Solved

Cannot open Exchange 2010 console or shell. "Kerberos auth failed. Access is denied"

Posted on 2011-03-03
15
16,980 Views
Last Modified: 2012-06-27
Hi All,
An issue just cropped up on an existing Exchange 2010 production server. When trying to open the Exchange Management Console or the shell, we get the following error:

"The following error occurred when trying to connect to the specified Exchange server 'server.domain.org':
The attempt to connect to http://server.domain.org/PowerShell using "Kerberos" authentication failed:
Connecting to remote server failed with the following error message: Access is denied. For more information, see the about_Remote_Troubleshooting Help topic.
"

I've confirmed my logon user (a domain admin account) is part of the Org Management security group. The time was off on the email server by over 7 minutes. I ran "net time \\dc1 /set" to sync the Exchange box with one of the domain controllers. No change. I even rebooted the server. No change.

I followed a bunch of other topics found on EE regarding WinRM issues, ran the winrm quickconfig, but this didn't change anything.

I'm at a loss and now we cannot manage the Exchange server since we can't get in via the shell or Console.
0
Comment
Question by:redeyeinc
15 Comments
 
LVL 34

Expert Comment

by:Shreedhar Ette
ID: 35028562
Please refer the previuosly answered question:
http://www.experts-exchange.com/Software/Server_Software/Email_Servers/Exchange/Q_25992806.html

Hope this helps,
Shree
0
 
LVL 17

Expert Comment

by:Viral Rathod
ID: 35028793
0
 

Author Comment

by:redeyeinc
ID: 35029495
Shree,
I followed those previous posts to no avail. The error is a bit vague (nothing refers to WinRM) and nothing is logged in EventVwr.

I even rebooted the server but this did not help. I seem to recall this happening a while ago right after installing Exchange. A reboot "resolved" it then, but not now.
0
Complete VMware vSphere® ESX(i) & Hyper-V Backup

Capture your entire system, including the host, with patented disk imaging integrated with VMware VADP / Microsoft VSS and RCT. RTOs is as low as 15 seconds with Acronis Active Restore™. You can enjoy unlimited P2V/V2V migrations from any source (even from a different hypervisor)

 
LVL 13

Expert Comment

by:soostibi
ID: 35030738
Have you tried to open a normal PowerShell window, and do:
add-pssnapin Microsoft.Exchange.Management.PowerShell.E2010

And try to run:
test-servicehealth

And see if there is any service that is not running.
0
 

Author Comment

by:redeyeinc
ID: 35031795
Did it. These are the results:

PS C:\Users\redeye> add-pssnapin Microsoft.Exchange.Management.PowerShell.E2010
PS C:\Users\redeye> test-servicehealth


Role                    : Mailbox Server Role
RequiredServicesRunning : True
ServicesRunning         : {IISAdmin, MSExchangeADTopology, MSExchangeIS, MSExchangeMailboxAssistants...}
ServicesNotRunning      : {}

Role                    : Client Access Server Role
RequiredServicesRunning : True
ServicesRunning         : {IISAdmin, MSExchangeAB, MSExchangeADTopology, MSExchangeFBA...}
ServicesNotRunning      : {}

Role                    : Hub Transport Server Role
RequiredServicesRunning : True
ServicesRunning         : {IISAdmin, MSExchangeADTopology, MSExchangeEdgeSync, MSExchangeServiceHost...}
ServicesNotRunning      : {}
0
 
LVL 13

Expert Comment

by:soostibi
ID: 35032031
OK, then all services are running.
0
 

Author Comment

by:redeyeinc
ID: 35032060
I did notice that my mail server clock is consistently 7 minutes ahead of any domain controller. I've run the "net time \\dc1 /set" command and tried to sync it up, and while it does sync the time, eventually it reverts back to being 7 minutes ahead.

Maybe I ought to start there with any continued troubleshooting??
0
 
LVL 13

Accepted Solution

by:
soostibi earned 500 total points
ID: 35033819
Is you machine virtualized? If so then check if your Exchange Server is double times syncronized or not. It should only be syncronizet to its DC, not to the physical machine.
0
 

Author Comment

by:redeyeinc
ID: 35035305
No. Not virtualized.
0
 

Author Comment

by:redeyeinc
ID: 35037338
Ok, this is creepy. Logged onto the server this morning with same user account as yesterday and I can open the EMC and Shell.

Nothing in Event Viewer.

I'm concerned about this still. If it's indicative of a problem under the covers we definitely need to get it under wraps. Weird stuff.....
0
 

Author Comment

by:redeyeinc
ID: 35112233
It turned out this was related to time being off by approx. 7 minutes on one of the domain controllers. Updated the time via the "net time \\dc1 /set" command and rebooted the Exchange server. This resolved the issue.
0
 

Author Comment

by:redeyeinc
ID: 35112247
Let me clarify. I ran that "net time" command on the offending domain controller that had the time off. I previously ran the "net time" command on the Exchange server, but the time turned out to be fine on that box. Long term solution is to take a deeper look at the older domain controllers on the network and make sure time sync is functional on all.
0
 

Author Closing Comment

by:redeyeinc
ID: 35112267
While our Exchange box is not virtualized, the time sync comment pointed us in the right direction.
0
 

Expert Comment

by:gleasoninc
ID: 35804744

One of three domain controllers had an incorrect time. fixed the time log off the exchange server and back on and was able to authenticate.
0
 
LVL 1

Expert Comment

by:PCS707
ID: 37516300
Thank you soostibi.  After synchronizing the time, I only had to log off and log back on without restarting.  
0

Featured Post

Ransomware-A Revenue Bonanza for Service Providers

Ransomware – malware that gets on your customers’ computers, encrypts their data, and extorts a hefty ransom for the decryption keys – is a surging new threat.  The purpose of this eBook is to educate the reader about ransomware attacks.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A brief introduction to what I consider to be the best editor for PowerShell.
This article aims to explain the working of CircularLogArchiver. This tool was designed to solve the buildup of log file in cases where systems do not support circular logging or where circular logging is not enabled
In this Micro Video tutorial you will learn the basics about Database Availability Groups and How to configure one using a live Exchange Server Environment. The video tutorial explains the basics of the Exchange server Database Availability grou…
This video demonstrates how to sync Microsoft Exchange Public Folders with smartphones using CodeTwo Exchange Sync and Exchange ActiveSync. To learn more about CodeTwo Exchange Sync and download the free trial, go to: http://www.codetwo.com/excha…

856 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question