Re: The Security Account Manager failed a KDC request

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



I do not know what this error is but you could double check to verify your domain is healhtly.

Run diagnostics against your Active Directory domain.

If you don't have the support tools installed, install them from your server install disk.
d:\support\tools\setup.exe

Run dcdiag, netdiag and repadmin in verbose mode.
-> DCDIAG /V /C /D /E /s:yourdcname > c:\dcdiag.log
-> netdiag.exe /v > c:\netdiag.log (On each dc)
-> repadmin.exe /showrepl dc* /verbose /all /intersite > c:\repl.txt
-> dnslint /ad /s "ip address of your dc"

**Note: Using the /E switch in dcdiag will run diagnostics against ALL dc's in the forest. If you have significant numbers of DC's this test could generate significant detail and take a long time. You also want to take into account slow links to dc's will also add to the testing time.

If you download a gui script I wrote it should be simple to set and run (DCDiag and NetDiag). It also has the option to run individual tests without having to learn all the switch options. The details will be output in notepad text files that pop up automagically.

The script is located on my website at http://www.pbbergs.com/windows/downloads.htm

Just select both dcdiag and netdiag make sure verbose is set. (Leave the default settings for dcdiag as set when selected)

When complete search for fail, error and warning messages.

Description and download for dnslint
http://support.microsoft.com/kb/321045


--
Paul Bergson
MVP - Directory Services
MCTS, MCT, MCSE, MCSA, Security+, BS CSci
2008, 2003, 2000 (Early Achiever), NT4

http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup This
posting is provided "AS IS" with no warranties, and confers no rights.


"Kevin Gallagher" <KevinGallagher@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message news:7FDC965F-CE1E-464F-BC5D-FB5AF53FA078@xxxxxxxxxxxxxxxx
I have just built a new Windows 2003 SP2 R2 DC and upon reboot I got the
following error. I have recently seen this error appear on another DC in my
forest again after a reboot. It doesn't appear any other time. Can anyone
suggest what is causing this and how I should resolve the issue.

Event Type: Error
Event Source: KDC
Event Category: None
Event ID: 7
Date: 18/03/2009
Time: 08:12:33
User: N/A
Computer: My-DC2
Description:
The Security Account Manager failed a KDC request in an unexpected way. The
error is in the data field. The account name was
ldap/xxx-dc3.mydom.ac.uk/mydom.ac.uk and lookup type 0x48.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 17 00 00 c0 ...À

.



Relevant Pages

  • Re: Failed Backup Domain Controller
    ... Run diagnostics against your Active Directory domain. ... Run dcdiag, netdiag and repadmin in verbose mode. ... I have found that the dead BDC is listed in AD S&S. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Failed P2V - Active Directory USN rollback issue
    ... Run diagnostics against your Active Directory domain. ... If you don't have the support tools installed, install them from your server install disk. ... Run dcdiag, netdiag and repadmin in verbose mode. ...
    (microsoft.public.windows.server.active_directory)
  • Re: DC start up sequence
    ... Run diagnostics against your Active Directory domain. ... Run dcdiag, netdiag and repadmin in verbose mode. ... controllers, as a result the connection down for a couple of hours to remote ...
    (microsoft.public.windows.server.active_directory)
  • RE: IMpact of changing the IP address of a Domain Controller
    ... Run diagnostics against your Active Directory domain. ... Run dcdiag, netdiag and repadmin in verbose mode. ... If you download a gui script I wrote it should be simple to set and run (DCDiag and NetDiag). ...
    (microsoft.public.windows.server.active_directory)
  • RE: AD Sites service not replicate
    ... Once done you should run diagnostics to verify everything is running correctlt. ... If you lost a dc you need to use ntdsutil and you may need to seize the 5 fsmo roles as well as clean up the metadata within AD. ... Run dcdiag, netdiag and repadmin in verbose mode. ... Event id 1586 from the site service event log. ...
    (microsoft.public.windows.server.active_directory)