• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 468
  • Last Modified:

Event ID 4

I am getting the following error on a member server in the domain.  The DCs are not showing any errors.  All servers are 2003. The machine called jmh-e6500 is listed in ADUC.  Will deleteing it from ADUC fix the issue?  The other machine mentioned in the error, server MH$ is an XP workstation, not a server.  Any help is appreciated.
cja

Event Type:      Error
Event Source:      Kerberos
Event Category:      None
Event ID:      4
Date:            2/22/2011
Time:            12:16:56 PM
User:            N/A
Computer:      SERVER-ADMIN-2
Description:
The kerberos client received a KRB_AP_ERR_MODIFIED error from the server MH$.  The target name used was cifs/JMH-E6500.Company-Dom.company.com. This indicates that the password used to encrypt the kerberos service ticket is different than that on the target server. Commonly, this is due to identically named machine accounts in the target realm (Company-DOM.COMPANY.COM), and the client realm.   Please contact your system administrator.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
0
cja-tech-guy
Asked:
cja-tech-guy
  • 2
1 Solution
 
Wonko_the_SaneCommented:
Unless you get those errors all the time and notice any real issues it's not too much of a concern, but here's some things to check:

- make sure the DNS records for the servers and clients mentioned are OK, including Reverse DNS ones
-Check if there is a duplicate Service Principal Name (SPN), or an SPN assigned to the wrong machine. You can use tools such as ADSIEDIT to view them for the machines involved, you are probably looking for a SPN that starts with HOST/
You can also export the entire domain:
ldifde -f dumpfile.txt -d dc=company-Dom,dc=company,dc=com-l serviceprincipalname
0
 
cja-tech-guyAuthor Commented:
The only thing I see in DNS is duplicate records for the IP of the machine named MH and JMH-E6500.  JMH-E6500 is no longer a member of the domain, it was removed months ago.  MH is a new machine that was added about 3 weeks ago.  Should I delete the DNS record for JMH-E6500?  What happens if I delete a DNS record for a machine that is still a member of the domain?  Does it get recreated?

Thanks,

cja
0
 
Wonko_the_SaneCommented:
Usually it will get recreated, at least in most standard configurations. You can trigger the registration from the machine by running "ipconfig /registerdns".

If there are duplicate records you may want to remove the one that's no longer valid.
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Free Tool: IP Lookup

Get more info about an IP address or domain name, such as organization, abuse contacts and geolocation.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now