Results 1 to 4 of 4

Thread: Event ID 3 Kerberos KDC_ERR_S_PRINCICAL_UNKNOWN

  1. #1
    Join Date
    Nov 2004
    Posts
    47

    Event ID 3 Kerberos KDC_ERR_S_PRINCICAL_UNKNOWN

    We are running a Windows 2003 server since long time with several users connected. Since past few days users started complaining for slow logon. When we started troubleshooting I found a load of error messages in my Event Viewer along with KDC_ERR_BADOPTION messages also. Event Viewer log is as follows:

    05/03/2007 12:33:36 Kerberos Error None 3 N/A DCAADC001 "A Kerberos Error
    Message was received:
    on logon session
    Client Time:
    Server Time: 12:33:36.0000 3/5/2007 Z
    Error Code: 0xd KDC_ERR_BADOPTION
    Extended Error: 0xc00000bb KLIN(0)
    Client Realm:
    Client Name:
    Server Realm: domain.com
    Server Name: host/dc1.domain.com
    Target Name: host/dc1.domain.com@domain.com
    Error Text:
    File: 9
    Line: ae0
    Error Data is in record data."

    05/03/2007 12:29:00 Kerberos Error None 3 N/A DCAADC001 "A Kerberos Error
    Message was received:
    on logon session
    Client Time:
    Server Time: 12:29:0.0000 3/5/2007 Z
    Error Code: 0x7 KDC_ERR_S_PRINCIPAL_UNKNOWN
    Extended Error:
    Client Realm:
    Client Name:
    Server Realm: domain.com
    Server Name: cifs/127.0.0.1
    Target Name: cifs/127.0.0.1@domain.com
    Error Text:
    File: 9
    Line: ae0
    Error Data is in record data."

  2. #2
    Join Date
    Aug 2005
    Posts
    257

    Re: Event ID 3 Kerberos KDC_ERR_S_PRINCICAL_UNKNOWN

    As per the log, I guess any of your user is making a request for a ticket for a service that Kerberos is not aware at all. So I think enabling the tracing on Kerberos will help you get the cause what is the actually problem. You can enable the same with the following steps:

    Start Registry Editor.Add the following registry value:
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Parameters

    Registry Value:
    LogLevel

    Value Type:
    REG_DWORD

    Value D
    ata:
    0x1

    If the Parameters subkey does not exist, create it.

  3. #3
    Join Date
    Nov 2004
    Posts
    47

    Re: Event ID 3 Kerberos KDC_ERR_S_PRINCICAL_UNKNOWN

    I appreciate your help Manik. As you suggested I have enabled loggin. Since then I getting the following message: (0xd and 0x7) on the only 2 DCs. Still I’m not able to understand why there is the cifs/127.0.0.1 setup as the Server Name and Target Name.

    Running Kerbtray, I see that when I am logged in I have connections to:
    cifs/SAN1 (not 127.0.0.1)
    host/DC1
    krbtgt/domain.loc

    When I look at the Encryption types, the Ticket Encryption Type and Key Encryption Type are the same for cifs and host but the Key Encryption Type is different (etype 0) for the krbtgt.

  4. #4
    Join Date
    Sep 2004
    Posts
    149

    Re: Event ID 3 Kerberos KDC_ERR_S_PRINCICAL_UNKNOWN

    Still i'm not able t understand the situation properly. I mean, there should be a copy function, just paste it in to the news reader. Or better post the actual message shown from the event log.

Similar Threads

  1. Event ID 3 Kerberos
    By TomJerzey in forum Active Directory
    Replies: 3
    Last Post: 05-06-2008, 01:33 PM
  2. Kerberos error event ID:4
    By Adam Raff in forum Windows Server Help
    Replies: 6
    Last Post: 18-04-2008, 02:17 PM
  3. Event ID 4 Source Kerberos
    By etienne in forum Active Directory
    Replies: 1
    Last Post: 11-04-2007, 01:53 AM
  4. Event ID: 537 Kerberos Authz
    By bigboy in forum Windows Security
    Replies: 3
    Last Post: 11-01-2007, 05:38 PM
  5. Event ID: 537 Kerberos
    By Evan in forum Windows Server Help
    Replies: 4
    Last Post: 22-10-2006, 09:16 AM

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
Page generated in 1,714,208,069.85122 seconds with 17 queries