Solved

Event ID 4

Posted on 2011-02-23
3
434 Views
Last Modified: 2012-06-21
I am getting the following error on a member server in the domain.  The DCs are not showing any errors.  All servers are 2003. The machine called jmh-e6500 is listed in ADUC.  Will deleteing it from ADUC fix the issue?  The other machine mentioned in the error, server MH$ is an XP workstation, not a server.  Any help is appreciated.
cja

Event Type:      Error
Event Source:      Kerberos
Event Category:      None
Event ID:      4
Date:            2/22/2011
Time:            12:16:56 PM
User:            N/A
Computer:      SERVER-ADMIN-2
Description:
The kerberos client received a KRB_AP_ERR_MODIFIED error from the server MH$.  The target name used was cifs/JMH-E6500.Company-Dom.company.com. This indicates that the password used to encrypt the kerberos service ticket is different than that on the target server. Commonly, this is due to identically named machine accounts in the target realm (Company-DOM.COMPANY.COM), and the client realm.   Please contact your system administrator.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
0
Comment
Question by:cja-tech-guy
  • 2
3 Comments
 
LVL 14

Accepted Solution

by:
Wonko_the_Sane earned 500 total points
ID: 34970183
Unless you get those errors all the time and notice any real issues it's not too much of a concern, but here's some things to check:

- make sure the DNS records for the servers and clients mentioned are OK, including Reverse DNS ones
-Check if there is a duplicate Service Principal Name (SPN), or an SPN assigned to the wrong machine. You can use tools such as ADSIEDIT to view them for the machines involved, you are probably looking for a SPN that starts with HOST/
You can also export the entire domain:
ldifde -f dumpfile.txt -d dc=company-Dom,dc=company,dc=com-l serviceprincipalname
0
 

Author Comment

by:cja-tech-guy
ID: 34970684
The only thing I see in DNS is duplicate records for the IP of the machine named MH and JMH-E6500.  JMH-E6500 is no longer a member of the domain, it was removed months ago.  MH is a new machine that was added about 3 weeks ago.  Should I delete the DNS record for JMH-E6500?  What happens if I delete a DNS record for a machine that is still a member of the domain?  Does it get recreated?

Thanks,

cja
0
 
LVL 14

Expert Comment

by:Wonko_the_Sane
ID: 34970789
Usually it will get recreated, at least in most standard configurations. You can trigger the registration from the machine by running "ipconfig /registerdns".

If there are duplicate records you may want to remove the one that's no longer valid.
0

Featured Post

NAS Cloud Backup Strategies

This article explains backup scenarios when using network storage. We review the so-called “3-2-1 strategy” and summarize the methods you can use to send NAS data to the cloud

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

by Batuhan Cetin In this article I will be guiding through the process of removing a failed DC metadata from Active Directory (hereafter, AD) using the ntdsutil tool in a Windows Server 2003 environment. These steps are not necessary in a Win…
Many of us need to configure DHCP server(s) in their environment. We can do that simply via DHCP console on server or using MMC snap-in on each computer with Administrative Tools installed in a network. But what if we have to configure many DHCP ser…
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…
Finds all prime numbers in a range requested and places them in a public primes() array. I've demostrated a template size of 30 (2 * 3 * 5) but larger templates can be built such 210  (2 * 3 * 5 * 7) or 2310  (2 * 3 * 5 * 7 * 11). The larger templa…

829 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question