Re: Kerberos Error Message

From: Steven L Umbach (n9rou_at_n0-spam-for-me-comcast.net)
Date: 09/10/04


Date: Fri, 10 Sep 2004 16:52:18 GMT

First check that basic dns configuration is correct as dns misconfiguration is the
root of most domain problems. Domain controllers must point to themselves and/or the
pdc fsmo domain controller. See the link below on AD dns FAQ.

http://support.microsoft.com/default.aspx?scid=kb%3Ben-us%3B291382

You can also use the support tools netdiag and dcdiag to check for domain controller
health. The both will run a battery of tests to check for proper configuration
including kerberos and you can use the /v switch with netdiag as in " netdiag
/test:kerberos /v ". --- Steve

http://support.microsoft.com/default.aspx?scid=kb;en-us;321708 -- netdiag and how to
install support tools.

"PC" <paulm DOT c at iol DOT ie> wrote in message
news:uVIY3ExlEHA.1244@TK2MSFTNGP15.phx.gbl...
> Hi,
>
> Hi Have a windows 2000 domain controllor. This server doesn't perform and
> Operations master roles. I have turned on Kerberos logging as I have been
> having some time sycronisation problem with some clients on the network.
>
> I'm receiveing a kerberos error every few hours (The doesn't seem to be any
> pattern as to when these errors occur). I have looked at eventID (EventID
> talks about domain trusts but this is a single domain with no trusts) and
> searched on google but I can't find anything about this specific error (Note
> in the error code: 0x20). The error is as follows:
>
> Event Type: Error
> Event Source: Kerberos
> Event Category: None
> Event ID: 594
> Date: 10/09/2004
> Time: 02:26:05
> User: N/A
> Computer: DCServer1
> Description:
> A Kerberos Error Message was received:
> on logon session InitializeSecurityContext
> Client Time:
> Server Time:
> Error Code: 1:26:5.0000 9/10/2004 (null) 0x20
> Extended Error: KRB_AP_ERR_TKT_EXPIRED
> Client Realm:
> Client Name:
> Server Realm: MyDomainName
> Server Name: krbtgt/MyDomainName
> Target Name: krbtgt/MyDomainName@MyDomainName
> Error Text:
> File:
> Line:
> Error Data is in record data.
>
> For more information, see Help and Support Center at
> http://go.microsoft.com/fwlink/events.asp.
>
>
> Does anybody know why I'm receiving this error or where I can find more
> information about it.
>
> Thanks
>
>
> Paul
>
>



Relevant Pages

  • Re: Creating a Virtual Domain
    ... "ipconfig /all" results for the DC and client virtual PCs respectively at ... Ethernet adapter Local Area Connection: ... Connection-specific DNS Suffix. ... > In general domain controller must also use Active Directory DNS (and _not_ ...
    (microsoft.public.windows.server.networking)
  • Re: Client performance problem windows 2003 server...
    ... there and install an english client to be doing the errorsearching on. ... to the Windows 2000 server in site A that is a English ... >>be a DNS replication issue. ... >>results from not having a domain controller in a particular site. ...
    (microsoft.public.windows.server.networking)
  • W2003 Active Directory + DNS - Can not join machine
    ... I'm trying to join a client machine to the DC. ... The client is a standalone Windows 2003 machine, ... DNS was successfully queried for the service location resource record ... - Host records that map the name of the domain controller to its IP ...
    (microsoft.public.windows.server.dns)
  • Re: cannot join WinXP to Windows 2000 domain
    ... another server W2003 DC for it's DNS and the LAN's DHCP ... I would even be willing to move the W2000 DNS services to reside on ... Host records that map the name of the domain controller to its ... Also you mix a bit 2 different items, client join problem and DC ...
    (microsoft.public.win2000.active_directory)
  • Re: cannot join WinXP to Windows 2000 domain
    ... Additional post an unedited ipconfig /all from both servers and the client machine. ... another server W2003 DC for it's DNS and the LAN's DHCP ... I would even be willing to move the W2000 DNS services to reside on ... Host records that map the name of the domain controller to its ...
    (microsoft.public.win2000.active_directory)