Solved

DS_SERVICE_PRINCIPAL_NAME Event 11

Posted on 2009-07-09
1
1,103 Views
Last Modified: 2012-06-27
I'm running into the DS_SERVICE_PRINCIPAL_NAME KDC Event 11 and I would appreciate some expert help resolving it.
I'm running a server 2003 domain. The host in question is server 2003 and running one instance of SQL 2005 and another of SQL 2000 and the error applies to the common SQL account that runs both instances.

I tried using methods 1 and 3 outlined at http://support.microsoft.com/kb/321044. I have to admit I'm not familiar with these tools or how to use the results. I tried using both ports 389 or 3268.  The exact error is MSSQLSvc/Host.Domain.org:1433 of type DS_SERVICE_PRINCIPAL_NAME.

Searching MSSQLSvc/MyServer.Domain.org:1433 returns a ton of results, from several servers and varied port numbers.

CN=SQLService,CN=....
Class: user
User Logon: SQLService
-- MSSQLSvc/MyServer.Domain.org:1401
-- MSSQLSvc/MyServer.Domain.org:1433
-- MSSQLSvc/MyServer.,Domain.org:1401
-- MSSQLSvc/AnotherServer.Domain.org:1433
....

User Logon: AUser
-- MSSQLSvc/MyServer.Host.Domain.org:1433
0
Comment
Question by:timbrigham
1 Comment
 
LVL 31

Accepted Solution

by:
Henrik Johansson earned 500 total points
ID: 24816086
The SPN shall be unique and only exist on one single account, in this case the service account running SQL Server on MyServer.
Use setspn and remove the duplicated SPN from the accounts that shall not have the SPN

setspn -D MSSQLSvc/MyServer.Domain.Org:1433 accountname

The method I prefer is to use dsquery (similar to ldifde method) is to use dsquery.
dsquery * -filter (serviceprincipalname=<serchedSPN>) -attr name
or
dsquery * -filter (serviceprincipalname=<serchedSPN>) -attr name serviceprincipalname
0

Featured Post

Is Your AD Toolbox Looking More Like a Toybox?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article explains how to reset the password of the sa account on a Microsoft SQL Server.  The steps in this article work in SQL 2005, 2008, 2008 R2, 2012, 2014 and 2016.
This article shows how to deploy dynamic backgrounds to computers depending on the aspect ratio of display
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.

816 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

8 Experts available now in Live!

Get 1:1 Help Now