Solved

Kerberos Security Error 4

Posted on 2009-07-16
7
543 Views
Last Modified: 2012-05-07
Hi - we installed a new server approx 2 months ago, and everything has being working wonderfully, then all of a sudden yesterday afternoon, all the connectivity between the clients and server bombed, ands I am now receiving the following security error from all the clients.

received a KRB_AP_ERR_MODIFIED error from the server SARIEPC$. The target name used was PENTAG\SARIEPC$. This indicates that the target server failed to decrypt the ticket provided by the client. This can occur when the target server principal name (SPN) is registered on an account other than the account the target service is using. Please ensure that the target SPN is registered on, and only registered on, the account used by the server. This error can also happen when the target service is using a different password for the target service account than what the Kerberos Key Distribution Center (KDC) has for the target service account. Please ensure that the service on the server and the KDC are both updated to use the current password. If the server name is not fully qualified, and the target domain (PENTAG.LOCAL) is different from the client domain (PENTAG.LOCAL), check if there are identically named server accounts in these two domains, or use the fully-qualified name to identify the server.

URGENT - PLEASE HELP ANYONE?
0
Comment
Question by:duzbin
  • 3
  • 3
7 Comments
 
LVL 19

Expert Comment

by:*** Hopeleonie ***
ID: 24867469
can you add the event source from the event id?
0
 
LVL 19

Accepted Solution

by:
*** Hopeleonie *** earned 250 total points
ID: 24867486
0
 
LVL 27

Expert Comment

by:Jonvee
ID: 24868225
>> KRB_AP_ERR_MODIFIED error from the server SARIEPC$ <<

The 'Resolution' in this MS article may help>

Event ID 11 in the System log of domain controllers:
http://support.microsoft.com/kb/321044/en-us
0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 
LVL 27

Expert Comment

by:Jonvee
ID: 24868284
@ hopeleonie ... initially i was unable to open your link.   However now that i have, i realise there may be some duplication in my link!  
If this is so it was unintentional, and perhaps duzbin can ignore my comment.
0
 
LVL 19

Expert Comment

by:*** Hopeleonie ***
ID: 24868392
hi jonvee

it takes a little time to open i just test it :-)

regards
hopeleonie
0
 
LVL 1

Author Comment

by:duzbin
ID: 24875398
Thanks Guys, I eventually reset everything ie. Nic Adapter,. and the problem disappeared, the Clients can once again connect to their "my Documents" etc. BUT now further problems have started and I cannot find any event to substantiate the error's I am receiving? The Clients can now NOT connect to RWW, or OWA or the CompanyWeb Site, and their MS Outlook cannot connect to the Exchange server???
The strange thing is that the Server is working well, The RWW, Company Web etc is all working on the server and is accessible. If I do an nslookup on the client pc for Company web it finds it, but if I try open the site, I get a "Page cannot be displayed" error. This was all working before I fixed the previous error from above. Want to tear my hair out - any ideas? Thanks in advance!
0
 
LVL 27

Assisted Solution

by:Jonvee
Jonvee earned 250 total points
ID: 24890639
In this earlier thread the problem went away as mysteriously as it appeared, but see if some of the ideas help>

"Website and Webmail not accessible externally, but ok internally":
http://www.experts-exchange.com/Networking/Misc/Q_21399657.html
0

Featured Post

Is Your AD Toolbox Looking More Like a Toybox?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
How to remove users in file list from specific AD group? 3 39
Windows Server Folder Access Control 6 33
Admin account lockout 10 38
Application Crash 2 21
I work for a company that primarily works with small businesses as their outsourced IT vendor. As such the majority of these customers utilize some version of Small Business Server. Due to the economics of running a small business, many of these cus…
A quick step-by-step overview of installing and configuring Carbonite Server Backup.
This tutorial will show how to push an installation of Backup Exec to an additional server in both 2012 and 2014 versions of the software. Click on the Backup Exec button in the upper left corner. From here, select Installation and Licensing, then I…
This tutorial will walk an individual through locating and launching the BEUtility application to properly change the service account username and\or password in situation where it may be necessary or where the password has been inadvertently change…

776 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question