Solved

DC event ID 4 Source Kerberos

Posted on 2011-09-03
12
585 Views
Last Modified: 2012-08-14
couple months back introduced 2 2k8 r2 DC to environment at decom 2 2k3 DC. and recently
other 2 2k3dc at branch office having replication issue. Event ID 4 found.
Netdiag show warining cannot resolve SPN dc
0
Comment
Question by:hell_angel
  • 7
  • 3
  • 2
12 Comments
 
LVL 10

Expert Comment

by:abhijitwaikar
Comment Utility
Hi,

Check this:  
http://www.eventid.net/display.asp?eventid=4&eventno=1968&source=Kerberos&phase=1
http://technet.microsoft.com/en-us/library/cc733987(WS.10).aspx
http://www.microsoft.com/technet/support/ee/transform.aspx?ProdName=Windows%20Operating%20System&ProdVer=5.2&EvtID=4&EvtSrc=Kerberos&LCID=1033

Also provide us more info about firewall, port, site link to help you.

Regards,
Abhijit Waikar.
MCSA|MCSA:Messaging|MCTS|MCITP:SA
My Blog: http://abhijitw.wordpress.com
This posting is provided AS IS with no warranties, and confers no rights.
0
 

Author Comment

by:hell_angel
Comment Utility
hi...there is no firewall between to site... is IPVPN connection....
0
 

Author Comment

by:hell_angel
Comment Utility
check through... there is no duplicate name as well... if i delete my DNS zone and recreate it will it help..?
0
 
LVL 10

Expert Comment

by:abhijitwaikar
Comment Utility
First of all check the DNS pointing on each server, they should point itself or local DNS server as primary and remote DNS server as a secondary.

Once you confirmed the DNS and IP setting run - ipconfig /flushdns & ipconfig /registerdns on each DC.

also restart DNS and Netlogonservice on each dc.

If issue reoccurs try to rest secure cannel as event indicates that the password used to encrypt the kerberos service ticket is different than that on the target server.  
Active Directory – Resetting secure channel: http://abhijitw.wordpress.com/2011/08/31/active-directory-resetting-secure-channel/

Regards,
Abhijit Waikar.
----------------------------
MCSA|MCSA:Messaging|MCTS|MCITP:SA
My Blog: http://abhijitw.wordpress.com
This posting is provided AS IS with no warranties, and confers no rights.
1
 

Author Comment

by:hell_angel
Comment Utility
branch server event error logged that can't authenticate with my fsmo role holder which is newly deployed.. meant i should run the reset command to reset my both newly deployed AD..?
what will be the implication...?
0
 
LVL 24

Expert Comment

by:Awinish
Comment Utility
0
How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

 

Author Comment

by:hell_angel
Comment Utility
checked through DNS record... no duplicate....
0
 
LVL 10

Accepted Solution

by:
abhijitwaikar earned 500 total points
Comment Utility
Yes, run the provided command on problematic DC, follow the steps which are provided in article.

If you run Netdom on "newly deployed AD" with the correct parameters, the password is changed locally and is simultaneously written on main DC, and replication propagates the change to other domain controllers.
0
 

Author Comment

by:hell_angel
Comment Utility
i did a netdom verify, the server verified successfuly.. still need to reset passwor for tha DC..?
0
 
LVL 24

Expert Comment

by:Awinish
Comment Utility
Its case of duplicate SPN, resetting the secure channel will not resolve the issue. Please refer the earlier posted article to get rid of duplicate SPN.

Regards
________________________________________
Awinish Vishwakarma
MY BLOG:  http://awinish.wordpress.com
0
 

Author Comment

by:hell_angel
Comment Utility
im going to do a password reset for the problematic server, before that, any possible if the server can't login after stop the KCC service and reboot..?
0
 

Author Closing Comment

by:hell_angel
Comment Utility
n/a
0

Featured Post

6 Surprising Benefits of Threat Intelligence

All sorts of threat intelligence is available on the web. Intelligence you can learn from, and use to anticipate and prepare for future attacks.

Join & Write a Comment

The saying goes a bad carpenter blames his tools. In the Directory Services world a bad system administrator, well, even with the best tools they’re probably not going to become an all star.  However for the system admin who is willing to spend a li…
Companies that have implemented Microsoft’s Active Directory need to ensure that the Active Directory is configured and operating properly. If there are issues found and not resolved, it eventually leads the components to fail or stop working and fi…
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now