Kerberos error

Hi all,

I am running a DC on Windows 2003 and my System Event Viewer is full of Kerberos error .... it doesn't seem to affect anything but I want to make sure these eror won't lead to anything else.

Event Type:      Error
Event Source:      Kerberos
Event Category:      None
Event ID:      3
Date:            7/9/2009
Time:            1:12:13 AM
User:            N/A
Computer:      NMMC-DC
Description:
A Kerberos Error Message was received:
         on logon session
 Client Time:
 Server Time: 5:12:13.0000 7/9/2009 Z
 Error Code: 0xd KDC_ERR_BADOPTION
 Extended Error: 0xc00000bb KLIN(0)
 Client Realm:
 Client Name:
 Server Realm: NMMC-NET.LOCAL
 Server Name: host/nmmc-dc.nmmc-net.local
 Target Name: host/nmmc-dc.nmmc-net.local@NMMC-NET.LOCAL
 Error Text:
 File: 9
 Line: ae0
 Error Data is in record data.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 30 15 a1 03 02 01 03 a2   0.¡....¢
0008: 0e 04 0c bb 00 00 c0 00   ...»..À.
0010: 00 00 00 03 00 00 00      .......


Also I setup another DC for redundancy and made it a glaobal catalog and all but I can't seem to connect to it when the main DC is down. I don't know if this could be related.
nmmcfkAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

PberSolutions ArchitectCommented:
See this regarding the Kerberos errors:
http://mailman.mit.edu/pipermail/kerberos/2005-February/007231.html

http://technet2.microsoft.com/windowsserver/en/library/b36b8071-3cc5-46fa-be13-280aa43f2fd21033.mspx?mfr=true 

Running kerbtray and purging the tickets has worked for me in the past.

kerbtray is part of these tools:
http://www.microsoft.com/downloads/details.aspx?FamilyID=9D467A69-57FF-4AE7-96EE-B18C4790CFFD&displaylang=en

As far as your 2nd DC not picking up,   It may be the clients need to point to the 2nd DC for DNS (it is desired to have your your DCs as AD integrated DNS servers.  See this:
http://www.pberblog.com/post/2009/06/09/DC-failed-second-DC-not-authenticating-users.aspx 
 
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
nmmcfkAuthor Commented:
OK I will see what I can do with that .... thanks for the info and i will kep you guys posted.
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Windows Server 2003

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.