Re: Events 673, 675, 566
- From: "Paul Bergson" <pbergson@xxxxxxxxxx>
- Date: Mon, 6 Feb 2006 21:27:33 -0600
Since this is kerberos, is the time on the client within 5 minutes of the
dc?
Also is this a 2000 machine in a 2003 Domain? It could also be a 2003
machine misconfigured in a 2003 domain.
See:
http://support.microsoft.com/kb/824905/en-us
--
Paul Bergson MCT, MCSE, MCSA, CNE, CNA, CCA
This posting is provided "AS IS" with no warranties, and confers no rights.
"musicman" <ryantracy@xxxxxxxxxxxx> wrote in message
news:1139265762.455785.71060@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Hello All,
I'm seeing multiple instances of the following events with alarming
frequency - any ideas?
Event Type: Failure Audit
Event Source: Security
Event Category: Account Logon
Event ID: 673
Date: 2/6/2006
Time: 2:52:28 PM
User: NT AUTHORITY\SYSTEM
Computer: MYDCDC1
Description:
Service Ticket Request:
User Name:
User Domain: HQ.COMPANY.COM
Service Name: host/servername.hq.company.com
Service ID: -
Ticket Options: 0x40830000
Ticket Encryption Type: -
Client Address: 10.1.2.96
Failure Code: 0xD
Logon GUID: -
Transited Services: -
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Event Type: Failure Audit
Event Source: Security
Event Category: Account Logon
Event ID: 675
Date: 2/6/2006
Time: 2:54:25 PM
User: NT AUTHORITY\SYSTEM
Computer: MYDC2
Description:
Pre-authentication failed:
User Name: username
User ID: mydomain\username
Service Name: krbtgt/cso
Pre-Authentication Type: 0x2
Failure Code: 0x18
Client Address: 10.1.2.172
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Event Type: Failure Audit
Event Source: Security
Event Category: Directory Service Access
Event ID: 566
Date: 2/6/2006
Time: 2:53:03 PM
User: ENG\RtcService
Computer: MYDC2
Description:
Object Operation:
Object Server: DS
Operation Type: Object Access
Object Type: domainDNS
Object Name: DC=hq,DC=company,DC=com
Handle ID: -
Primary User Name: MYDC2$
Primary Domain: CSO
Primary Logon ID: (0x0,0x3E7)
Client User Name: RtcService
Client Domain: ENG
Client Logon ID: (0x0,0x40935FF)
Accesses: Control Access
Properties:
---
Replicating Directory Changes
domainDNS
Additional Info:
Additional Info2:
Access Mask: 0x100
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
.
- Follow-Ups:
- Re: Events 673, 675, 566
- From: musicman
- Re: Events 673, 675, 566
- References:
- Events 673, 675, 566
- From: musicman
- Events 673, 675, 566
- Prev by Date: Re: Question about the new printer depolyment in R2
- Next by Date: Re: Exclude from GPO ..
- Previous by thread: Events 673, 675, 566
- Next by thread: Re: Events 673, 675, 566
- Index(es):
Relevant Pages
|