Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Kerberos error

Posted on 2009-07-09
3
Medium Priority
?
588 Views
Last Modified: 2012-05-07
Hi all,

I am running a DC on Windows 2003 and my System Event Viewer is full of Kerberos error .... it doesn't seem to affect anything but I want to make sure these eror won't lead to anything else.

Event Type:      Error
Event Source:      Kerberos
Event Category:      None
Event ID:      3
Date:            7/9/2009
Time:            1:12:13 AM
User:            N/A
Computer:      NMMC-DC
Description:
A Kerberos Error Message was received:
         on logon session
 Client Time:
 Server Time: 5:12:13.0000 7/9/2009 Z
 Error Code: 0xd KDC_ERR_BADOPTION
 Extended Error: 0xc00000bb KLIN(0)
 Client Realm:
 Client Name:
 Server Realm: NMMC-NET.LOCAL
 Server Name: host/nmmc-dc.nmmc-net.local
 Target Name: host/nmmc-dc.nmmc-net.local@NMMC-NET.LOCAL
 Error Text:
 File: 9
 Line: ae0
 Error Data is in record data.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 30 15 a1 03 02 01 03 a2   0.¡....¢
0008: 0e 04 0c bb 00 00 c0 00   ...»..À.
0010: 00 00 00 03 00 00 00      .......


Also I setup another DC for redundancy and made it a glaobal catalog and all but I can't seem to connect to it when the main DC is down. I don't know if this could be related.
0
Comment
Question by:nmmcfk
2 Comments
 
LVL 26

Accepted Solution

by:
Pber earned 1000 total points
ID: 24812984
See this regarding the Kerberos errors:
http://mailman.mit.edu/pipermail/kerberos/2005-February/007231.html

http://technet2.microsoft.com/windowsserver/en/library/b36b8071-3cc5-46fa-be13-280aa43f2fd21033.mspx?mfr=true 

Running kerbtray and purging the tickets has worked for me in the past.

kerbtray is part of these tools:
http://www.microsoft.com/downloads/details.aspx?FamilyID=9D467A69-57FF-4AE7-96EE-B18C4790CFFD&displaylang=en

As far as your 2nd DC not picking up,   It may be the clients need to point to the 2nd DC for DNS (it is desired to have your your DCs as AD integrated DNS servers.  See this:
http://www.pberblog.com/post/2009/06/09/DC-failed-second-DC-not-authenticating-users.aspx 
 
0
 

Author Comment

by:nmmcfk
ID: 24860983
OK I will see what I can do with that .... thanks for the info and i will kep you guys posted.
0

Featured Post

Free Tool: Path Explorer

An intuitive utility to help find the CSS path to UI elements on a webpage. These paths are used frequently in a variety of front-end development and QA automation tasks.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

On July 14th 2015, Windows Server 2003 will become End of Support, leaving hundreds of thousands of servers around the world that still run this 12 year old operating system vulnerable and potentially out of compliance in many organisations around t…
ADCs have gained traction within the last decade, largely due to increased demand for legacy load balancing appliances to handle more advanced application delivery requirements and improve application performance.
This Micro Tutorial will teach you how to add a cinematic look to any film or video out there. There are very few simple steps that you will follow to do so. This will be demonstrated using Adobe Premiere Pro CS6.
This video shows how to quickly and easily deploy an email signature for all users in Office 365 and prevent it from being added to replies and forwards. (the resulting signature is applied on the server level in Exchange Online) The email signat…

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question