Re: kerberos

From: Mike Schmalz (mschmalz)
Date: 11/26/03


Date: Wed, 26 Nov 2003 06:51:11 -0800

I am having the exact same issue in the same situation. Here is some info on my situation. Luna is my server, and I have replaced the domain with "mydomain" and if it is an FQDN I have typed "mydomain.com"

If I run netdiag on the Server 2003 member server, the Kerberos Test fails with the following: [FATAL] Kerberos does not have a ticket for host/luna.mydomain.com At that time, I have the following events logged as I have turned on Kerberos Logging on this member server:

Event Type: Error
Event Source: Kerberos
Event Category: None
Event ID: 3
Date: 11/26/2003
Time: 9:21:30 AM
User: N/A
Computer: LUNA
Description:
A Kerberos Error Message was received:
         on logon session
 Client Time:
 Server Time: 14:21:30.0000 11/26/2003 Z
 Error Code: 0x7 KDC_ERR_S_PRINCIPAL_UNKNOWN
 Extended Error:
 Client Realm:
 Client Name:
 Server Realm: MYDOMAIN.COM
 Server Name: krbtgt/MYDOMAIN.COM
 Target Name: cifs/COMPUTERTHATNOLONGEREXISTS.mydomain.com@MYDOMAIN.COM
 Error Text:
 File: 9
 Line: ab8
 Error Data is in record data.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.

-----------------------------------------------------------------------------------------

Event Type: Error
Event Source: Kerberos
Event Category: None
Event ID: 3
Date: 11/26/2003
Time: 9:21:30 AM
User: N/A
Computer: LUNA
Description:
A Kerberos Error Message was received:
         on logon session
 Client Time:
 Server Time: 14:21:30.0000 11/26/2003 Z
 Error Code: 0xe KDC_ERR_ETYPE_NOTSUPP
 Extended Error:
 Client Realm:
 Client Name:
 Server Realm: MYDOMAIN.COM
 Server Name: krbtgt/MYDOMAIN.COM
 Target Name: host/luna.mydomain.com@MYDOMAIN.COM
 Error Text:
 File: 9
 Line: ab8
 Error Data is in record data.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.

-----------------------------------------------------------------------------------------

Event Type: Error
Event Source: Kerberos
Event Category: None
Event ID: 3
Date: 11/26/2003
Time: 9:34:03 AM
User: N/A
Computer: LUNA
Description:
A Kerberos Error Message was received:
         on logon session
 Client Time:
 Server Time: 14:34:3.0000 11/26/2003 Z
 Error Code: 0x7 KDC_ERR_S_PRINCIPAL_UNKNOWN
 Extended Error:
 Client Realm:
 Client Name:
 Server Realm: MYDOMAIN.COM
 Server Name: krbtgt/MYDOMAIN.COM
 Target Name: ldap/DOMAIN_CONTROLLER_IP_ADDRESS@MYDOMAIN.COM
 Error Text:
 File: 9
 Line: ab8
 Error Data is in record data.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.

-----------------------------------------------------------------------------------------

Event Type: Error
Event Source: Kerberos
Event Category: None
Event ID: 3
Date: 11/26/2003
Time: 9:34:03 AM
User: N/A
Computer: LUNA
Description:
A Kerberos Error Message was received:
         on logon session
 Client Time:
 Server Time: 14:34:3.0000 11/26/2003 Z
 Error Code: 0x7 KDC_ERR_S_PRINCIPAL_UNKNOWN
 Extended Error:
 Client Realm:
 Client Name:
 Server Realm: MYDOMAIN.COM
 Server Name: krbtgt/MYDOMAIN.COM
 Target Name: ldap/OTHER_DC_IP_ADDRESS@MYDOMAIN.COM
 Error Text:
 File: 9
 Line: ab8
 Error Data is in record data.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.



Relevant Pages

  • Event ID:3 Numerous Kerberos Errors
    ... Server: krbtgt/domain.COM@xxxxxxxxxx ... A Kerberos Error Message was received: ... Client Realm: ... Error Data is in record data. ...
    (microsoft.public.windows.server.general)
  • Trusted domain not show in "Entire Directory" list.
    ... Client Realm: ... Server Realm: OLD_DOMAIN.COM ... Error Data is in record data. ...
    (microsoft.public.windows.server.active_directory)
  • Re: SetSPN problem
    ... > Jasper Smith (SQL Server MVP) ... > Client Realm: ... > Error Data is in record data. ...
    (microsoft.public.sqlserver.security)
  • Re: Kerberos error
    ... Client Realm: ... Server Realm: DOOM.ABC.COM ... Error Data is in record data. ...
    (microsoft.public.win2000.active_directory)
  • Re: Kerberos Issues
    ... > I get a ton of Kerberos event log items. ... > Client Realm: ... > Error Data is in record data. ...
    (microsoft.public.win2000.security)