Solved

Security-Kerberos event 4

Posted on 2013-11-20
1
1,914 Views
Last Modified: 2014-04-30
Hi I'm receiving this error as below how can be fixed?

The Kerberos client received a KRB_AP_ERR_MODIFIED error from the server host/mailbesa.domain.besa.org.al. The target name used was DNS/mailbesa.domain.besa.org.al. This indicates that the target server failed to decrypt the ticket provided by the client. This can occur when the target server principal name (SPN) is registered on an account other than the account the target service is using. Please ensure that the target SPN is registered on, and only registered on, the account used by the server. This error can also happen when the target service is using a different password for the target service account than what the Kerberos Key Distribution Center (KDC) has for the target service account. Please ensure that the service on the server and the KDC are both updated to use the current password. If the server name is not fully qualified, and the target domain (DOMAIN.BESA.ORG.AL) is different from the client domain (DOMAIN.BESA.ORG.AL), check if there are identically named server accounts in these two domains, or use the fully-qualified name to identify the server.


- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
  <Provider Name="Microsoft-Windows-Security-Kerberos" Guid="{98E6CFCB-EE0A-41E0-A57B-622D4E1B30B1}" EventSourceName="Kerberos" />
  <EventID Qualifiers="16384">4</EventID>
  <Version>0</Version>
  <Level>2</Level>
  <Task>0</Task>
  <Opcode>0</Opcode>
  <Keywords>0x80000000000000</Keywords>
  <TimeCreated SystemTime="2013-11-20T11:45:06.000000000Z" />
  <EventRecordID>165936</EventRecordID>
  <Correlation />
  <Execution ProcessID="0" ThreadID="0" />
  <Channel>System</Channel>
  <Computer>mailbesa1.domain.besa.org.al</Computer>
  <Security />
  </System>
- <EventData>
  <Data Name="Server">host/mailbesa.domain.besa.org.al</Data>
  <Data Name="TargetRealm">DOMAIN.BESA.ORG.AL</Data>
  <Data Name="Targetname">ldap/mailbesa.domain.besa.org.al</Data>
  <Data Name="ClientRealm">DOMAIN.BESA.ORG.AL</Data>
  <Binary />
  </EventData>
  </Event>

Thank you
0
Comment
Question by:akokalari
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
1 Comment
 
LVL 2

Accepted Solution

by:
Chris Matthews earned 500 total points
ID: 39662680
Looks like a DNS issue.  Delete all non static dns entries in the zone and reverse zone.  Set DHCP to update DNS.  It may take a few days for the errors to clear out but they should after dns registers the correct ip addresses.


If you look in dns now you probably have multiple machine names listed with the same IP
0

Featured Post

Webinar: Aligning, Automating, Winning

Join Dan Russo, Senior Manager of Operations Intelligence, for an in-depth discussion on how Dealertrack, leading provider of integrated digital solutions for the automotive industry, transformed their DevOps processes to increase collaboration and move with greater velocity.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

To effectively work with Diskpart on a Server Core, it is necessary to write some small batch script's, because you can't execute diskpart in a remote powershell session. To get startet, place the Diskpart batch script's into a share on your loca…
You might have come across a situation when you have Exchange 2013 server in two different sites (Production and DR). After adding the Database copy in ECP console it displays Database copy status unknown for the DR exchange server. Issue is strange…
This tutorial will give a short introduction and overview of Backup Exec 2012 and how to navigate and perform basic functions. Click on the Backup Exec button in the upper left corner. From here, are global settings for the application such as conne…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …

739 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question