Kerberos won't start

  • Thread starter Thread starter Guest
  • Start date Start date
G

Guest

Hi!

I have a problem with the Kerberos Service. After restarting my Exchange
2000 server (win 2000 SP4, not DC) the kerberos service won't restart. I get
a error 1352: The security account manager (SAM) or local security authority
(LSA) server was in the wrong state to perform the security operation.
The DC is a server 2003.

The user with XP can logon to my Exchange server thrue Outlook, but the
users with 2000 can't. They get a re-authentication box to fill in, and it
doesn't work.

What can this depend on?

Regards!
 
Hi!

Thank's for your answer. Noe I've solved the problem:

I was actually wrong about the Kerberos problem. The problem wasn't in the
kerberos service, wish by the way is suppose to be disabled on member
servers. The problem was in the registry keys; ntlmminserversec and
ntlmminclientsec:
HKEY_LOCAL_MACHINE/SYSTEM/CurrentControlSet/Control/Lsa/MSV1_0

Because of the server environment with both 2000 servers and a 2003 domain
controller server this key wasn't set to 0 (zero) in the Exchange 2000 server
(2000 server). This also made the OWA unfunctional from win2000-clients. Note
that everything worked fine from winXP clients, since these have different
authentication protocols.

Regards
 
Back
Top