KDC Error 11

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: John Rosenlof (greyseal96_at_hotmail.com)
Date: 02/10/05


Date: Thu, 10 Feb 2005 10:25:58 -0800

Hi,

I'm having a really hard time figuring this out and I was hoping somebody
here might be able to shed some light on this.

We keep getting KDC errors of type 11 in the system event log. They say
that there are multiple accounts with the name... and then it lists
different names in each message, but they are all based on the same computer
and they are all of type10.
Ex:
HOST/ATLANTA, HOST/ATLANTA.DOMAIN.COM, HOST/atlanta.DOMAIN.COM,
HOST/Atlanta, cifs/ATLANTA.DOMAIN.COM, cifs/ATLANTA,
HTTP/atlanta.DOMAIN.COM, HTTP/ATLANTA

I've read the KB article on how to find duplicate SPN's. LDP didn't help,
but the ldifde utility did. I printed out a file with our domain as a base
(dc=domain,dc=dom) and found multiple spn's under Atlanta's computer
account. I used ADSIEdit and found these spn's under the properties page of
cn=atlanta, cn=computers,dc=domain,dc=com. Here are the spn's from Atlanta:
HOST/ATLANTA
HOST/atlanta.DOMAIN.COM
MSSQLSvc/atlanta.DOMAIN.COM:4819
SMTPSVC/ATLANTA
SMTPSVC/atlanta.DOMAIN.COM

This server isn't running our SQL servers, but it is our CRM server. I'm
trying to figure out 1) how it came to have those duplicate spn's 2) what
the impact would be of deleting some (especially on CRM) 3) which ones to
delete 4) what cifs and HTTP have to do with those duplicate spn's if
they're not even listed in the spn list from atlanta.

Any ideas or help? Thanks a lot in advance.

-John



Relevant Pages

  • RE: Duplicating Certificate Templates
    ... I have a similar issue and I would like to confirm if we need a CA server ... smart card logon in SBS network. ... Based on my research, I agree with you, we cannot duplicate a certificate ... we do not need to duplicate certificate template when we just want ...
    (microsoft.public.windows.server.sbs)
  • Re: duplicate name exists on network
    ... > Domain) I still received the error message that a duplicate computer name ... > The DHCP server is an NT server. ... I know how to turn this off on the machines, ... >>> A duplicate name has been detected on the TCP network. ...
    (microsoft.public.win2000.active_directory)
  • Re: Double click
    ... > likely a duplicate, you should be able to just discard the duplicate, and ... > record they're submitting.) ... >>> request has been received by the server. ...
    (microsoft.public.inetserver.asp.db)
  • Map drives over IPSec VPN
    ... Pinging between the Atlanta server and the entire dallas network works. ... Dallas clients can only ping to the Atlanta server, ...
    (microsoft.public.windows.server.networking)
  • Re: duplicate name exists on network
    ... Domain) I still received the error message that a duplicate computer name ... The DHCP server is an NT server. ... >> Event Type: Warning ...
    (microsoft.public.win2000.active_directory)