Solved

Security-Kerberos event 4

Posted on 2013-11-20
1
1,856 Views
Last Modified: 2014-04-30
Hi I'm receiving this error as below how can be fixed?

The Kerberos client received a KRB_AP_ERR_MODIFIED error from the server host/mailbesa.domain.besa.org.al. The target name used was DNS/mailbesa.domain.besa.org.al. This indicates that the target server failed to decrypt the ticket provided by the client. This can occur when the target server principal name (SPN) is registered on an account other than the account the target service is using. Please ensure that the target SPN is registered on, and only registered on, the account used by the server. This error can also happen when the target service is using a different password for the target service account than what the Kerberos Key Distribution Center (KDC) has for the target service account. Please ensure that the service on the server and the KDC are both updated to use the current password. If the server name is not fully qualified, and the target domain (DOMAIN.BESA.ORG.AL) is different from the client domain (DOMAIN.BESA.ORG.AL), check if there are identically named server accounts in these two domains, or use the fully-qualified name to identify the server.


- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
  <Provider Name="Microsoft-Windows-Security-Kerberos" Guid="{98E6CFCB-EE0A-41E0-A57B-622D4E1B30B1}" EventSourceName="Kerberos" />
  <EventID Qualifiers="16384">4</EventID>
  <Version>0</Version>
  <Level>2</Level>
  <Task>0</Task>
  <Opcode>0</Opcode>
  <Keywords>0x80000000000000</Keywords>
  <TimeCreated SystemTime="2013-11-20T11:45:06.000000000Z" />
  <EventRecordID>165936</EventRecordID>
  <Correlation />
  <Execution ProcessID="0" ThreadID="0" />
  <Channel>System</Channel>
  <Computer>mailbesa1.domain.besa.org.al</Computer>
  <Security />
  </System>
- <EventData>
  <Data Name="Server">host/mailbesa.domain.besa.org.al</Data>
  <Data Name="TargetRealm">DOMAIN.BESA.ORG.AL</Data>
  <Data Name="Targetname">ldap/mailbesa.domain.besa.org.al</Data>
  <Data Name="ClientRealm">DOMAIN.BESA.ORG.AL</Data>
  <Binary />
  </EventData>
  </Event>

Thank you
0
Comment
Question by:akokalari
1 Comment
 
LVL 2

Accepted Solution

by:
Chris Matthews earned 500 total points
ID: 39662680
Looks like a DNS issue.  Delete all non static dns entries in the zone and reverse zone.  Set DHCP to update DNS.  It may take a few days for the errors to clear out but they should after dns registers the correct ip addresses.


If you look in dns now you probably have multiple machine names listed with the same IP
0

Featured Post

Don't lose your head updating email signatures!

Do your end users still have the wrong email signature? Do email signature updates bore you or fill you with a sense of dread? You can make this a whole lot easier on yourself by trusting an Exclaimer email signature management solution. Over 50 million users do...so should you!

Join & Write a Comment

We recently had an issue where out of nowhere, end users started indicating that their logins to our terminal server were just showing a "blank screen." After checking the usual suspects -- profiles, shell=explorer.exe in the registry, userinit.exe,…
If you migrate a Terminal Server licenses server inside the 2008 server family, you can takte advantage of the build-in migration tool. If you like to migrate an older 2003 Server (and the installed client CALs) to a 2008 R2 server for example, you …
This tutorial will walk an individual through locating and launching the BEUtility application to properly change the service account username and\or password in situation where it may be necessary or where the password has been inadvertently change…
This tutorial will show how to configure a new Backup Exec 2012 server and move an existing database to that server with the use of the BEUtility. Install Backup Exec 2012 on the new server and apply all of the latest hotfixes and service packs. The…

747 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now