Re: KRB_AP_ERR_MODIFIED Error on Windows2003 Server



Hi,

DNS problems can cause this error as well. This is because a client is
attempting to contact systema so the Kerberos Key Distribution Center
encrypts the service ticket with systema's password but poor DNS causes the
query to actually go to systemb and therefore it is encrypted with the
wrong password and generates the error.

Hope this helps,

Brian Delaney
Microsoft Canada
--

This posting is provided "AS IS" with no warranties, and confers no rights.
--------------------
From: "kcsteele" <k.c.steele@xxxxxxxxx>
Newsgroups: microsoft.public.windows.server.general
Subject: Re: KRB_AP_ERR_MODIFIED Error on Windows2003 Server
Date: 13 Sep 2006 06:16:16 -0700
Organization: http://groups.google.com

I had a similar issue earlier this year, from what I remember it was
caused by incorrect PTR entries in DNS. I would check your reverse DNS
records.
nobody wrote:
Thanks for the info - I will try to get access to the domain controller
and
see what ldif shows. No, this is not causing any problems, but out of the
100+ servers I support, it seems odd to have just this one reporting
these
errors.

"Brian Delaney [MSFT]" wrote:

Is this causing any problems?

This usually means, the password used to encrypt the kerberos service
ticket is wrong. This is typically caused by an incorrect
serviceprincipalname (SPN) registration. In this case the SPN
incorrectly
registered would be host/xyz666.nobody.corp.priv (as cifs/ is rolled up
under the host/ SPN)

You can take an ldif dump on one of the DCs of the domain partition to
see
where this SPN has been registered to see if it is correct or not.
Ldif
syntax is:
ldifde -f dumpfile.txt -d DC=nobody,DC=corp,DC=priv -l
serviceprincipalname

In some cases this error can also be a result of Kerberos packet
fragmentation.

Hope this helps,

Brian Delaney
Microsoft Canada
--

This posting is provided "AS IS" with no warranties, and confers no
rights.
--------------------
Thread-Topic: KRB_AP_ERR_MODIFIED Error on Windows2003 Server
thread-index: AcbWlhvN7IX5bJ4DRAqlb3FL2AVtzw==
X-WBNR-Posting-Host: 64.91.16.96
From: =?Utf-8?B?bm9ib2R5?= <nobody@xxxxxxxxxxxxxxxxxxxxxxxxx>
Subject: KRB_AP_ERR_MODIFIED Error on Windows2003 Server
Date: Tue, 12 Sep 2006 11:06:02 -0700

On a Windows2003 Server Standard Edition without SP#1, I am seeing
strange
Kerberos errors:

9/11/2006 8:35:01 AM
Event Type: Error
Event Source: Kerberos
Event Category: None
Event ID: 4
Date: 9/11/2006
Time: 7:27:24 AM
User: N/A
Computer: xyz123
Description:
The kerberos client received a KRB_AP_ERR_MODIFIED error from the
server
MARIOTTI$. The target name used was cifs/xyz666.nobody.corp.priv.
This
indicates that the password used to encrypt the kerberos service
ticket is
different than that on the target server. Commonly, this is due to
identically named machine accounts in the target realm
(nobody.CORP.PRIV),
and the client realm. Please contact your system administrator.

Note that the server referenced in the description [Mariotti$] does
not
exist anywhere on our domains. This member/resource server is not a
domain
controller or exchange server. Just a simple file and print server.
More
errors appeared this morning referencing 2 more servers that do not
exist
anywhere. User workstations are all laptops that have recently
travelled.

What the heck ?






.



Relevant Pages

  • Re: Is "SPN advertisement" or well-known SPNs a security hole?
    ... connect to his machine by spoofing DNS or some other means. ... server and the Kerberos service principal name used in the mutual ... In Jeffrey's example, the client locates the ... normative or required by Kerberos. ...
    (comp.protocols.kerberos)
  • Re: Subordinate Certificate Server - No templates?!
    ... Disregard the wins warning but the dns and kerberos warnings could ... list of preferred dns servers for your new CA server. ... new certificate as a CA not to replace any existing certificates but to add ...
    (microsoft.public.security)
  • Re: Working out a OS X 10.4 Tiger ssh implementation issue, slow logins
    ... port of the OpenSSH release; it has code added to it. ... order to construct a ticket request for the SSH server, ... for the ticket request instead of going to the DNS. ... client will try to find the Kerberos context for the server via the DNS ...
    (comp.security.ssh)
  • Re: Critical Errors in System Log
    ... EventID: 4 Source: Kerberos ... The kerberos client received a KRB_AP_ERR_MODIFIED error from the server ... ip address and update its host record on the DNS server. ...
    (microsoft.public.windows.server.sbs)
  • Issues migrating SBS 2003 domain to Server 2008 Standard
    ... We are stuck migrating our SBS 2003 domain to Server 2008. ... Fatal Error:DsGetDcName (SRV-EXCH) call failed, ... Verify your Domain Name Sysytem (DNS) is ... network connectivity to a domain controller. ...
    (microsoft.public.windows.server.sbs)

Quantcast