Directory Server Diagnosis Performing initial setup: Trying to find home server... Home Server = JoeCoDATASrv * Identified AD Forest. Done gathering initial info. Doing initial required tests Testing server: Default-First-Site-Name\JOECODATASRV Starting test: Connectivity ......................... JOECODATASRV passed test Connectivity Doing primary tests Testing server: Default-First-Site-Name\JOECODATASRV Starting test: Advertising ......................... JOECODATASRV passed test Advertising Starting test: FrsEvent ......................... JOECODATASRV passed test FrsEvent Starting test: DFSREvent ......................... JOECODATASRV passed test DFSREvent Starting test: SysVolCheck ......................... JOECODATASRV passed test SysVolCheck Starting test: KccEvent A warning event occurred. EventID: 0x80000785 Time Generated: 11/14/2013 08:55:54 Event String: The attempt to establish a replication link for the following writable directory partition failed. A warning event occurred. EventID: 0x80000785 Time Generated: 11/14/2013 08:55:54 Event String: The attempt to establish a replication link for the following writable directory partition failed. A warning event occurred. EventID: 0x80000785 Time Generated: 11/14/2013 08:55:54 Event String: The attempt to establish a replication link for the following writable directory partition failed. ......................... JOECODATASRV passed test KccEvent Starting test: KnowsOfRoleHolders ......................... JOECODATASRV passed test KnowsOfRoleHolders Starting test: MachineAccount ......................... JOECODATASRV passed test MachineAccount Starting test: NCSecDesc Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have Replicating Directory Changes In Filtered Set access rights for the naming context: DC=DomainDnsZones,DC=ad,DC=jt-s,DC=co,DC=uk Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have Replicating Directory Changes In Filtered Set access rights for the naming context: DC=ForestDnsZones,DC=ad,DC=jt-s,DC=co,DC=uk ......................... JOECODATASRV failed test NCSecDesc Starting test: NetLogons ......................... JOECODATASRV passed test NetLogons Starting test: ObjectsReplicated ......................... JOECODATASRV passed test ObjectsReplicated Starting test: Replications ......................... JOECODATASRV passed test Replications Starting test: RidManager ......................... JOECODATASRV passed test RidManager Starting test: Services ......................... JOECODATASRV passed test Services Starting test: SystemLog A warning event occurred. EventID: 0x00001795 Time Generated: 11/14/2013 08:10:54 Event String: The program lsass.exe, with the assigned process ID 500, could not authenticate locally by using the target name LDAP/0c4fb55c-275f-4955-942a-b3450ac1068a._msdcs.ad.jt-s.co.uk. The target name used is not valid. A target name should refer to one of the local computer names, for example, the DNS host name. An error event occurred. EventID: 0x40000004 Time Generated: 11/14/2013 08:41:25 Event String: The Kerberos client received a KRB_AP_ERR_MODIFIED error from the server joecodatasrv$. The target name used was JT-S\JT-SSRV01$. This indicates that the target server failed to decrypt the ticket provided by the client. This can occur when the target server principal name (SPN) is registered on an account other than the account the target service is using. Please ensure that the target SPN is registered on, and only registered on, the account used by the server. This error can also happen when the target service is using a different password for the target service account than what the Kerberos Key Distribution Center (KDC) has for the target service account. Please ensure that the service on the server and the KDC are both updated to use the current password. If the server name is not fully qualified, and the target domain (AD.JT-S.CO.UK) is different from the client domain (AD.JT-S.CO.UK), check if there are identically named server accounts in these two domains, or use the fully-qualified name to identify the server. An error event occurred. EventID: 0x40000004 Time Generated: 11/14/2013 08:55:54 Event String: The Kerberos client received a KRB_AP_ERR_MODIFIED error from the server joecodatasrv$. The target name used was E3514235-4B06-11D1-AB04-00C04FC2DCD2/0c4fb55c-275f-4955-942a-b3450ac1068a/ad.jt-s.co.uk@ad.jt-s.co.uk. This indicates that the target server failed to decrypt the ticket provided by the client. This can occur when the target server principal name (SPN) is registered on an account other than the account the target service is using. Please ensure that the target SPN is registered on, and only registered on, the account used by the server. This error can also happen when the target service is using a different password for the target service account than what the Kerberos Key Distribution Center (KDC) has for the target service account. Please ensure that the service on the server and the KDC are both updated to use the current password. If the server name is not fully qualified, and the target domain (AD.JT-S.CO.UK) is different from the client domain (AD.JT-S.CO.UK), check if there are identically named server accounts in these two domains, or use the fully-qualified name to identify the server. A warning event occurred. EventID: 0x00001795 Time Generated: 11/14/2013 09:04:28 Event String: The program lsass.exe, with the assigned process ID 500, could not authenticate locally by using the target name ldap/JT-SSrv01.ad.jt-s.co.uk. The target name used is not valid. A target name should refer to one of the local computer names, for example, the DNS host name. An error event occurred. EventID: 0x40000004 Time Generated: 11/14/2013 09:07:24 Event String: The Kerberos client received a KRB_AP_ERR_MODIFIED error from the server joecodatasrv$. The target name used was cifs/JT-SSrv01.ad.jt-s.co.uk. This indicates that the target server failed to decrypt the ticket provided by the client. This can occur when the target server principal name (SPN) is registered on an account other than the account the target service is using. Please ensure that the target SPN is registered on, and only registered on, the account used by the server. This error can also happen when the target service is using a different password for the target service account than what the Kerberos Key Distribution Center (KDC) has for the target service account. Please ensure that the service on the server and the KDC are both updated to use the current password. If the server name is not fully qualified, and the target domain (AD.JT-S.CO.UK) is different from the client domain (AD.JT-S.CO.UK), check if there are identically named server accounts in these two domains, or use the fully-qualified name to identify the server. ......................... JOECODATASRV failed test SystemLog Starting test: VerifyReferences ......................... JOECODATASRV passed test VerifyReferences Running partition tests on : DomainDnsZones Starting test: CheckSDRefDom ......................... DomainDnsZones passed test CheckSDRefDom Starting test: CrossRefValidation ......................... DomainDnsZones passed test CrossRefValidation Running partition tests on : ForestDnsZones Starting test: CheckSDRefDom ......................... ForestDnsZones passed test CheckSDRefDom Starting test: CrossRefValidation ......................... ForestDnsZones passed test CrossRefValidation Running partition tests on : Schema Starting test: CheckSDRefDom ......................... Schema passed test CheckSDRefDom Starting test: CrossRefValidation ......................... Schema passed test CrossRefValidation Running partition tests on : Configuration Starting test: CheckSDRefDom ......................... Configuration passed test CheckSDRefDom Starting test: CrossRefValidation ......................... Configuration passed test CrossRefValidation Running partition tests on : ad Starting test: CheckSDRefDom ......................... ad passed test CheckSDRefDom Starting test: CrossRefValidation ......................... ad passed test CrossRefValidation Running enterprise tests on : ad.jt-s.co.uk Starting test: LocatorCheck ......................... ad.jt-s.co.uk passed test LocatorCheck Starting test: Intersite ......................... ad.jt-s.co.uk passed test Intersite