How to safely delete duplicated SPNs ?







hi !

i got on dc - windows 2008 r2 version 6.1 (build 7601: service pack 1 following error message:

log name:      system
source:        microsoft-windows-kerberos-key-distribution-center
date:          4/26/2012 6:27:23 pm
event id:      11
task category: none
level:         error
keywords:      classic
user:          n/a
computer:      srvdc.domainck.yy.dd
description:
kdc encountered duplicate names while processing kerberos authentication request. duplicate name mssqlsrv/srv01.domainck.yy.dd:1433 (of type ds_service_principal_name). may result in authentication failures or downgrades ntlm. in order prevent occuring remove duplicate entries mssqlsrv/srv01.domainck.yy.dd:1433 in active directory.
event xml:
<event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <system>
    <provider name="microsoft-windows-kerberos-key-distribution-center" guid="{3fd9da1a-5a54-46c5-9a26-9bd7c0685056}" eventsourcename="kdc" />
    <eventid qualifiers="49152">11</eventid>
    <version>0</version>
    <level>2</level>
    <task>0</task>
    <opcode>0</opcode>
    <keywords>0x80000000000000</keywords>
    <timecreated systemtime="2012-04-26t16:27:23.000000000z" />
    <eventrecordid>24401</eventrecordid>
    <correlation />
    <execution processid="0" threadid="0" />
    <channel>system</channel>
    <computer>srvdc.domainck.yy.dd</computer>
    <security />
  </system>
  <eventdata>
    <data name="name">mssqlsrv/srv01.domainck.yy.dd:1433</data>
    <data name="type">ds_service_principal_name</data>
    <binary>
    </binary>
  </eventdata>
</event>

 

on srv01.domainck.yy.dd:1433 when setspn -x i :

microsoft windows [version 6.1.7601]

copyright (c) 2009 microsoft corporation.  rights reserved.

c:\users\user1>setspn -x
checking domain dc=domainck,dc=yy,dc=dd
processing entry 4

mssql/srv01.domainck.yy.dd:1433 registered on these accounts:
        cn=srv02,ou=corp servers,dc=domainck,dc=yy,dc=dd
        cn=srv01,ou=corp servers,dc=domainck,dc=yy,dc=dd

{14e52635-0a95-4a5c-bdb1-e0d0c703b6c8}/backup registered on these accounts:
        cn=backup,ou=corp servers,dc=domainck,dc=yy,dc=dd
        cn=administrator,cn=users,dc=domainck,dc=yy,dc=dd

{14e52635-0a95-4a5c-bdb1-e0d0c703b6c8}/backup.domainck.yy.dd registered on these accounts:
        cn=backup,ou=corp servers,dc=domainck,dc=yy,dc=dd
        cn=administrator,cn=users,dc=domainck,dc=yy,dc=dd

mssqlsrv/srv01:1433 registered on these accounts:
        cn=srv02,ou=corp servers,dc=domainck,dc=yy,dc=dd
        cn=srv01,ou=corp servers,dc=domainck,dc=yy,dc=dd

found 4 groups of duplicate spns.

- how know spns can safely delete?
- impact of not deleting duplicated spns ?
- how reverse the delete of duplicated spns?
- how know clean successful without damage ?

hi,

in addition above troubleshooting suggestions, please refer following microsoft technet blogs further troubleshooting information:

quickly explained: service principal name: registration, duplication

http://blogs.technet.com/b/qzaidi/archive/2010/10/12/quickly-explained-service-principal-name-registration-duplication.aspx

kerberos authentication problems – service principal name (spn) issues - part 1

http://blogs.technet.com/b/askds/archive/2008/06/09/kerberos-authentication-problems-service-principal-name-spn-issues-part-1.aspx

kerberos authentication problems – service principal name (spn) issues - part 2

http://blogs.technet.com/b/askds/archive/2008/06/09/kerberos-authentication-problems-service-principal-name-spn-issues-part-2.aspx

kerberos authentication problems – service principal name (spn) issues - part 3

http://blogs.technet.com/b/askds/archive/2008/06/09/kerberos-authentication-problems-service-principal-name-spn-issues-part-3.aspx

regards,


arthur li

technet community support



Windows Server  >  Windows Server General Forum



Comments

Popular posts from this blog

Edit Group Policy

Hyper-V VM not reaching OS 'Logon' screen

DNS question...