Kerberos error

I am having an issue where two Windows Domain Controllers do not appear to be "talking".  I have two DCs: Netserver1 (running Windows Server 2008) and Netserver2 (running Windows Server 2008 R2).  I am getting the following attached error on Netserver2:  KRB_AP_ERR_MODIFIED error from the server Netserver3$.  Any assistance on correcting this would be appreciated.
Error1.pdf
PhilshAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Randy DownsOWNERCommented:
Try this.

To resolve this issue the service principal name must be searched for and removed from the alternative account and then it must be added to the correct account in Active Directory. To do that follow these steps:

At an elevated command prompt and using Enterprise Administrator credentials, run the command "setspn -Q <SPN>". This will return a computer name. SetSPN.exe is installed with the Active Directory Directory Services role or with RSAT.
Remove the incorrectly registered SPN by going to the command prompt and running the command "setspn -D <SPN> <computername>".
Add the SPN to the correct account at the command prompt by running the command "setspn -A <SPN> <computername of computer which had the System event 4>".
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
John Gates, CISSPSecurity ProfessionalCommented:
If the above did not work then on netserver2 server at a command prompt run:

dcdiag /v > dcdiag.txt

Read the contents and post what things are failing.  There are a couple things that could cause that error.  Make sure the time on both servers is synchronized and there is not greater than 5 mins difference as well.  Let me know the result of the command above and I can help further.

-D-
0
John Gates, CISSPSecurity ProfessionalCommented:
You will have to type notepad dcdiag.txt that is where the output of the command will be.
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Windows Server 2008

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.