Error with Kerbos Key Distribution Center on DC

  • Thread starter Thread starter bbnoon
  • Start date Start date
B

bbnoon

Hello,

We have a win2k domain with 2 domain controllers. I recently migrated
the 2nd DC to a newer box, and it is causing network-wide log on
issues. The new DC won't let me log on to it locally, giving an error
that there is a time difference between the client and server. this
also happens for any computer authenticating with the new server.
However, I can go into the computer management console of any
functional domain computer, connect remotely to the management console
for the new DC, restart the kerbose key distribution center service,
and the problem goes away for several hours - then it comes back.

The time is synchronized within milliseconds across the network, time
zones are all the same, and all the computers authenticate with the old
DC just fine. both DCs are running win 2k sp4 server

any thoughts?
 
Followup:

there are failure errors in the security logs whenever this occurs.

Source: Security
Event ID: 675
Category: Account Logon

Pre-authentication failed:
User Name: Administrator
User ID: *DomainName*\Administrator
Service Name: krbtgt/*DomainName*
Pre-Authentication Type: 0x2
Failure Code: 0x25
Client Address: 127.0.0.1

I'm baffled...
 
Followup:

there are failure errors in the security logs whenever this occurs.

Source: Security
Event ID: 675
Category: Account Logon

Pre-authentication failed:
User Name: Administrator
User ID: *DomainName*\Administrator
Service Name: krbtgt/*DomainName*
Pre-Authentication Type: 0x2
Failure Code: 0x25
Client Address: 127.0.0.1

I'm baffled...
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Similar Threads

LSASRV Error 1
Second DC 1
Sync between two DC 3
Domain Controller Issues - Urgent Help 1
Migration questions 1
DC error? 2
DCPROMO for Child Domain DC. 2
DC not responding 11

Back
Top