Re: Kerberos Tickets



It is possible that the client computer can not find the domain controller
because of DNS problems with the client and/or domain controller. Read the
link below on Active Directory DNS FAQ to make sure your DNS is correctly
configured in the domain and NEVER use and ISP DNS server as a preferred DNS
server for any domain computer. Also use the support tools netdiag on any
domain computer and dcdiag on domain controllers only for further
troubleshooting of problems including DNS, dc discovery, secure channel, and
much more and look in the logs of the computers involved to see if any
pertinent errors/warnings are found. Domain computers also need to be kept
in synch time wise which should be done automatically. --- Steve

http://support.microsoft.com/default.aspx?scid=kb%3Ben-us%3B291382
http://support.microsoft.com/default.aspx?scid=kb;en-us;321708 --- netdiag
and support tools

"Brady" <Brady@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:CD175C37-0C46-46C1-8D78-9E5637BA4C86@xxxxxxxxxxxxxxxx
>I am looking for any information on a network event/anomaly that would help
> explain why a Kerberos ticket would expire or go stale. Our understanding
> is
> that if a domain controller is not avaialble for a period of time or
> unavailable at the time of login it could create this scenario. The
> question
> posed is what would create this behavior, being there was no indication
> that
> the DC was unavailable?


.



Relevant Pages

  • Remote Branch DC wont Replicate With Corporate DC
    ... Active Directory could not resolve the following DNS host name of the source ... domain controller to an IP address. ... 'Event' is not recognized as an internal or external command, ... operable program or batch file. ...
    (microsoft.public.windows.server.dns)
  • RPC Endpoint Mapper Error
    ... We are adding our first Windows 2003 Domain Controller to a Windows ... I checked DNS entries with articles from Microsoft on ... PASS - All the DNS entries for DC are registered on DNS server ... List of NetBt transports currently bound to the Redir ...
    (microsoft.public.win2000.active_directory)
  • Re: Replication event errors
    ... PASS - All the DNS entries for DC are registered on DNS server ... But as a test I manually added a dns alias for Domain controller: ... Active Directory failed to construct a mutual authentication service ... computer name of the source domain controller. ...
    (microsoft.public.windows.server.active_directory)
  • Re: the system cannot log you on now because the domain <domain>is not available
    ... What I would suggest trying, at least temporarily, is to open Domain Controller ... The other main concern is that dns is configured correctly for the whole domain. ... controllers running dns with the AD domain zone and NEVER an ISP dns server anywhere ... > event log showed teh failed attempts at locating the DC. ...
    (microsoft.public.windows.server.networking)
  • Re: Active Directory could not resolve DNS host name
    ... Best practices for DNS client settings in Windows 2000 Server and in Windows ... How to Verify the Creation of SRV Records for a Domain Controller ... Active Directory could not resolve the following DNS host name of the ...
    (microsoft.public.windows.server.active_directory)