.

C:\>setspn -D MSSQLSvc/lpz-tickets.LowryParkZoo.com:1433 Administrator

Author Comment

ID: 22970626
Thanks for both recommendations.  That helped me to understand what I was doing.

Author Closing Comment

ID: 31517091
Thanks again.

Featured Post

Veeam and MySQL: How to Perform Backup & Recovery

MySQL and the MariaDB variant are among the most used databases in Linux environments, and many critical applications support their data on them. Watch this recorded webinar to find out how Veeam Backup & Replication allows you to get consistent backups of MySQL databases.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I guess it is not common knowledge to most Wintel engineers/administrators: If you have an SNMP-based monitoring system in your environment (and it's common to have SNMP or Syslog) it's reasonably easy to enable monitoring of the Windows Event logs,…
Many of us need to configure DHCP server(s) in their environment. We can do that simply via DHCP console on server or using MMC snap-in on each computer with Administrative Tools installed in a network. But what if we have to configure many DHCP ser…
Are you ready to place your question in front of subject-matter experts for more timely responses? With the release of Priority Question, Premium Members, Team Accounts and Qualified Experts can now identify the emergent level of their issue, signal…
Is your OST file inaccessible, Need to transfer OST file from one computer to another? Want to convert OST file to PST? If the answer to any of the above question is yes, then look no further. With the help of Stellar OST to PST Converter, you can e…

862 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question