Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

DC event ID 4 Source Kerberos

Posted on 2011-09-03
12
Medium Priority
?
607 Views
Last Modified: 2012-08-14
couple months back introduced 2 2k8 r2 DC to environment at decom 2 2k3 DC. and recently
other 2 2k3dc at branch office having replication issue. Event ID 4 found.
Netdiag show warining cannot resolve SPN dc
0
Comment
Question by:hell_angel
  • 7
  • 3
  • 2
12 Comments
 
LVL 10

Expert Comment

by:abhijitwaikar
ID: 36478374
Hi,

Check this:  
http://www.eventid.net/display.asp?eventid=4&eventno=1968&source=Kerberos&phase=1
http://technet.microsoft.com/en-us/library/cc733987(WS.10).aspx
http://www.microsoft.com/technet/support/ee/transform.aspx?ProdName=Windows%20Operating%20System&ProdVer=5.2&EvtID=4&EvtSrc=Kerberos&LCID=1033

Also provide us more info about firewall, port, site link to help you.

Regards,
Abhijit Waikar.
MCSA|MCSA:Messaging|MCTS|MCITP:SA
My Blog: http://abhijitw.wordpress.com
This posting is provided AS IS with no warranties, and confers no rights.
0
 

Author Comment

by:hell_angel
ID: 36479237
hi...there is no firewall between to site... is IPVPN connection....
0
 

Author Comment

by:hell_angel
ID: 36479240
check through... there is no duplicate name as well... if i delete my DNS zone and recreate it will it help..?
0
Creating Active Directory Users from a Text File

If your organization has a need to mass-create AD user accounts, watch this video to see how its done without the need for scripting or other unnecessary complexities.

 
LVL 10

Expert Comment

by:abhijitwaikar
ID: 36480715
First of all check the DNS pointing on each server, they should point itself or local DNS server as primary and remote DNS server as a secondary.

Once you confirmed the DNS and IP setting run - ipconfig /flushdns & ipconfig /registerdns on each DC.

also restart DNS and Netlogonservice on each dc.

If issue reoccurs try to rest secure cannel as event indicates that the password used to encrypt the kerberos service ticket is different than that on the target server.  
Active Directory – Resetting secure channel: http://abhijitw.wordpress.com/2011/08/31/active-directory-resetting-secure-channel/

Regards,
Abhijit Waikar.
----------------------------
MCSA|MCSA:Messaging|MCTS|MCITP:SA
My Blog: http://abhijitw.wordpress.com
This posting is provided AS IS with no warranties, and confers no rights.
1
 

Author Comment

by:hell_angel
ID: 36480810
branch server event error logged that can't authenticate with my fsmo role holder which is newly deployed.. meant i should run the reset command to reset my both newly deployed AD..?
what will be the implication...?
0
 
LVL 24

Expert Comment

by:Awinish
ID: 36480811
0
 

Author Comment

by:hell_angel
ID: 36480823
checked through DNS record... no duplicate....
0
 
LVL 10

Accepted Solution

by:
abhijitwaikar earned 2000 total points
ID: 36481577
Yes, run the provided command on problematic DC, follow the steps which are provided in article.

If you run Netdom on "newly deployed AD" with the correct parameters, the password is changed locally and is simultaneously written on main DC, and replication propagates the change to other domain controllers.
0
 

Author Comment

by:hell_angel
ID: 36484489
i did a netdom verify, the server verified successfuly.. still need to reset passwor for tha DC..?
0
 
LVL 24

Expert Comment

by:Awinish
ID: 36484565
Its case of duplicate SPN, resetting the secure channel will not resolve the issue. Please refer the earlier posted article to get rid of duplicate SPN.

Regards
________________________________________
Awinish Vishwakarma
MY BLOG:  http://awinish.wordpress.com
0
 

Author Comment

by:hell_angel
ID: 36500546
im going to do a password reset for the problematic server, before that, any possible if the server can't login after stop the KCC service and reboot..?
0
 

Author Closing Comment

by:hell_angel
ID: 36568311
n/a
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Uncontrolled local administrators groups within any organization pose a huge security risk. Because these groups are locally managed it becomes difficult to audit and maintain them.
A bad practice commonly found during an account life cycle is to set its password to an initial, insecure password. The Password Reset Tool was developed to make the password reset process easier and more secure.
This video shows how to use Hyena, from SystemTools Software, to update 100 user accounts from an external text file. View in 1080p for best video quality.
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…
Suggested Courses

971 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question