Re: Event ID 676

From: Anubis (anonymous_at_discussions.microsoft.com)
Date: 07/27/04


Date: Tue, 27 Jul 2004 10:18:23 +0100

Check out the DC that is listed, you should then find the corresponding
event there with the workstation IP address listed. I have also would that
Kerberos ticket error 12 can be caused by users being in too many groups. We
found this problem when trying to access EMC NAS devices.

"djc" <noone@nowhere.com> wrote in message
news:OW2Jen0cEHA.2812@tk2msftngp13.phx.gbl...
> thanks for the reply. I think where I am confused is the client address..
I
> am expecting it to be 'from where' the logon was attempted... like the
> user's workstation name... but that address is a domain controller?
actually
> I just double-checked and some of these events are from domain controller
> addresses and some are from client workstations? I am confused. I know the
> users don't have physical access to the servers so thats out. I suppose
> terminal services logon attempts could generate this? I'm just not sure
how
> to interprets these security auditing events.
>
> "Steven L Umbach" <n9rou@n0-spam-for-me-comcast.net> wrote in message
> news:3KcNc.161924$a24.85480@attbi_s03...
> > That would seem to be the case. Failure code 0x12 can be a variety of
> reasons but not
> > having the user right for access could certainly be one. Below is a list
> of items I
> > found on a MS doc. --- Steve
> >
> > 0x12 - KDC_ERR_CLIENT_REVOKED: Clients credentials have been revoked
> > Associated internal Windows error codes
> > . STATUS_ACCOUNT_DISABLED
> >
> > . STATUS_ACCOUNT_EXPIRED
> >
> > . STATUS_ACCOUNT_LOCKED_OUT
> >
> > . STATUS_ACCOUNT_DISABLED
> >
> > . STATUS_INVALID_LOGON_HOURS
> >
> > . STATUS_LOGIN_TIME_RESTRICTION
> >
> > . STATUS_LOGIN_WKSTA_RESTRICTION
> >
> > . STATUS_ACCOUNT_RESTRICTION
> >
> >
> >
> >
> > "djc" <noone@nowhere.com> wrote in message
> > news:O18ZKI0cEHA.996@TK2MSFTNGP12.phx.gbl...
> > > Source: Security
> > > Category: Account Logon
> > > Authentication Ticket Request Failed:
> > > User Name: smithly
> > > Supplied Realm Name: HELLER.COM
> > > Service Name: krbtgt/HELLER.COM
> > > Ticket Options: 0x40810010
> > > Failure Code: 0x12
> > > Client Address: 10.10.100.100
> > >
> > > according to the info I found on this failure code (12), this event is
> > > because of a time of day or workstation restriction. This would seem
to
> make
> > > sense because the client address listed is a server that this user
would
> not
> > > have the log on locally user right assigned for.
> > >
> > > Is this correct, this is telling me that smithly has attemped to logon
> to
> > > 10.10.100.100?
> > >
> > >
> >
> >
>
>



Relevant Pages

  • Re: Local admin rights not flowing through
    ... It sounds like it could be a problem with contacting the domain controller ... You can check the security log on the client workstation, ... assuming auditing of logon events is enabled as shown in Local Security ... >>> the profile. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Slow login and difficulties accessing network reources
    ... Networking, Internet, Routing, VPN Troubleshooting on ... I have a remote site (with 4 workstation) connected over a VPN WAN ... Event Type: Error ... domain controller or the workstation, or is it the WAN connectivity between ...
    (microsoft.public.windows.server.networking)
  • Re: account lockout fails
    ... In my domain controller security log I received the following events ... Address is the workstation IP address. ... each other in the security log until there were a total of 24. ... domain lockout policy did not take effect and lock the account. ...
    (microsoft.public.win2000.security)
  • Re: Issues with w32tm on AD network
    ... Directory based network with just Windows servers. ... workstation, and NTP on that workstation keeps loosing the time, and ... I am using the NTP pool, but have done this for years on a Linux ... The domain members will stop detecting the domain controller ...
    (comp.protocols.time.ntp)
  • Re: Terminal Services and SBS 2003
    ... infect your workstations with malware on your domain controller?" ... 2000 and 2003 domain controllers (small companies with only one server). ... true equivalent of someone using your domain controller as a workstation" as ... run any applications that use the Internet. ...
    (microsoft.public.windows.server.sbs)