Directory Server Diagnosis Performing initial setup: Trying to find home server... ***Error: DC-SV-01 is not a Directory Server. Must specify /s: or /n: or nothing to use the local machine. ERROR: Could not find home server. Directory Server Diagnosis Performing initial setup: Trying to find home server... Home Server = DC-SV-01 * Identified AD Forest. Done gathering initial info. Doing initial required tests Testing server: Default-First-Site\DC-SV-01 Starting test: Connectivity ......................... DC-SV-01 passed test Connectivity Doing primary tests Testing server: Default-First-Site\DC-SV-01 Starting test: Advertising Warning: DsGetDcName returned information for \\DC-SV-02.XXXXXXXX.XXXXX.XXXX.XX, when we were trying to reach DC-SV-01. SERVER IS NOT RESPONDING or IS NOT CONSIDERED SUITABLE. ......................... DC-SV-01 failed test Advertising Starting test: FrsEvent There are warning or error events within the last 24 hours after the SYSVOL has been shared. Failing SYSVOL replication problems may cause Group Policy problems. ......................... DC-SV-01 passed test FrsEvent Starting test: DFSREvent ......................... DC-SV-01 passed test DFSREvent Starting test: SysVolCheck ......................... DC-SV-01 passed test SysVolCheck Starting test: KccEvent A warning event occurred. EventID: 0x8000082C Time Generated: 03/11/2014 12:54:22 Event String: A warning event occurred. EventID: 0x8000082C Time Generated: 03/11/2014 12:54:52 Event String: A warning event occurred. EventID: 0x80000677 Time Generated: 03/11/2014 13:07:53 Event String: Active Directory Domain Services attempted to communicate with the following global catalog and the attempts were unsuccessful. An error event occurred. EventID: 0xC0000466 Time Generated: 03/11/2014 13:07:53 Event String: Active Directory Domain Services was unable to establish a connection with the global catalog. A warning event occurred. EventID: 0x8000082C Time Generated: 03/11/2014 13:08:23 Event String: ......................... DC-SV-01 failed test KccEvent Starting test: KnowsOfRoleHolders ......................... DC-SV-01 passed test KnowsOfRoleHolders Starting test: MachineAccount ......................... DC-SV-01 passed test MachineAccount Starting test: NCSecDesc ......................... DC-SV-01 passed test NCSecDesc Starting test: NetLogons Unable to connect to the NETLOGON share! (\\DC-SV-01\netlogon) [DC-SV-01] An net use or LsaPolicy operation failed with error 67, The network name cannot be found.. ......................... DC-SV-01 failed test NetLogons Starting test: ObjectsReplicated ......................... DC-SV-01 passed test ObjectsReplicated Starting test: Replications [Replications Check,DC-SV-01] A recent replication attempt failed: From DC-SV-02 to DC-SV-01 Naming Context: DC=ForestDnsZones,DC=XXXXXXXX,DC=XXXXX,DC=sch,DC=uk The replication generated an error (1256): The remote system is not available. For information about network troubleshooting, see Windows Help. The failure occurred at 2014-03-11 12:52:53. The last success occurred at 2013-12-20 13:49:38. 24 failures have occurred since the last success. [DC-SV-02] DsBindWithSpnEx() failed with error -2146893022, The target principal name is incorrect.. [Replications Check,DC-SV-01] A recent replication attempt failed: From DC-SV-02 to DC-SV-01 Naming Context: DC=DomainDnsZones,DC=XXXXXXXX,DC=XXXXX,DC=sch,DC=uk The replication generated an error (1256): The remote system is not available. For information about network troubleshooting, see Windows Help. The failure occurred at 2014-03-11 12:52:53. The last success occurred at 2013-12-20 13:49:38. 24 failures have occurred since the last success. [Replications Check,DC-SV-01] A recent replication attempt failed: From DC-SV-02 to DC-SV-01 Naming Context: CN=Schema,CN=Configuration,DC=XXXXXXXX,DC=XXXXX,DC=sch,DC=uk The replication generated an error (-2146893022): The target principal name is incorrect. The failure occurred at 2014-03-11 12:52:53. The last success occurred at 2013-12-20 13:49:38. 24 failures have occurred since the last success. [Replications Check,DC-SV-01] A recent replication attempt failed: From DC-SV-02 to DC-SV-01 Naming Context: CN=Configuration,DC=XXXXXXXX,DC=XXXXX,DC=sch,DC=uk The replication generated an error (-2146893022): The target principal name is incorrect. The failure occurred at 2014-03-11 12:52:53. The last success occurred at 2013-12-20 13:49:38. 