RE: Security Event Log Repeating... Access errors




Tony thanks for the quick reply.

In the "System" log these critical events repead every minute:

I have followed the kb articles including the setspn.exe
--------------------------------
A Kerberos Error Message was received:
on logon session EDECANUSLLC.LOCAL\edecanusbase$
Client Time:
Server Time: 3:31:43.0000 12/4/2005 Z
Error Code: 0x18 KDC_ERR_PREAUTH_FAILED
Extended Error:
Client Realm:
Client Name:
Server Realm: EDECANUSLLC.LOCAL
Server Name: krbtgt/EDECANUSLLC.LOCAL
Target Name: krbtgt/EDECANUSLLC.LOCAL@xxxxxxxxxxxxxxxxx
Error Text:
File: e
Line: 6bc
Error Data is in record data.
-----------------------------------------------------------
A Kerberos Error Message was received:
on logon session
Client Time:
Server Time: 3:31:1.0000 12/4/2005 Z
Error Code: 0xd KDC_ERR_BADOPTION
Extended Error: 0xc00000bb KLIN(0)
Client Realm:
Client Name:
Server Realm: EDECANUSLLC.LOCAL
Server Name: host/edecanusbase.edecanusllc.local
Target Name: host/edecanusbase.edecanusllc.local@xxxxxxxxxxxxxxxxx
Error Text:
File: 9
Line: ae0
Error Data is in record data.

Any input on the preceeding?

How do I diagnose/repair the following prior suggestions?
- Can be a Service not using a properly configured Service Account
- Can be a bad Kerberos certificate
- Can be an orphaned Active Directory object
- Can be bad network time syncs


"Tony Su" wrote:

> For the following, there are KB articles for troubleshooting
>
> IMO
> - Can be a Service not using a properly configured Service Account
> - Can be a bad Kerberos certificate
> - Can be an orphaned Active Directory object
> - Can be bad network time syncs
> - Can be mis-matched or incorrectly configured NTLM authentication level
> (for instance, is this a Win98 or other non-Win2K SP4 or XP machine?)
>
> I'd suspect the last one if all your errors are related, but that's not
> guaranteed.
> --
> Tony Su
> www.su-networking.com
> ISA
> SBS
> Enterprise Mobile Solutions Architect
>
>
> "Adrian Albrecht" wrote:
>
> > Can someone tell me where to look to fix these errors? Other than being
> > annonying I can't find and detriment to performance.
> >
> > Critical Errors in Security Log
> >
> >
> > Source Event ID Last Occurrence Total Occurrences
> > Security 529 12/3/2005 5:48 AM 2,389 *
> > Logon Failure:
> > Reason: Unknown user name or bad password
> > User Name: EDECANUSBASE$
> > Domain: EDECANUSLLC
> > Logon Type: 3
> > Logon Process: NtLmSsp
> > Authentication Package: NTLM
> > Workstation Name: EDECANUSBASE
> > Caller User Name: -
> > Caller Domain: -
> > Caller Logon ID: -
> > Caller Process ID: -
> > Transited Services: -
> > Source Network Address: -
> > Source Port: -
> >
> >
> >
> >
> >
> > Source Event ID Last Occurrence Total Occurrences
> > Security 675 12/3/2005 5:48 AM 2,389 *
> > Pre-authentication failed:
> > User Name: EDECANUSBASE$
> > User ID: EDECANUSLLC\EDECANUSBASE$
> > Service Name: krbtgt/EDECANUSLLC.LOCAL
> > Pre-Authentication Type: 0x2
> > Failure Code: 0x18
> > Client Address: 127.0.0.1
> >
> >
> >
> >
> >
> > Source Event ID Last Occurrence Total Occurrences
> > Security 680 12/3/2005 5:48 AM 2,388 *
> > Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
> > Logon account: EDECANUSBASE$
> > Source Workstation: EDECANUSBASE
> > Error Code: 0xC000006A
> >
> >
.



Relevant Pages

  • Re: Server not found in Kerberos Database
    ... Server not found in Kerberos Database ... When I am trying to do a kinit on the client, ... I have a KDC on Win2003 and a client which is a Linux is trying = ...
    (comp.protocols.kerberos)
  • Problems unwrapping SPNEGO token for Single Signon (SSO) in WebLogic Server 8.1.
    ... but cannot get WebLogic to unwrap the SPNEGO token so it authenticates using Kerberos. ... We've tried adding the AllowTGTSessionKey registry key on client and server, but that didn't change it either. ... Enable Integrated Windows Authentication ...
    (comp.protocols.kerberos)
  • Re: Kerberos authentication fails
    ... we had have kerberos log activated yesterday while we test the ... Client Server Name: ... * System Event logs in GPRSServer03 ... Server domain: DISTROMEL.GPRS ...
    (microsoft.public.sqlserver)
  • Re: Kerberos authentication fails
    ... we had have kerberos log activated yesterday while we test the ... Client Server Name: ... * System Event logs in GPRSServer03 ... Server domain: DISTROMEL.GPRS ...
    (microsoft.public.win2000.security)