troubleshooting Question

KDC / Duplicate SPN - Ghost?

Avatar of SPLAT-Tech
SPLAT-TechFlag for United States of America asked on
Microsoft Legacy OSMicrosoft Server OSWindows Server 2008
14 Comments2 Solutions1779 ViewsLast Modified:
I am having an issue on one of my DCs. I keep getting an event log entry stating I have a duplicate SPN. The DC stops processing logins as a result.

The KDC encountered duplicate names while processing a Kerberos authentication request. The duplicate name is RPCSS/mis45 (of type DS_SERVICE_PRINCIPAL_NAME). This may result in authentication failures or downgrades to NTLM. In order to prevent this from occuring remove the duplicate entries for RPCSS/mis45 in Active Directory.

I am not however, able to find the duplicate SPN stated in the log entry.

C:\>setspn -X
Checking domain DC=splat,DC=com
Processing entry 11
found 0 group of duplicate SPNs.

C:\>setspn -l mis45
Registered ServicePrincipalNames for CN=MIS45,CN=Computers,DC=splat,DC=com:

I also ran the query at the Forrest level  and got 71 groups of duplicate entries on different systems. Some that don't exist anymore and some that still do including the mentioned culprit. The duplicates are however, on child domains. (I will deal with those later)

Why can't I find the duplicate SPN?
Could the duplicate SPN mentioned be in one of the child domains?
Why is only this DC getting the log entry?

Our community of experts have been thoroughly vetted for their expertise and industry experience.

Join our community to see this answer!
Unlock 2 Answers and 14 Comments.
Start Free Trial
Learn from the best

Network and collaborate with thousands of CTOs, CISOs, and IT Pros rooting for you and your success.

Andrew Hancock - VMware vExpert
See if this solution works for you by signing up for a 7 day free trial.
Unlock 2 Answers and 14 Comments.
Try for 7 days

”The time we save is the biggest benefit of E-E to our team. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange.

-Mike Kapnisakis, Warner Bros