24 failures have occurred since the last success. [Replications Check,DC-SV-01] A recent replication attempt failed: From DC-SV-02 to DC-SV-01 Naming Context: DC=XXXXXXXX,DC=XXXXX,DC=sch,DC=uk The replication generated an error (-2146893022): The target principal name is incorrect. The failure occurred at 2014-03-11 12:52:53. The last success occurred at 2013-12-20 14:05:09. 24 failures have occurred since the last success. ......................... DC-SV-01 failed test Replications Starting test: RidManager The DS has corrupt data: rIDPreviousAllocationPool value is not valid No rids allocated -- please check eventlog. ......................... DC-SV-01 failed test RidManager Starting test: Services ......................... DC-SV-01 passed test Services Starting test: SystemLog An error event occurred. EventID: 0x40000004 Time Generated: 03/11/2014 12:27:21 Event String: The Kerberos client received a KRB_AP_ERR_MODIFIED error from the server print-sv-01$. The target name used was cifs/print-sv-01.XXXXXXXX.XXXXX.XXXX.XX. This indicates that the target server failed to decrypt the ticket provided by the client. This can occur when the target server principal name (SPN) is registered on an account other than the account the target service is using. Ensure that the target SPN is only registered on the account used by the server. This error can also happen if the target service account password is different than what is configured on the Kerberos Key Distribution Center for that target service. Ensure that the service on the server and the KDC are both configured to use the same password. If the server name is not fully qualified, and the target domain (XXXXXXXX.XXXXX.XXXX.XX) is different from the client domain (XXXXXXXX.XXXXX.XXXX.XX), check if there are identically named server accounts in these two domains, or use the fully-qualified name to identify the server. A warning event occurred. EventID: 0x000003F6 Time Generated: 03/11/2014 12:28:53 Event String: Name resolution for the name 10.in-addr.arpa timed out after none of the configured DNS servers responded. An error event occurred. EventID: 0x40000004 Time Generated: 03/11/2014 12:52:53 Event String: The Kerberos client received a KRB_AP_ERR_MODIFIED error from the server dc-sv-02$. The target name used was E3514235-4B06-11D1-AB04-00C04FC2DCD2/bd4c0c59-1269-49f0-bda5-b5b15cf57edb/XXXXXXXX.XXXXX.XXXX.XX@XXXXXXXX.XXXXX.XXXX.XX. This indicates that the target server failed to decrypt the ticket provided by the client. This can occur when the target server principal name (SPN) is registered on an account other than the account the target service is using. Ensure that the target SPN is only registered on the account used by the server. This error can also happen if the target service account password is different than what is configured on the Kerberos Key Distribution Center for that target service. Ensure that the service on the server and the KDC are both configured to use the same password. If the server name is not fully qualified, and the target domain (XXXXXXXX.XXXXX.XXXX.XX) is different from the client domain (XXXXXXXX.XXXXX.XXXX.XX), check if there are identically named server accounts in these two domains, or use the fully-qualified name to identify the server. An error event occurred. EventID: 0x0000410B Time Generated: 03/11/2014 12:53:22 Event String: The request for a new account-identifier pool failed. The operation will be retried until the request succeeds. The error is An error event occurred. EventID: 0x00000423 Time Generated: 03/11/2014 12:53:28 Event String: The DHCP service failed to see a directory server for authorization. An error event occurred. EventID: 0x40000004 Time Generated: 03/11/2014 12:54:21 Event String: The Kerberos client received a KRB_AP_ERR_MODIFIED error from the server dc-sv-02$. The target name used was LDAP/DC-SV-02.XXXXXXXX.XXXXX.XXXX.XX/XXXXXXXX.XXXXX.XXXX.XX@XXXXXXXX.XXXXX.XXXX.XX. This indicates that the target server failed to decrypt the ticket provided by the client. This can occur when the target server principal name (SPN) is registered on an account other than the account the target service is using. Ensure that the target SPN is only registered on the account used by the server. This error can also happen if the target service account password is different than what is configured on the Kerberos Key Distribution Center for that target service. Ensure that the service on the server and the KDC are both