[31969] in Kerberos

home help back first fref pref prev next nref lref last post

Re: Windows event id 4 (kerberos)

daemon@ATHENA.MIT.EDU (raj esh L)
Wed Jan 20 14:49:51 2010

Message-ID: <396550.77258.qm@web50001.mail.re2.yahoo.com>
Date: Wed, 20 Jan 2010 11:49:46 -0800 (PST)
From: raj esh L <rrcrajesh2003@yahoo.com>
To: "Douglas E. Engert" <deengert@anl.gov>
In-Reply-To: <4B57591E.8080205@anl.gov>
MIME-Version: 1.0
Cc: kerberos@mit.edu, kerberos-owner@mit.edu
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu

Hi,

Thanks for your response

I found many people faced these sort of problems on DCs and suggested to check SPN duplications. I verified those and could find any issues with it. But we are facing on member server which acts as print server. 

I verified this article and it is more related to IIS. However I checked DNS side and do not find any problem. If some one assist by analyzing through netmon captures that would be help full.
http://support.microsoft.com/kb/558115


________________________________
From: Douglas E. Engert <deengert@anl.gov>
To: raj esh L <rrcrajesh2003@yahoo.com>
Cc: kerberos-owner@mit.edu; kerberos@mit.edu
Sent: Thu, 21 January, 2010 0:57:26
Subject: Re: Windows event id 4 (kerberos)



raj esh L wrote:
> We have observed Kerberos event id4 on one member server (Print server )BRAPRINT001 (10.1.37.167). Please find the description below about the event id. Can some one please help me on it ?
>  Event Type:            Error
> Event Source:          Kerberos
> Event Category:      None
> Event ID:                4
> Date:                       1/13/2010
> Time:                       6:16:35 PM
> User:                       N/A
> Computer:               BRAPRINT001
> Description:
> The kerberos client received a KRB_AP_ERR_MODIFIED error from the server SLH-001155$.  The target name used was cifs/ATL017784.dir.ucb-group.com. This indicates that the password used to encrypt the kerberos service ticket is different than that on the target server. Commonly, this is due to identically named  machine accounts in the target realm (DIR.UCB-GROUP.COM), and the client realm.   Please contact your system administrator.
>  For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
>   ATL017784.dir.ucb-group.com [10.70.11.107]
>  We captured network for it. Can you please help here what is going on?
>   captured file is available at http://www.megaupload.com/?d=WDIG1CAT
> 
> 

Googling for: Windows EventID: 4 Kerberos

I found there are a number of other people who have had similar problems.
You may also want to look at:

http://www.eventid.net/display.asp?eventid=4&eventno=1968&source=Kerberos&phase=1

There are a number of other people who have had similiar problems.

Also see:
http://support.microsoft.com/kb/558115
>       ________________________________________________
> Kerberos mailing list          Kerberos@mit.edu
> https://mailman.mit.edu/mailman/listinfo/kerberos
> 
> 

-- 
Douglas E. Engert  <DEEngert@anl.gov>
Argonne National Laboratory
9700 South Cass Avenue
Argonne, Illinois  60439
(630) 252-5444



      
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post