Error with Kerbos Key Distribution Center on DC

G

Guest

Guest
Archived from groups: microsoft.public.win2000.general (More info?)

Hello,

We have a win2k domain with 2 domain controllers. I recently migrated
the 2nd DC to a newer box, and it is causing network-wide log on
issues. The new DC won't let me log on to it locally, giving an error
that there is a time difference between the client and server. this
also happens for any computer authenticating with the new server.
However, I can go into the computer management console of any
functional domain computer, connect remotely to the management console
for the new DC, restart the kerbose key distribution center service,
and the problem goes away for several hours - then it comes back.

The time is synchronized within milliseconds across the network, time
zones are all the same, and all the computers authenticate with the old
DC just fine. both DCs are running win 2k sp4 server

any thoughts?
 
G

Guest

Guest
Archived from groups: microsoft.public.win2000.general (More info?)

Followup:

there are failure errors in the security logs whenever this occurs.

Source: Security
Event ID: 675
Category: Account Logon

Pre-authentication failed:
User Name: Administrator
User ID: *DomainName*\Administrator
Service Name: krbtgt/*DomainName*
Pre-Authentication Type: 0x2
Failure Code: 0x25
Client Address: 127.0.0.1

I'm baffled...
 
G

Guest

Guest
Archived from groups: microsoft.public.win2000.general (More info?)

Followup:

there are failure errors in the security logs whenever this occurs.

Source: Security
Event ID: 675
Category: Account Logon

Pre-authentication failed:
User Name: Administrator
User ID: *DomainName*\Administrator
Service Name: krbtgt/*DomainName*
Pre-Authentication Type: 0x2
Failure Code: 0x25
Client Address: 127.0.0.1

I'm baffled...