Login and Time Sync Issues



I have a SBS 2003 that has been running about 6 months. I have a second Win2K DC and a Win2k Member server and some XP client
systems.

THe SBS hardware got flaky about 2 weeks ago and would hardware freeze.
Finally on Thursday it went down and would not get past POST.

Today I replaced the motherboard, processor and memory and rebooted.
After Plug & Play things looked pretty good EXCEPT that no one can access any files on the SBS and the SBS system can not create a
net use to any other system. In the case of trying to use a share on the member Win2k system from the SBS system, I get the error
that says 'This server's clock is not sync'd with the domain's PDC'.

Well, the SBS should be the PDC, but everyone is logging in with the Win2k DC as the login server and apparently the SBS system
now thinks the 2000 DC is the PDC.

I have stopped the PDC and booted the SBS system and tried to reboot and login from one of the client systems. Took about 10 mins
to get through setting network connections. Never did get logged in. Lost patience.

No real error messages in any event logs other then the SBS System and they only occurred when the 2K DC was offline Event 40961
The Security System could not establish a secured connection with the server LDAP/ZEUS. No authentication protocol was available.

Event 40960
The Security System detected an authentication error for the server LDAP/ZEUS. The failure code from authentication protocol
Kerberos was "There are currently no logon servers available to service the logon request.
(0xc000005e)".


Before I messed around a lot I was receiving this error Event 5 The kerberos client received a KRB_AP_ERR_TKT_NYV error from the
server ROYHOME$. This indicates that the ticket used against that server is not yet valid (in relationship to that server time).
Contact your system administrator to make sure the client and server times are in sync, and that the KDC in realm ROYCHASTAIN.ORG
is in sync with the KDC in the client realm.


Now, just to be clear, the clocks are all within 30 seconds of each other. (And the dates and AM/PM are correct to.)

Since the 2 DCs can not authenticate to each other, DNS and FRS replication etc are failing and things are falling apart.

PS.
The SBS install has never been completed. Exchange and ISA are not running on the SBS box. Needless to say the SBS system can
not even get to the Internet, because it can not authenticate with the ISA server on another member server.

Thanks for you input to resolve this issue.

-------------------------------------------
Roy Chastain
KMSYS Worldwide, Inc.
http://www.kmsys.com
.



Relevant Pages

  • Re: SBS 2003 server sharing a folder to a non authenticated user or device (can it be done?)
    ... Plus exchange and SQL do consume quite a bit of non-paged pool and this has the effect of making the server cough occasionally, you only see this at high IO times. ... What you MUST be aware of the the whapping security hole the guest account will drive into your network. ... Someone must have done an impact analysis for enabling the guest account on a default SBS install.. ... authentication and will use Exchange ...
    (microsoft.public.windows.server.sbs)
  • Re: OWA Authentication Problem With SBS 2003
    ... > Thank you for posting in the SBS newsgroup. ... > the OWA from SBS 2003 Server itself, one of internal clients or Internet? ... Please re-run the CEICW (Configure Email and Internet Connection ... > configure the correct Authentication type for OWA. ...
    (microsoft.public.windows.server.sbs)
  • Re: OWA Authentication Problem With SBS 2003
    ... you are able to log in OWA after disabling the form based ... authentication, and you would like to let the OWA work when you re-enable ... obtain access to your Exchange Server 2003 mailbox. ... This newsgroup only focuses on SBS technical issues. ...
    (microsoft.public.windows.server.sbs)
  • Re: Fax Alerts
    ... Server" and choose Properties. ... Click the Authentication button. ... Anonymous access ... Granted SBS Server External IP Address ...
    (microsoft.public.windows.server.sbs)
  • Re: Login and Time Sync Issues
    ... The Event IDs 40960 and 5 were on the SBS Server and ONLY when the other DC was offline. ... Everything about the SBS system is working other than its ability to communicate with the rest of the domain. ... working only things that require authentication are not working. ... >and paste the full content to the Newsgroup. ...
    (microsoft.public.windows.server.sbs)

Loading