Duplicate SPN for Domain Controller account
i worked consultant morning federated services added domain controller , in process manually used setspn.exe -a command add federated services account. little did know duplicate spn entries domain controller , stop me being able login it. can still access shares , event viewer got me little further.
i found this: http://support.microsoft.com/kb/2015518 , problem facing. now have identified duplicate account safest way remove , need completed domain controller?
please help!
i used ldp.exe procedure find this, why duplicate not show using setspn.exe -x command? for reason wonder preferred method remove it. i'm thinking setspn.exe -d not work, i'm not sure , don't want chance it.
will dc need restarted working again or should synchronization work incorrect spn gone?
nevermind. i found answer after more searching.
for interested used adsiedit remove duplicate. it quite simple. go offending account, right click it, properties, scroll "serviceprincipalname", click edit , remove incorrect entry.
it completed on secondary domain controller working fine , after removed duplicate able login primary domain controller again.
cheers!
Windows Server > Windows Server General Forum
Comments
Post a Comment