Re: Tickets Kerberos
- From: "Jorge Silva" <jorgesilva_pt@xxxxxxxxxxx>
- Date: Fri, 24 Nov 2006 15:27:42 -0000
A reverse lookup is not required for proper AD function. However, without a reverse lookup zone and PTRs, you may see 40960 and 40961 events due to Win2k3 and WinXP trying to make a secure PTR registration at the External DNS that is Authoritative over the reverse lookup of the IP on the machine's local interface. If it's a private address it will say cannot establish a secured connection with the server prisoner.iana.org.
Also, nslookup will report "Can't find server name for address <IPAddressOfDNSServer>"
By creating a Reverse lookup zone you solve that error, also make sure that you have all clients NIC preferred DNS server pointing to their local (Internal) DNS server.
--
*************************************************
I hope that the information above helps you
Good Luck
Jorge Silva
MCSA + Exchange + MSCE
*************************************************
<mourad.ladjici@xxxxxxxxx> wrote in message news:u9jOVk9DHHA.348@xxxxxxxxxxxxxxxxxxxxxxx
I already did it and it didn't work.
I should wait one hours to have tickets kerberos (i use kerbtray to see that) and then i can access share folders.
I can see in the event viewer this log, when it's not working :
The Security System could not establish a secured connection with the server <server name>. No authentication protocol was available.
Event ID: 40961 Source : LsaSrv
Regards,
Mourad
"Jorge Silva" <jorgesilva_pt@xxxxxxxxxxx> a écrit dans le message de news: %2354IlE9DHHA.4604@xxxxxxxxxxxxxxxxxxxxxxxHi
Fastest way is to reset the computer account in AD, then re-add the computer to Ad again.
--
*************************************************
I hope that the information above helps you
Good Luck
Jorge Silva
MCSA + Exchange + MSCE
*************************************************
<mourad.ladjici@xxxxxxxxx> wrote in message news:%23ANQ1y8DHHA.4132@xxxxxxxxxxxxxxxxxxxxxxxHi,
I am working in Active Directory Windows 2003, when I open a session with my computer (Windows XP with SP2), I don't have a tickets Kerberos, then I can't access at Share Folders.
How can I renew a tickets Kerberos ?
.
- References:
- Re: Tickets Kerberos
- From: Jorge Silva
- Re: Tickets Kerberos
- From: mourad.ladjici
- Re: Tickets Kerberos
- Prev by Date: Re: Tool for Creating Users
- Next by Date: Re: Tickets Kerberos
- Previous by thread: Re: Tickets Kerberos
- Next by thread: Re: Tickets Kerberos
- Index(es):
Relevant Pages
|