Re: Kerberos errors after swapping domain controller IPs



I have four domain controllers in my domain - 2 older dcs and 2 newer dcs.
The two older dcs were the DNS and WINS servers that all network devices were
pointed to. I moved the IP addresses from the older two dcs to the newer two
dcs so all network devices would not have to be repointed. The older dcs
were reassigned new IPs. I made sure DNS and WINS showed all the updated IPs
at the end of this process.

This process went well except that now I see Kereberos errors on multiple
servers in my domain. I am not seeing any problems - just the error messages.

Error message:
The kerberos client received a KRB_AP_ERR_MODIFIED error from the server
host/NEW SERVER. The target name used was ldap/OLD SERVER. This indicates
that the password used to encrypt the kerberos service ticket is different
than that on the target server. Commonly, this is due to identically named
machine accounts in the target realm (DOMAIN), and the client realm. Please
contact your system administrator.

Please help if you have seen this and know of a fix. I am not sure if this
is a real problem or not.

Thanks.
Check name resolution on problematic servers. May be there are some
hosts entries or simply you have old IPs cached.

And you should purge all Kerberos tickets (for example, with "klist
purge" command, klist utility can be obtained form Resource Kit package).



--
With best regards
Nickolay Domukhovsky, MCSA
.



Relevant Pages

  • Re: SYSVOL GPOs re:copying
    ... If you create a test user account on each DC, does it successfully replicate to each of the other DCs? ... Stop FRS on each of the new DCs. ... open a command prompt and change directory into the GPMC scripts folder. ... The effort and/or risk in fixing this server seems to exceed the ...
    (microsoft.public.win2000.active_directory)
  • Re: PDC Is not replicating !!
    ... server on the replication DC. ... I have ACE server installed. ... > DCs replicating by disabling replication when USN rollback is ... > If you used imaging to copy your production environment into a lab ...
    (microsoft.public.win2000.active_directory)
  • Re: Sites & Services - DSAccess w/E2K3 SP2
    ... I don't believe the firewalls are the issue as they are set to any-any among ... the all the DCs and exchange server. ... All the DCs replicate information in a mesh ... Immediately after upgrading to Exchange 2003 SP2, ...
    (microsoft.public.exchange.admin)
  • Re: LSASS.exe process near 100% usage
    ... Try pulling the network cable from the back of the server when the spike ... Do the DCs ever reboot on their own? ... The DC that was not gracefully demoted, was it a FSMO Role holder? ... 824196 Description of the License Logging Service in Windows Server ...
    (microsoft.public.win2000.active_directory)
  • User autentification and access to "sister" domain resources
    ... I am in process of designing brand new AD structure for our customer. ... 2003 Servers - pretty classic design ... All DCs are Global Catalogs. ... user_from_domainA gets IP address from siteB DHCP server ...
    (microsoft.public.win2000.active_directory)