Admin Know-IT-All Question #18 |
 |
By Mr. Know-IT-All
14 Jan 2003 | SearchWinIT.com |
 |


|
Were you correct?
"Follow. But! Follow only if ye be men of valour, for the entrance to this cave is guarded by a creature so foul, so cruel that no man yet has fought with it and lived! Bones of full fifty men lie strewn about its lair. So, brave knights, if you do doubt your courage or your strength, come no further, for death awaits you all with nasty, big, pointy teeth."
- Tim the Enchanter, Monty Python and the Holy Grail
Today's Know-IT-All answer is:
d. A duplicate SPN (ServicePrincipalName) value in the AD tree
Learn more:
At times, a domain user will try to connect to a Windows 2000 server that is a member of the same domain, only to be asked for their credentials (user ID / password) before they can access the server.
When this happens, an error may be generated in the event log which reads:
Event Type:Error
Event Source:KDC
Event Category:None
Event ID:11
Description: There are multiple accounts with name
host/SERVERNAME.microsoft.com of type 10
If this happens, it's due to a duplicate SPN (ServicePrincipalName) value in the Active Directory tree. SPNs are used for things other than direct user validation; for instance, a service that runs under a user account will have an SPN attribute for that account.
If this quiz has left you yearning for more information, please check the links below for related articles and tips:
>> Read Serdar Yegulalp's full article entitled: Deal with duped SPNs.
>> Read this Administrator forum thread entitled: VPN site-to-site issues.
Do you have an idea for an admin Know-IT-All question? Let Mr. Know-IT-All know!
');
// -->
|
 |
|
 |