MS05-042 Security Update Problems

From: Andrew McCullough (amccullough_at_ingeus.co.uk)
Date: 08/30/05

  • Next message: Thomas Krüger: "Re: Vulnerability in Helpdesk software Hesk 0.92"
    Date: Tue, 30 Aug 2005 18:00:22 +0100
    To: <bugtraq@securityfocus.com>
    
    

    Hello All,

    Has anyone else experienced problems after applying the Kerberos
    Security Update? We're running 2k3 server (Enterprise) as a DC with
    standard application set. Following the application of this patch we
    started seeing Kerberos and KDC issues. Once the patch had been applied
    we started seeing KDC (event ID 7) errors - "The Security Account
    Manager failed a KDC request in an unexpected way" and this error
    repeated for each DC on our domain.

    Following this, we started seeing Kerberos errors - Kerberos (event ID
    4) - The Kerberos client received a KRB_AP_ERR_MODIFIED error from the
    server computername. The target name was cifs/anothercomputer. This
    indicates that the password used to encrypt the Kerberos service ticket
    is different than that on the target server.

    This error had not appeared previously and no changes had been made to
    the mentioned computer or the target.

    We also experienced issues with a fileserver local to this DC being
    unable to print - presumably due to being unable to authenticate printer
    users.

    Having removed the Kerberos patch from the problem DC all appears to
    have returned to normal, however we'd like to know if anyone else has
    had this problem or if there are any ways to resolve the issues we had?

    Thanks in advance,

    Andy McCullough
    Information Technology & Telecommunications
    WorkDirections UK
    Email: amccullough@workdirections.co.uk

    Andrew McCullough
    Information Technology & Telecommunications
    WorkDirections UK
    Email: amccullough@workdirections.co.uk
     

    **********************************************************************
    The information, including attachments, contained in this e-mail is confidential and may be subject to legal professional privilege. It is intended solely for the addressee. If you receive this e-mail by mistake please promptly inform us by reply e-mail and then delete the e-mail and destroy any printed copy. You must not disclose or use in any way the information in the e-mail.

    There is no warranty that this email is error or virus free. It may be a private communication, and if so, does not represent the views of the Ingeus Group of Companies or its management. If it is a private communication, care should be taken in opening it to ensure that undue offence is not given.

    **********************************************************************


  • Next message: Thomas Krüger: "Re: Vulnerability in Helpdesk software Hesk 0.92"

    Relevant Pages

    • RE: Critical Errors in System Log
      ... EventID: 4 Source: Kerberos ... The kerberos client received a KRB_AP_ERR_MODIFIED error from the server ... the kerberos service ticket is different than that on the target server. ...
      (microsoft.public.windows.server.sbs)
    • Re: Cannot telnet some ports
      ... Some with remote administration feature I believe. ... POP3 Server 110 ... # Network services, Internet style ... kerberos 750/udp kdc # Kerberos udp ...
      (microsoft.public.windows.server.general)
    • RE: Can someone please tell me what this mean.
      ... Did you have a server crash before? ... The kerberos client received a KRB_AP_ERR_MODIFIED error from the ... that on the target server. ... machine accounts in the target realm, ...
      (microsoft.public.windows.server.general)
    • Re: kerberos error
      ... services on this server but I get ... The kerberos client received a KRB_AP_ERR_MODIFIED error from the ... different than that on the target server. ... which machine account do I need to fix and what is the client realm? ...
      (microsoft.public.windows.server.general)
    • RE: The kerberos client received a KRB_AP_ERR_MODIFIED error from the server
      ... following Kerberos error on your DCs after replacing a DC. ... The kerberos client received a KRB_AP_ERR_MODIFIED error from the server ... The target name used was SMTPSVC/mail.domain.com. ... Microsoft Online Newsgroup Support ...
      (microsoft.public.exchange.admin)