Solved

Kerberos error

Posted on 2009-07-09
3
584 Views
Last Modified: 2012-05-07
Hi all,

I am running a DC on Windows 2003 and my System Event Viewer is full of Kerberos error .... it doesn't seem to affect anything but I want to make sure these eror won't lead to anything else.

Event Type:      Error
Event Source:      Kerberos
Event Category:      None
Event ID:      3
Date:            7/9/2009
Time:            1:12:13 AM
User:            N/A
Computer:      NMMC-DC
Description:
A Kerberos Error Message was received:
         on logon session
 Client Time:
 Server Time: 5:12:13.0000 7/9/2009 Z
 Error Code: 0xd KDC_ERR_BADOPTION
 Extended Error: 0xc00000bb KLIN(0)
 Client Realm:
 Client Name:
 Server Realm: NMMC-NET.LOCAL
 Server Name: host/nmmc-dc.nmmc-net.local
 Target Name: host/nmmc-dc.nmmc-net.local@NMMC-NET.LOCAL
 Error Text:
 File: 9
 Line: ae0
 Error Data is in record data.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 30 15 a1 03 02 01 03 a2   0.¡....¢
0008: 0e 04 0c bb 00 00 c0 00   ...»..À.
0010: 00 00 00 03 00 00 00      .......


Also I setup another DC for redundancy and made it a glaobal catalog and all but I can't seem to connect to it when the main DC is down. I don't know if this could be related.
0
Comment
Question by:nmmcfk
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 26

Accepted Solution

by:
Pber earned 250 total points
ID: 24812984
See this regarding the Kerberos errors:
http://mailman.mit.edu/pipermail/kerberos/2005-February/007231.html

http://technet2.microsoft.com/windowsserver/en/library/b36b8071-3cc5-46fa-be13-280aa43f2fd21033.mspx?mfr=true 

Running kerbtray and purging the tickets has worked for me in the past.

kerbtray is part of these tools:
http://www.microsoft.com/downloads/details.aspx?FamilyID=9D467A69-57FF-4AE7-96EE-B18C4790CFFD&displaylang=en

As far as your 2nd DC not picking up,   It may be the clients need to point to the 2nd DC for DNS (it is desired to have your your DCs as AD integrated DNS servers.  See this:
http://www.pberblog.com/post/2009/06/09/DC-failed-second-DC-not-authenticating-users.aspx 
 
0
 

Author Comment

by:nmmcfk
ID: 24860983
OK I will see what I can do with that .... thanks for the info and i will kep you guys posted.
0

Featured Post

Comparison of Amazon Drive, Google Drive, OneDrive

What is Best for Backup: Amazon Drive, Google Drive or MS OneDrive? In this free whitepaper we look at their performance, pricing, and platform availability to help you decide which cloud drive is right for your situation. Download and read the results of our testing for free!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I guess it is not common knowledge to most Wintel engineers/administrators: If you have an SNMP-based monitoring system in your environment (and it's common to have SNMP or Syslog) it's reasonably easy to enable monitoring of the Windows Event logs,…
I've always wanted to allow a user to have a printer no matter where they login. The steps below will show you how to achieve just that. In this Article I'll show how to deploy printers automatically with group policy and then using security fil…

739 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question