Re: Continued KDC error event id 11 Service Principal name, etc..

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: Chriss3 [MVP] (noSpamHere_at_chrisse.se)
Date: 08/18/04


Date: Wed, 18 Aug 2004 19:19:15 +0200

Hello Eric, You have found the two objects that both have the same
ServicePrincipal Name, Remove the Service Principal Name that conflicts from
one of the objects. This is a multi-valued attribute, each object can have
several Service Principal Names. You can modify this with ADSIEdit and
LDP.exe, I think ADSIEdit is the easiest way do to so.

-- 
Regards
Christoffer Andersson
Microsoft MVP - Directory Services
No email replies please - reply in the newsgroup
------------------------------------------------
http://www.chrisse.se - Active Directory Tips
"Eric Wishan" <eric@wishan.com> skrev i meddelandet
news:840701c48543$cc4f7940$a501280a@phx.gbl...
> I have a continued KDC error from my event logs.
> "There are multiple accounts with name
> cifs/moses.wishan.com of type DS_SERVICE_PRINCIPAL_NAME.
>
> and
>
> There are multiple accounts with name
> cifs/moses.wishan.com of type DS_SERVICE_PRINCIPAL_NAME.
>
> I have used both articel from microsoft on filtering AD
> and generating lists to highlight the duplicate SPN's.
> Honestly, after filtering and reviewing these outputs, I
> am not actually sure what to look for in finding an
> duplicate, and then EXACTLY where to delete the duplicate
> SPN.  The following is an excerpt from the ldap filtering
> utility:
>
> ***Searching...
> ldap_search_s(ld, "DC=wishan,DC=com",
> 2, "serviceprincipalname=host/moses.wishan.com",
> attrList,  0, &msg)
> Result <0>: (null)
> Matched DNs:
> Getting 2 entries:
> >> Dn: CN=Administrator,CN=Users,DC=wishan,DC=com
> 4> objectClass: top; person; organizationalPerson;
> user;
> 1> cn: Administrator;
> 1> description: Built-in account for administering
> the computer/domain;
> 1> distinguishedName:
> CN=Administrator,CN=Users,DC=wishan,DC=com;
> 1> name: Administrator;
> 1> canonicalName: wishan.com/Users/Administrator;
> >> Dn: CN=MOSES,OU=Domain Controllers,DC=wishan,DC=com
> 5> objectClass: top; person; organizationalPerson;
> user; computer;
> 1> cn: MOSES;
> 1> distinguishedName: CN=MOSES,OU=Domain
> Controllers,DC=wishan,DC=com;
> 1> name: MOSES;
> 1> canonicalName: wishan.com/Domain
> Controllers/MOSES;
>
> Any SPECIFIC help would be greatly appreciated!  Thanks in
> advance.
>
>


Relevant Pages

  • Continued KDC error event id 11 Service Principal name, etc..
    ... "There are multiple accounts with name ... and generating lists to highlight the duplicate SPN's. ... Honestly, after filtering and reviewing these outputs, I ... the computer/domain; ...
    (microsoft.public.windows.server.active_directory)
  • Re: Administrator account hijacked?
    ... Sean :-) Good advice on the filtering. ... Torrey, if you haven't yet installed the SBS BPA, the link is in my signature. ... We have thousands of e-mails sending out from Administrator as postmaster at ... >> see mail messages that are being received and sent through this>> account. ...
    (microsoft.public.windows.server.sbs)
  • Re: Problem Back
    ... In order to use Ip filtering you would need static IP's for the 13. ... administrator login with no password. ... > and now here's some good news and bad news... ... all computers except the server one uses dynamic IPs. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Continued KDC error event id 11 Service Principal name, etc..
    ... >>Microsoft MVP - Directory Services ... >>> I have used both articel from microsoft on filtering AD ... >>> and generating lists to highlight the duplicate SPN's. ...
    (microsoft.public.windows.server.active_directory)
  • Re: 4320 Wins Replication Error
    ... It isn't going to give a duplicate name error if there wasn't a duplicate ... It if is a legitiment entry it will reenter itself after ... the WINS server if their dialup settings include a WINS ... >>Is there a machine on each LAN called "Administrator"? ...
    (microsoft.public.windows.server.networking)