Duplicate SPN for Domain Controller account


i worked consultant morning federated services added domain controller , in process manually used setspn.exe -a command add federated services account.  little did know duplicate spn entries domain controller , stop me being able login it.  can still access shares , event viewer got me little further.

i found this:  http://support.microsoft.com/kb/2015518  , problem facing.  now have identified duplicate account safest way remove , need completed domain controller?

please help!

i used ldp.exe procedure find this, why duplicate not show using setspn.exe -x command?  for reason wonder preferred method remove it.  i'm thinking setspn.exe -d not work, i'm not sure , don't want chance it.  

will dc need restarted working again or should synchronization work incorrect spn gone?

nevermind.  i found answer after more searching.  

for interested used adsiedit remove duplicate.  it quite simple.  go offending account, right click it, properties, scroll "serviceprincipalname", click edit , remove incorrect entry.

it completed on secondary domain controller working fine , after removed duplicate able login primary domain controller again.

cheers!




Windows Server  >  Windows Server General Forum



Comments

Popular posts from this blog

Edit Group Policy

Hyper-V VM not reaching OS 'Logon' screen

DNS question...