Disabling Kerberos

B

Bishop

I have a large amount of kerberos failures on my Domain controllers,
how do I disable Kerberos for less failled logs?
This is causing my DC's a higher load, and many of the logs are timed
about 10 hits every 2-3 seconds? Is there something else I should be
looking to do to rememdy this? I have over 2000 users.

Please all help will be accepted.

email me at: (e-mail address removed)
 
M

.:mmac:.

what is the error code and source of the failure?

is it just tgt renewal? If you have auditing on in the default policy you
will see these errors and even though they are benign, you can't stop the
renewal notices.
 
B

bishop_

Many of the error codes are 675/673. The kbrtgt/UserName. There is
auditing on the default policy. So this frequency is normal?
Should I be seeing just as much success as failures...[silly as it may
sound?]
We recently had a small outbreak of a SDbot variant, and this caused
some accounts to be locked out. Could this be the result of the failed
675/673 Event ID's?

bucketbug
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top