configured to use the same password. If the server name is not fully qualified, and the target domain (XXXXXXXX.XXXXX.XXXX.XX) is different from the client domain (XXXXXXXX.XXXXX.XXXX.XX), check if there are identically named server accounts in these two domains, or use the fully-qualified name to identify the server. An error event occurred. EventID: 0x40000004 Time Generated: 03/11/2014 12:54:48 Event String: The Kerberos client received a KRB_AP_ERR_MODIFIED error from the server dc-sv-02$. The target name used was LDAP/DC-SV-02.XXXXXXXX.XXXXX.XXXX.XX. This indicates that the target server failed to decrypt the ticket provided by the client. This can occur when the target server principal name (SPN) is registered on an account other than the account the target service is using. Ensure that the target SPN is only registered on the account used by the server. This error can also happen if the target service account password is different than what is configured on the Kerberos Key Distribution Center for that target service. Ensure that the service on the server and the KDC are both configured to use the same password. If the server name is not fully qualified, and the target domain (XXXXXXXX.XXXXX.XXXX.XX) is different from the client domain (XXXXXXXX.XXXXX.XXXX.XX), check if there are identically named server accounts in these two domains, or use the fully-qualified name to identify the server. An error event occurred. EventID: 0xC00038D6 Time Generated: 03/11/2014 12:56:53 Event String: The DFS Namespace service could not initialize cross forest trust information on this domain controller, but it will periodically retry the operation. The return code is in the record data. An error event occurred. EventID: 0x40000004 Time Generated: 03/11/2014 12:57:55 Event String: The Kerberos client received a KRB_AP_ERR_MODIFIED error from the server dc-sv-02$. The target name used was XXXXXXXX\DC-SV-02$. This indicates that the target server failed to decrypt the ticket provided by the client. This can occur when the target server principal name (SPN) is registered on an account other than the account the target service is using. Ensure that the target SPN is only registered on the account used by the server. This error can also happen if the target service account password is different than what is configured on the Kerberos Key Distribution Center for that target service. Ensure that the service on the server and the KDC are both configured to use the same password. If the server name is not fully qualified, and the target domain (XXXXXXXX.XXXXX.XXXX.XX) is different from the client domain (XXXXXXXX.XXXXX.XXXX.XX), check if there are identically named server accounts in these two domains, or use the fully-qualified name to identify the server. An error event occurred. EventID: 0x40000004 Time Generated: 03/11/2014 12:58:40 Event String: The Kerberos client received a KRB_AP_ERR_MODIFIED error from the server dc-sv-02$. The target name used was cifs/DC-SV-02.XXXXXXXX.XXXXX.XXXX.XX. This indicates that the target server failed to decrypt the ticket provided by the client. This can occur when the target server principal name (SPN) is registered on an account other than the account the target service is using. Ensure that the target SPN is only registered on the account used by the server. This error can also happen if the target service account password is different than what is configured on the Kerberos Key Distribution Center for that target service. Ensure that the service on the server and the KDC are both configured to use the same password. If the server name is not fully qualified, and the target domain (XXXXXXXX.XXXXX.XXXX.XX) is different from the client domain (XXXXXXXX.XXXXX.XXXX.XX), check if there are identically named server accounts in these two domains, or use the fully-qualified name to identify the server. An error event occurred. EventID: 0x40000004 Time Generated: 03/11/2014 12:58:48 Event String: The Kerberos client received a KRB_AP_ERR_MODIFIED error from the server deploy-sv-01$. The target name used was cifs/DEPLOY-SV-01.XXXXXXXX.XXXXX.XXXX.XX. This indicates that the target server failed to decrypt the ticket provided by the client. This can occur when the target server principal name (SPN) is registered on an account other than the account the target service is using. Ensure that the target SPN is only registered on the account used by the server. This error can also happen