I have a single server environment (Windows Server 2003) which is a DC (amongst other things) and after a scheduled reboot I noticed that a bunch of Services would not start, and the following error in eventvwr:
Event Type: Warning
Event Source: KDC
Event Category: None
Event ID: 20
Time: 11:49:14 PM
The currently selected KDC certificate was once valid, but now is invalid and no suitable replacement was found. Smartcard logon may not function correctly if this problem is not remedied. Have the system administrator check on the state of the domain's public key infrastructure. The chain status is in the error data.
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp
0000: 00 00 00 00 00 00 00 00 ........
0008: 00 00 00 00 00 00 00 00 ........
I have done a look online and most are saying to run "Certutil -dcinfo deleteBad" but I get errors back from this, even after a reboot.