How to safely delete duplicated SPNs ?
hi !
i got on dc - windows 2008 r2 version 6.1 (build 7601: service pack 1 following error message:
log name: system
source: microsoft-windows-kerberos-key-distribution-center
date: 4/26/2012 6:27:23 pm
event id: 11
task category: none
level: error
keywords: classic
user: n/a
computer: srvdc.domainck.yy.dd
description:
kdc encountered duplicate names while processing kerberos authentication request. duplicate name mssqlsrv/srv01.domainck.yy.dd:1433 (of type ds_service_principal_name). may result in authentication failures or downgrades ntlm. in order prevent occuring remove duplicate entries mssqlsrv/srv01.domainck.yy.dd:1433 in active directory.
event xml:
<event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<system>
<provider name="microsoft-windows-kerberos-key-distribution-center" guid="{3fd9da1a-5a54-46c5-9a26-9bd7c0685056}" eventsourcename="kdc" />
<eventid qualifiers="49152">11</eventid>
<version>0</version>
<level>2</level>
<task>0</task>
<opcode>0</opcode>
<keywords>0x80000000000000</keywords>
<timecreated systemtime="2012-04-26t16:27:23.000000000z" />
<eventrecordid>24401</eventrecordid>
<correlation />
<execution processid="0" threadid="0" />
<channel>system</channel>
<computer>srvdc.domainck.yy.dd</computer>
<security />
</system>
<eventdata>
<data name="name">mssqlsrv/srv01.domainck.yy.dd:1433</data>
<data name="type">ds_service_principal_name</data>
<binary>
</binary>
</eventdata>
</event>
on srv01.domainck.yy.dd:1433 when setspn -x i :
microsoft windows [version 6.1.7601]
copyright (c) 2009 microsoft corporation. rights reserved.
c:\users\user1>setspn -x
checking domain dc=domainck,dc=yy,dc=dd
processing entry 4
mssql/srv01.domainck.yy.dd:1433 registered on these accounts:
cn=srv02,ou=corp servers,dc=domainck,dc=yy,dc=dd
cn=srv01,ou=corp servers,dc=domainck,dc=yy,dc=dd
{14e52635-0a95-4a5c-bdb1-e0d0c703b6c8}/backup registered on these accounts:
cn=backup,ou=corp servers,dc=domainck,dc=yy,dc=dd
cn=administrator,cn=users,dc=domainck,dc=yy,dc=dd
{14e52635-0a95-4a5c-bdb1-e0d0c703b6c8}/backup.domainck.yy.dd registered on these accounts:
cn=backup,ou=corp servers,dc=domainck,dc=yy,dc=dd
cn=administrator,cn=users,dc=domainck,dc=yy,dc=dd
mssqlsrv/srv01:1433 registered on these accounts:
cn=srv02,ou=corp servers,dc=domainck,dc=yy,dc=dd
cn=srv01,ou=corp servers,dc=domainck,dc=yy,dc=dd
found 4 groups of duplicate spns.
- how know spns can safely delete?
- impact of not deleting duplicated spns ?
- how reverse the delete of duplicated spns?
- how know clean successful without damage ?
hi,
in addition above troubleshooting suggestions, please refer following microsoft technet blogs further troubleshooting information:
quickly explained: service principal name: registration, duplication
kerberos authentication problems – service principal name (spn) issues - part 1
kerberos authentication problems – service principal name (spn) issues - part 2
kerberos authentication problems – service principal name (spn) issues - part 3
regards,
arthur li
technet community support
Windows Server > Windows Server General Forum
Comments
Post a Comment