Improve company productivity with a Business Account.Sign Up

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 2118
  • Last Modified:

Security-Kerberos event 4

Hi I'm receiving this error as below how can be fixed?

The Kerberos client received a KRB_AP_ERR_MODIFIED error from the server host/mailbesa.domain.besa.org.al. The target name used was DNS/mailbesa.domain.besa.org.al. This indicates that the target server failed to decrypt the ticket provided by the client. This can occur when the target server principal name (SPN) is registered on an account other than the account the target service is using. Please ensure that the target SPN is registered on, and only registered on, the account used by the server. This error can also happen when the target service is using a different password for the target service account than what the Kerberos Key Distribution Center (KDC) has for the target service account. Please ensure that the service on the server and the KDC are both updated to use the current password. If the server name is not fully qualified, and the target domain (DOMAIN.BESA.ORG.AL) is different from the client domain (DOMAIN.BESA.ORG.AL), check if there are identically named server accounts in these two domains, or use the fully-qualified name to identify the server.


- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
  <Provider Name="Microsoft-Windows-Security-Kerberos" Guid="{98E6CFCB-EE0A-41E0-A57B-622D4E1B30B1}" EventSourceName="Kerberos" />
  <EventID Qualifiers="16384">4</EventID>
  <Version>0</Version>
  <Level>2</Level>
  <Task>0</Task>
  <Opcode>0</Opcode>
  <Keywords>0x80000000000000</Keywords>
  <TimeCreated SystemTime="2013-11-20T11:45:06.000000000Z" />
  <EventRecordID>165936</EventRecordID>
  <Correlation />
  <Execution ProcessID="0" ThreadID="0" />
  <Channel>System</Channel>
  <Computer>mailbesa1.domain.besa.org.al</Computer>
  <Security />
  </System>
- <EventData>
  <Data Name="Server">host/mailbesa.domain.besa.org.al</Data>
  <Data Name="TargetRealm">DOMAIN.BESA.ORG.AL</Data>
  <Data Name="Targetname">ldap/mailbesa.domain.besa.org.al</Data>
  <Data Name="ClientRealm">DOMAIN.BESA.ORG.AL</Data>
  <Binary />
  </EventData>
  </Event>

Thank you
0
akokalari
Asked:
akokalari
1 Solution
 
Chris MatthewsCommented:
Looks like a DNS issue.  Delete all non static dns entries in the zone and reverse zone.  Set DHCP to update DNS.  It may take a few days for the errors to clear out but they should after dns registers the correct ip addresses.


If you look in dns now you probably have multiple machine names listed with the same IP
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Creating Active Directory Users from a Text File

If your organization has a need to mass-create AD user accounts, watch this video to see how its done without the need for scripting or other unnecessary complexities.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now