kerberos time skew

kerberos time skew

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
kerberos time skew bill 11-10-2005
Posted by =?Utf-8?B?YmlsbA==?= on November 10, 2005, 8:16 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
I have a domain that i have inherited, the security logs are full of failures
due to kerberos time skew. i think i have been able to reset the secure
channel between the 2 domain controllers, i have also set up the pdc as the
time server for the rest of the domain. some of the patched computers have
synced with the time server as far as time and as far as being trusted
members of the domain but many have not. also alot of userenv code 1000
errors on the broken clients. whats the easiest way to fix this? i have seen
this before ( not here) and found the only way to fix was to unjoin and
rejoin the domain but for nearly 100 clients that would not be fun.


Event Type:        Failure Audit
Event Source:        Security
Event Category:        Account Logon
Event ID:        673
Date:                11/10/2005
Time:                5:53:08 PM
User:                NT AUTHORITY\SYSTEM
Computer:        WESLEY01DC02
Description:
Service Ticket Request:
        User Name:                
        User Domain:                
        Service Name:                
        Service ID:                -
        Ticket Options:                0x40800000
        Ticket Encryption Type:        -
        Client Address:                172.16.100.254
        Failure Code:                0x25
        Logon GUID:                -
        Transited Services:        -


For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.


Posted by S. Pidgorny on November 13, 2005, 2:34 am
If you were  Registered and logged in, you could reply and use other advanced thread options
The easies way is to make sure domain time synchronisation actually works.
You need to inspect the clients' logs to see if there are entries from the
time service and run series of tests to make sure both NTP and CIFS time
synchronisation is functional.

--
Svyatoslav Pidgorny, MS MVP - Security, MCSE
-= F1 is the key =-

>I have a domain that i have inherited, the security logs are full of
>failures
> due to kerberos time skew. i think i have been able to reset the secure
> channel between the 2 domain controllers, i have also set up the pdc as
> the
> time server for the rest of the domain. some of the patched computers
> have
> synced with the time server as far as time and as far as being trusted
> members of the domain but many have not. also alot of userenv code 1000
> errors on the broken clients. whats the easiest way to fix this? i have
> seen
> this before ( not here) and found the only way to fix was to unjoin and
> rejoin the domain but for nearly 100 clients that would not be fun.
>
>
> Event Type: Failure Audit
> Event Source: Security
> Event Category: Account Logon
> Event ID: 673
> Date: 11/10/2005
> Time: 5:53:08 PM
> User: NT AUTHORITY\SYSTEM
> Computer: WESLEY01DC02
> Description:
> Service Ticket Request:
> User Name:
> User Domain:
> Service Name:
> Service ID: -
> Ticket Options: 0x40800000
> Ticket Encryption Type: -
> Client Address: 172.16.100.254
> Failure Code: 0x25
> Logon GUID: -
> Transited Services: -
>
>
> For more information, see Help and Support Center at
> http://go.microsoft.com/fwlink/events.asp.
>



Similar ThreadsPosted
Run-time error "70" April 24, 2006, 6:32 am
Time Restraints December 23, 2006, 9:56 pm
time is 11pm December 16, 2007, 10:55 pm
Time Travel!! July 14, 2008, 6:10 am
cannot change the date and time December 5, 2005, 10:29 am
IP Address time limitation February 28, 2006, 4:59 am
Great time in France June 7, 2006, 10:30 am
Time of access- How to find? July 27, 2006, 8:03 pm
Kerberos UDP vs TCP November 14, 2006, 4:18 am
Re: automatic log off of user after idle time June 21, 2005, 8:19 am

The site map in XML format XML site map

Contact Us | Privacy Policy