Event ID 675 - Pre-authentication failed

From: Stephane Charbonneau (stephane.charbonneau@synatek.com)
Date: 03/14/03


From: stephane.charbonneau@synatek.com (Stephane Charbonneau)
Date: 14 Mar 2003 10:07:59 -0800


We're adding a 3rd Party certificates into AD to allow for smart card
logon. I've almost got the solution working:

- CA cert in GP and NTAuth
- DC certs deployed on a single forest, single domain, single domain
controller (with appropriate extensions)
- UPN on user certs, along with the required info

I've used the certutil.exe tool from .NET Admin Tools to verifiy the
DC and user smart card certs and all looks good.

However, when attempting to log into the WinXPSP1 machine (with proper
DNS entries and is member of domain), I get the following error on the
KDC:

Source: Security
Event ID: 675

Pre-authentication failed:
  User Name: username
  User ID: DOMAIN\username
  Service Name: krbtgt/DOMAIN.COM
  Pre-Authentication Type: 0xF
  Failure Code: 0x10
  Client Address: <IP>

The client gets the following error:

"The server authenticating you reported an error (0x00000BB)..."

I can't find a reference to this error code, so am having some
difficulties in focusing my efforts.

Does anyone know what this failure code means?

Thanks,
Steph



Relevant Pages

  • Re: Single Sign-on authentication using Smart Cards
    ... The certs that I see using the ActivCard software show one ... for signature, encryption, and identity but I don't see one for logon. ... See the link below in Part II on planning a smart card deployment. ... I do have the Certs on the card but when I insert it during the logon ...
    (microsoft.public.win2000.security)
  • Re: Smart Card Logon
    ... Are the CRLs all accessible and available in the certs for the entire chain? ... > smart card logon cert to account in AD. ... > 2) Placed external CAs Root certificate in Trusted CA ...
    (microsoft.public.win2000.security)
  • RE: Smart Card - Sun.
    ... It will hold your certs. ... If you lose your smart card, ... I have a Sun Blade 100 workstation, running Solaris 9. ...
    (Security-Basics)