Solved

DS_SERVICE_PRINCIPAL_NAME Event 11

Posted on 2009-07-09
1
1,093 Views
Last Modified: 2012-06-27
I'm running into the DS_SERVICE_PRINCIPAL_NAME KDC Event 11 and I would appreciate some expert help resolving it.
I'm running a server 2003 domain. The host in question is server 2003 and running one instance of SQL 2005 and another of SQL 2000 and the error applies to the common SQL account that runs both instances.

I tried using methods 1 and 3 outlined at http://support.microsoft.com/kb/321044. I have to admit I'm not familiar with these tools or how to use the results. I tried using both ports 389 or 3268.  The exact error is MSSQLSvc/Host.Domain.org:1433 of type DS_SERVICE_PRINCIPAL_NAME.

Searching MSSQLSvc/MyServer.Domain.org:1433 returns a ton of results, from several servers and varied port numbers.

CN=SQLService,CN=....
Class: user
User Logon: SQLService
-- MSSQLSvc/MyServer.Domain.org:1401
-- MSSQLSvc/MyServer.Domain.org:1433
-- MSSQLSvc/MyServer.,Domain.org:1401
-- MSSQLSvc/AnotherServer.Domain.org:1433
....

User Logon: AUser
-- MSSQLSvc/MyServer.Host.Domain.org:1433
0
Comment
Question by:timbrigham
1 Comment
 
LVL 31

Accepted Solution

by:
Henrik Johansson earned 500 total points
Comment Utility
The SPN shall be unique and only exist on one single account, in this case the service account running SQL Server on MyServer.
Use setspn and remove the duplicated SPN from the accounts that shall not have the SPN

setspn -D MSSQLSvc/MyServer.Domain.Org:1433 accountname

The method I prefer is to use dsquery (similar to ldifde method) is to use dsquery.
dsquery * -filter (serviceprincipalname=<serchedSPN>) -attr name
or
dsquery * -filter (serviceprincipalname=<serchedSPN>) -attr name serviceprincipalname
0

Featured Post

How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

Join & Write a Comment

Suggested Solutions

Introduction You may have a need to setup a group of users to allow local administrative access on workstations.  In a domain environment this can easily be achieved with Restricted Groups and Group Policies. This article will demonstrate how to…
In this article I will describe the Copy Database Wizard method as one possible migration process and I will add the extra tasks needed for an upgrade when and where is applied so it will cover all.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

744 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

14 Experts available now in Live!

Get 1:1 Help Now