Solved

Kerberos event id 7 + netlogon event id 5719 errors, domain workstation unable to log on

Posted on 2009-05-19
9
2,308 Views
Last Modified: 2012-05-07
Hi all,

Recently I've had several workstations come up with these event error logs (in chronological order):

Event Type:      Error
Event Source:      NETLOGON
Event Category:      None
Event ID:      5719
Date:            5/14/2009
Time:            11:19:50 AM
User:            N/A
Computer:      ABBOTT-MAIN
Description:
No Domain Controller is available for domain ABBOTT due to the following:
The RPC server is unavailable. .
Make sure that the computer is connected to the network and try again. If the problem persists, please contact your domain administrator.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 17 00 02 c0               ...    

Event Type:      Error
Event Source:      Kerberos
Event Category:      None
Event ID:      7
Date:            5/14/2009
Time:            11:47:06 AM
User:            N/A
Computer:      ABBOTT-MAIN
Description:
The kerberos subsystem encountered a PAC verification failure.  This indicates that the PAC from the client ABBOTT-MAIN$ in realm ABBOTT.LOCAL had a PAC which failed to verify or was modified.  Contact your system administrator.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 5e 00 00 c0               ^..  


I've read a few other topics and have tried re-syncing w32time to make sure all the clocks match, but I'm out of ideas at this point. The one workstation can't even log in, but if I check the system logs off of the domain (where it's able to log on) I don't see any errors when its trying to log on. On other workstations that are already logged in (and I don't dare log them out) i see those two errors in the system log. Also, I don't happen to see anything awry on the SBS 2003 server system logs either.

Any help would be greatly appreciated!

--Hans
0
Comment
Question by:dyndragon91
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 4
9 Comments
 
LVL 10

Accepted Solution

by:
PlusIT earned 250 total points
ID: 24427252
for the workstations that are failing to login to the domain:

- join the wks back into a workgroup
- delete the AD computer account manually from the AD
- wait 10 to 15 minutes
- rejoin the computer, if the problem restarts let me know.  
0
 

Author Comment

by:dyndragon91
ID: 24427434
I am concerned about doing this. Do I need to re-add the computer via the /connectcomputer/ wizard to retain all the SBS features and scripts? I don't think I do, but I just wanted to double check.
0
 
LVL 10

Assisted Solution

by:PlusIT
PlusIT earned 250 total points
ID: 24427444
Hey,

yes you do retain those as they are linked to the user account not the computer account.  After rejoining into the domain logging in with the domain user will even have preserved the profile.  I have seen similar problems like yours and rejoining the domain after manually deleting the computer account (NOT the user account!) mostly fixes these kind of issues.  Just make sure you wait long enough after manually deleting the computer account.  I wouldn't use connect computer though just do it from the properties screen of My Computer

Good luck!
0
Edgartown IT Case Study

Learn about Edgartown's quest to ensure the safety and security of the entire town's employee and citizen data. Read the case study!

 

Author Comment

by:dyndragon91
ID: 24431046
I will give this a shot and report back. I'm not at this site for a day or two.
0
 

Author Comment

by:dyndragon91
ID: 24435919
Odd thing. Now I plug in the workstation that couldn't log in before and it works with no problems. ????! I'm dreading rootcausing this. What might cause these issues?
0
 
LVL 10

Assisted Solution

by:PlusIT
PlusIT earned 250 total points
ID: 24443788
check DNS settings, are you still using WINS?  Inconsitency between WINS and DNS information can cause this also.  I suggest you don't use WINS anymore and completely rely on DNS.

again there's a lot that could be going on still, from general physical network trouble to kerberos tickiting failing.  I would have a look at WINS / DNS first.  The first solution i gave always works when your PC can't logon to the domain, but when it sometimes can i'm thinking further like Wins, kerberos or plain old date and time being set wrong.

Did you acctually double check after testing with w32time your computer and bios time was set correctly before logging in ?
0
 

Author Comment

by:dyndragon91
ID: 24444149
This is a one PDC domain, so even if I was using WINS and DNS, there's only one domain server to resolve to and it's set to be a static IP address. In any case, I'm not using WINS as far as I know.

I did actually double check to make sure the bios time was set correctly. I know that you can get auth failures if the time is off, so that was the first thing I checked. I'm starting to think that one of the network switches might be on the fritz.

Still investigating...thanks for the tips.

0
 
LVL 10

Assisted Solution

by:PlusIT
PlusIT earned 250 total points
ID: 24444342
to make sure your client is not using WINS do an ipconfig /all on the client and check for WINS entries.
0
 

Author Closing Comment

by:dyndragon91
ID: 31583189
Good troubleshooting steps and it worked.
0

Featured Post

Visualize your virtual and backup environments

Create well-organized and polished visualizations of your virtual and backup environments when planning VMware vSphere, Microsoft Hyper-V or Veeam deployments. It helps you to gain better visibility and valuable business insights.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Introduction At 19:33 (UST) on Tuesday 21st September the long awaited email arrived with the subject title of “ANNOUNCING THE AVAILABILITY OF WINDOWS SBS 7 PREVIEW”.  It was time to drop whatever I was doing and dedicate as much bandwidth as possi…
Scenerio: You have a server running Server 2003 and have applied a retail pack of Terminal Server Licenses.  You want to change servers or your server has crashed and you need to reapply the Terminal Server Licenses. When you enter the 16-digit lic…
Although Jacob Bernoulli (1654-1705) has been credited as the creator of "Binomial Distribution Table", Gottfried Leibniz (1646-1716) did his dissertation on the subject in 1666; Leibniz you may recall is the co-inventor of "Calculus" and beat Isaac…

740 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question