Security database on the server...
hello.
in company have 2x ad dc, primary working on windows server 2k3, additional working on windows server 2k8. at workstations appear error: " security database on server not have computer account workstation ". turned off preauthentication people accounts , computers account, doesn't help. remove computer account form ad , added next time doesn't to. times, when at workstation appear error is need to reboot computer , user can sign in computer. in event log there errors related wins server. solutions? best regards.
ps. when shutdown 2k8 ewerthing ok.
error logs in event viewer:
"logon attempt by: microsoft_authentication_package_v1_0
logon account: pc-beh-37$
source workstation: pc-beh-37
error code: 0xc0000064
for more information, see , support center @ http://go.microsoft.com/fwlink/events.asp."
"
pre-authentication failed:
user name: mateusz
user id: nfm\mateusz
service name: krbtgt/nfm
pre-authentication type: 0x0
failure code: 0x19
client address: 10.0.0.50
for more information, see , support center at
"
"
authentication ticket request:
user name: nt authority\network service
supplied realm name: nfm
user id: -
service name: krbtgt/nfm
service id: -
ticket options: 0x40810010
result code: 0x6
ticket encryption type: -
pre-authentication type: -
client address: 127.0.0.1
certificate issuer name:
certificate serial number:
certificate thumbprint:
"
jacekl.
as "security database on server not have computer account workstation" there can multiple reassons.
- the obivious 1 computer account got deleted ad, still there/a reboot solves it... that's not case
more likely:
- or there bad channel ad: both dc's in sync? dns healthy? explain why after reboot works: perhaps other dc selected communication
- or kerberos spn's faulty/being screwed process. believe these can fixed @ boot: http://setspn.blogspot.com/2009/11/no-spn-means-no-logon.html
- ...
the "pre-authentication failed" errors can safely ignored. more or less inherent kerberos protocol. client tries kerberos communication withouth timestamp included, gets warning , told put additional informaton in request (explanation not precise, it's correct more or less)
http://setspn.blogspot.com
Windows Server > Directory Services
Comments
Post a Comment