Re: Multiple accounts with the name MSSQLSvc...

From: Jens Süßmeyer (Jens_at_Remove_this_For_Contacting.sqlserver2005.de)
Date: 04/28/05

  • Next message: Jens Süßmeyer: "Re: Login failed for user 'sa'"
    Date: Thu, 28 Apr 2005 11:57:54 +0200
    
    

    Somebody setup the SPN for the service account on those machines,
    unfortunately the same SPN has been promoted more than one time.

    Jens Suessmeyer.

    "Michel Schuurman" <ms_remove_@omni-trade.nl> schrieb im Newsbeitrag
    news:uW9$Ad9SFHA.2172@tk2msftngp13.phx.gbl...
    > Hi,
    >
    > Got a KDC Error with the following description:
    >
    > ==========================================
    > Event Type: Error
    > Event Source: KDC
    > Event Category: None
    > Event ID: 11
    > Date: 28-04-2005
    > Time: 2:01:01
    > User: N/A
    > Computer: server
    > Description:
    > There are multiple accounts with name MSSQLSvc/server.domain.local:1433 of
    > type DS_SERVICE_PRINCIPAL_NAME.
    >
    > For more information, see Help and Support Center at
    > http://go.microsoft.com/fwlink/events.asp.
    > ==========================================
    >
    >
    > The LDP-tool gives the following results:
    >
    > ==========================================
    > ***Searching...
    > ldap_search_s(ld, "DC=domain,DC=local", 2,
    > "serviceprincipalname=MSSQLSvc/server.domain.local:1433", attrList, 0,
    > &msg)
    > Result <0>: (null)
    > Matched DNs:
    > Getting 2 entries:
    >>> Dn: CN=Administrator,CN=Users,DC=domain,DC=local
    > 4> objectClass: top; person; organizationalPerson; user;
    > 1> cn: Administrator;
    > 1> description: Built-in account for administering the computer/domain;
    > 1> distinguishedName: CN=Administrator,CN=Users,DC=domain,DC=local;
    > 1> name: Administrator;
    > 1> canonicalName: domain.local/Users/Administrator;
    >>> Dn: CN=server,OU=Domain Controllers,DC=domain,DC=local
    > 5> objectClass: top; person; organizationalPerson; user; computer;
    > 1> cn: server;
    > 1> distinguishedName: CN=server,OU=Domain Controllers,DC=domain,DC=local;
    > 1> name: server;
    > 1> canonicalName: domain.local/Domain Controllers/server;
    > ==========================================
    >
    > Can anyone explain me what I can do about this? Deleting one of the
    > accounts is not an option I guess... I read that in some cases a computer
    > or user should be unregistered en registered again but in this case I'm
    > not so confident about it re-registring the Server itself or the
    > administrator-account..
    >
    > Any help on this is much appreciated.
    >
    >
    >
    > Michel Schuurman
    >
    > Omni Trade Automatisering B.V.
    >


  • Next message: Jens Süßmeyer: "Re: Login failed for user 'sa'"

    Relevant Pages

    • Re: SPN for SSL over common name
      ... you can't register those SPNs under the SQL Server's ... service account is the MSSQL SPN. ... That SPN should be registered under ... Lastly, since the SQL Server is not being used for delegation anywhere, ...
      (microsoft.public.inetserver.iis.security)
    • Re: SPN for SSL over common name
      ... you can't register those SPNs under the SQL Server's ... That SPN should be registered under the SQL ... Server's service account and *removed* from the SQL ... Lastly, since the SQL Server is not being used for delegation anywhere, ...
      (microsoft.public.inetserver.iis.security)
    • Re: Kerberos w/ SQL and WIN2000
      ... are not using Linked Servers then you don't need to set up an SPN AFAIK ... Win2000 will default to using kerberos to connect to the server anyway ... For my server called sqlnlb01 in domain domsql.com using a service account ...
      (microsoft.public.sqlserver.security)
    • Re: SPN for SSL over common name
      ... That SPN should be registered under the SQL ... Server's service account and *removed* from the SQL Server's ... Lastly, since the SQL Server is not being used for delegation anywhere, it's ...
      (microsoft.public.inetserver.iis.security)
    • Re: SPN for SSL over common name
      ... you can't register those SPNs under the SQL Server's ... That SPN should be registered under the SQL ... Server's service account and *removed* from the SQL Server's ... Lastly, since the SQL Server is not being used for delegation anywhere, ...
      (microsoft.public.inetserver.iis.security)