Re: Kerberos Error Getting Ticket From Domain: krb5kdc_err_s_principal_unknown



From what you have said it sounds like you are misinterpreting what is
happening. It is not that the DC is not recognizing the domain, but that
it is not recognizing the machine as a member of the domain, and hence
it is not granting a TGT to it. This might be because the join has problems
or perhaps the times are too far out of sync.

"Will" <westes-usc@xxxxxxxxxxxxxx> wrote in message
news:w4WdnfD8c87mBAbZnZ2dnUVZ_sWdnZ2d@xxxxxxxxxxxxxxx
Member server A is contacting domain controller my-dc1 in domain
hq.corp.com. What I am seeing in the sniffer trace is that the member
server asks the my-dc1 domain controller in its role as a Kerberos ticket
granter for a ticket to the domain (i.e., krbtgt/hq.corp.com). The
domain
controller is returning krb5kdc_err_s_principal_unknown. That can't be
good? What is the expected result when a member server asks for a ticket
for the entire domain?

The following line in the trace shows the member server asking for the
Kerberos ticket for the domain controller krbtgt/my-dc1 and this it does
obtain.

What would cause the domain controller to not recognize its own domain in
the Kerberos ticket request?

--
Will




.



Relevant Pages

  • RE: "Send As" permission resetting on SBS
    ... permission of the user account that is a member of one of administrative ... groups will be reset to match the ACL of the AdminSDHolder thread. ... Directory domain controller that holds the primary domain controller ...
    (microsoft.public.windows.server.sbs)
  • RE: "Send As" permission resetting on SBS
    ... permission of the user account that is a member of one of administrative ... groups will be reset to match the ACL of the AdminSDHolder thread. ... Directory domain controller that holds the primary domain controller ...
    (microsoft.public.windows.server.sbs)
  • Re: What policy change did I (or my colleague) make and how do I fix i
    ... Maybe you are no longer a member of the groups that are allowed access. ... If no one can logon locally to a domain controller you will need to ... change the user right settings from a non domain controller domain computer to ...
    (microsoft.public.windows.group_policy)
  • Re: Administrator cant change security
    ... administrators group on the domain member can configure permissions on any ... computers can not reliably contact a domain controller. ... I'm signing on as Administrator on a second Windows 2003 server that is ...
    (microsoft.public.windows.server.security)
  • Re: Remove domain with no domain controller
    ... Is the account you are logging on with a member of Enterprise Admins? ... For example, even if you are an administrator in domain A, you don't have ... permission to delete a domain controller in domain B. ...
    (microsoft.public.windows.server.active_directory)