Re: Random Kerberos Authentication access denied issues

From: Bernard (qbernard_at_hotmail.com.discuss)
Date: 12/01/04


Date: Wed, 1 Dec 2004 12:18:46 +0800

No idea, but you might want to take a look at the old posts
http://groups.google.com.my/groups?q=Error%20Code%3A%200x7%20%20KDC_ERR_S_PRINCIPAL_UNKNOWN&hl=en&lr=&sa=N&tab=wg

and
HOW TO: Troubleshoot Kerberos-Related Issues in IIS
http://support.microsoft.com/?id=326985

-- 
Regards,
Bernard Cheah
http://www.tryiis.com/
http://support.microsoft.com/
http://www.msmvps.com/bernard/
"Jag" <Jag@discussions.microsoft.com> wrote in message
news:C71C8A46-B0D2-4DE6-9561-01E879127644@microsoft.com...
> We have the following configuration...
>   several 2000 ADS servers
>   several  NT4 BDC domain servers
>   several IIS 6 on a 2003 member server
>   several IIS 5 on a 2000 member server
>
> The problem is that intermittantly we will fail to authenticate via
Kerberos
> to a web site that pulls up a list of options in IE based upon NT group
> membership.
> The end user with IE receives an access denied permission error and the
web
> server logs the following event.
>       A Kerberos Error Message was received:  on logon session
>  Client Time:
>  Server Time: 18:47:1.0000 9/17/2004 Z
>  Error Code: 0x7  KDC_ERR_S_PRINCIPAL_UNKNOWN
>  Extended Error:
>  Client Realm:
>  Client Name:
>  Server Realm: USXPRESS.COM
>  Server Name: krbtgt/USXPRESS.COM
>  Target Name: host/xgsthlweb.usxpress.com@USXPRESS.COM
>  Error Text:
>  File: 9
>  Line: ab8
>  Error Data is in record data.
> For more information, .....
>
> The problem will go away for about a week then come back.  When we get the
> error it happens to all users even admins regardless of what computer they
> are using or what version of IE they are useing.  In the past I was able
to
> set the application pool identity from predefined "network service" to
"local
> service" and it would work for a few days no problems then when it fails
> again I can switch the application pool identity from predefined "local
> service" to "network service" and it will work for a while then fail
again.
> I never have any problems with the web site on the 2000 server with IIS 5,
> only with the 2003 server with IIS 6.  I have gone through all the docs on
> troubleshooting Kerberos issues and everything looks good.
> The fact that it works for a while and then fails has me confused... I
could
> understand it not working but to work and then stop when no changes were
made
> is beyond me.  Anyone have any idea what might be causing this?
>
> Thanks
>


Relevant Pages

  • RE: Backup, Monitoring and Reporting:Program cannot display the we
    ... Reporting and Backup page from the Server Management console. ... a.Add Local Service and Network Service account Read & Execute, ... IIS 6.0 Compression Corruption Causes Access Violations ... Install MBExplorer by installing IIS 6 Resource Kit Tools: ...
    (microsoft.public.windows.server.sbs)
  • [NT] Heap Overrun in HTR Chunked Encoding Could Enable Web Server Compromise
    ... This patch eliminates a newly discovered vulnerability affecting Internet ... in IIS 4.0 and 5.0, and could likewise be used to overrun heap memory on ... allowing code to be run on the server. ... * Microsoft has long recommended disabling HTR functionality unless there ...
    (Securiteam)
  • Re: Problem with connect computer wizard
    ... Make sure the Windows XP client is pointing to the SBS 2003 server as ... Please collect the IIS metabase and the latest IIS log files further ... This newsgroup only focuses on SBS technical issues. ...
    (microsoft.public.windows.server.sbs)
  • RE: IIS Key pairs (how to export an IIS 4.0 self-issued Root CA a nd import into new IIS 4.0 box)
    ... IIS key to an Intel SSL acelerator ... it issues client certificates to the end users. ... Step I - Installing the New Server ... Install NT SP 3 ONLY ...
    (Focus-Microsoft)
  • Re: SBS 2003 After Service Pack 1 for SBS
    ... we can conclude the SBS 2003 SP1 has been applied ... Please help me collect the IIS metabase to check ... and using server management console to reproduce the problem. ... This newsgroup only focuses on SBS technical issues. ...
    (microsoft.public.windows.server.sbs)

Loading