Solved

Event ID 4

Posted on 2011-02-23
3
437 Views
Last Modified: 2012-06-21
I am getting the following error on a member server in the domain.  The DCs are not showing any errors.  All servers are 2003. The machine called jmh-e6500 is listed in ADUC.  Will deleteing it from ADUC fix the issue?  The other machine mentioned in the error, server MH$ is an XP workstation, not a server.  Any help is appreciated.
cja

Event Type:      Error
Event Source:      Kerberos
Event Category:      None
Event ID:      4
Date:            2/22/2011
Time:            12:16:56 PM
User:            N/A
Computer:      SERVER-ADMIN-2
Description:
The kerberos client received a KRB_AP_ERR_MODIFIED error from the server MH$.  The target name used was cifs/JMH-E6500.Company-Dom.company.com. This indicates that the password used to encrypt the kerberos service ticket is different than that on the target server. Commonly, this is due to identically named machine accounts in the target realm (Company-DOM.COMPANY.COM), and the client realm.   Please contact your system administrator.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
0
Comment
Question by:cja-tech-guy
  • 2
3 Comments
 
LVL 14

Accepted Solution

by:
Wonko_the_Sane earned 500 total points
ID: 34970183
Unless you get those errors all the time and notice any real issues it's not too much of a concern, but here's some things to check:

- make sure the DNS records for the servers and clients mentioned are OK, including Reverse DNS ones
-Check if there is a duplicate Service Principal Name (SPN), or an SPN assigned to the wrong machine. You can use tools such as ADSIEDIT to view them for the machines involved, you are probably looking for a SPN that starts with HOST/
You can also export the entire domain:
ldifde -f dumpfile.txt -d dc=company-Dom,dc=company,dc=com-l serviceprincipalname
0
 

Author Comment

by:cja-tech-guy
ID: 34970684
The only thing I see in DNS is duplicate records for the IP of the machine named MH and JMH-E6500.  JMH-E6500 is no longer a member of the domain, it was removed months ago.  MH is a new machine that was added about 3 weeks ago.  Should I delete the DNS record for JMH-E6500?  What happens if I delete a DNS record for a machine that is still a member of the domain?  Does it get recreated?

Thanks,

cja
0
 
LVL 14

Expert Comment

by:Wonko_the_Sane
ID: 34970789
Usually it will get recreated, at least in most standard configurations. You can trigger the registration from the machine by running "ipconfig /registerdns".

If there are duplicate records you may want to remove the one that's no longer valid.
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Many of us need to configure DHCP server(s) in their environment. We can do that simply via DHCP console on server or using MMC snap-in on each computer with Administrative Tools installed in a network. But what if we have to configure many DHCP ser…
Learn about cloud computing and its benefits for small business owners.
Nobody understands Phishing better than an anti-spam company. That’s why we are providing Phishing Awareness Training to our customers. According to a report by Verizon, only 3% of targeted users report malicious emails to management. With compan…

749 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question