if the target service account password is different than what is configured on the Kerberos Key Distribution Center for that target service. Ensure that the service on the server and the KDC are both configured to use the same password. If the server name is not fully qualified, and the target domain (XXXXXXXX.XXXXX.XXXX.XX) is different from the client domain (XXXXXXXX.XXXXX.XXXX.XX), check if there are identically named server accounts in these two domains, or use the fully-qualified name to identify the server. An error event occurred. EventID: 0x40000004 Time Generated: 03/11/2014 13:07:53 Event String: The Kerberos client received a KRB_AP_ERR_MODIFIED error from the server dc-sv-02$. The target name used was GC/DC-SV-02.XXXXXXXX.XXXXX.XXXX.XX/XXXXXXXX.XXXXX.XXXX.XX@XXXXXXXX.XXXXX.XXXX.XX. This indicates that the target server failed to decrypt the ticket provided by the client. This can occur when the target server principal name (SPN) is registered on an account other than the account the target service is using. Ensure that the target SPN is only registered on the account used by the server. This error can also happen if the target service account password is different than what is configured on the Kerberos Key Distribution Center for that target service. Ensure that the service on the server and the KDC are both configured to use the same password. If the server name is not fully qualified, and the target domain (XXXXXXXX.XXXXX.XXXX.XX) is different from the client domain (XXXXXXXX.XXXXX.XXXX.XX), check if there are identically named server accounts in these two domains, or use the fully-qualified name to identify the server. An error event occurred. EventID: 0x40000004 Time Generated: 03/11/2014 13:07:58 Event String: The Kerberos client received a KRB_AP_ERR_MODIFIED error from the server dc-sv-02$. The target name used was ldap/DC-SV-02.XXXXXXXX.XXXXX.XXXX.XX/XXXXXXXX.XXXXX.XXXX.XX@XXXXXXXX.XXXXX.XXXX.XX. This indicates that the target server failed to decrypt the ticket provided by the client. This can occur when the target server principal name (SPN) is registered on an account other than the account the target service is using. Ensure that the target SPN is only registered on the account used by the server. This error can also happen if the target service account password is different than what is configured on the Kerberos Key Distribution Center for that target service. Ensure that the service on the server and the KDC are both configured to use the same password. If the server name is not fully qualified, and the target domain (XXXXXXXX.XXXXX.XXXX.XX) is different from the client domain (XXXXXXXX.XXXXX.XXXX.XX), check if there are identically named server accounts in these two domains, or use the fully-qualified name to identify the server. An error event occurred. EventID: 0x40000004 Time Generated: 03/11/2014 13:08:39 Event String: The Kerberos client received a KRB_AP_ERR_MODIFIED error from the server dc-sv-02$. The target name used was LDAP/bd4c0c59-1269-49f0-bda5-b5b15cf57edb._msdcs.XXXXXXXX.XXXXX.XXXX.XX. This indicates that the target server failed to decrypt the ticket provided by the client. This can occur when the target server principal name (SPN) is registered on an account other than the account the target service is using. Ensure that the target SPN is only registered on the account used by the server. This error can also happen if the target service account password is different than what is configured on the Kerberos Key Distribution Center for that target service. Ensure that the service on the server and the KDC are both configured to use the same password. If the server name is not fully qualified, and the target domain (XXXXXXXX.XXXXX.XXXX.XX) is different from the client domain (XXXXXXXX.XXXXX.XXXX.XX), check if there are identically named server accounts in these two domains, or use the fully-qualified name to identify the server. ......................... DC-SV-01 failed test SystemLog Starting test: VerifyReferences ......................... DC-SV-01 passed test VerifyReferences Running partition tests on : ForestDnsZones Starting test: CheckSDRefDom ......................... ForestDnsZones passed test CheckSDRefDom Starting test: CrossRefValidation ......................... ForestDnsZones passed test CrossRefValidation Running partition tests on : DomainDnsZones Starting test: CheckSDRefDom ......................... DomainDnsZones passed test CheckSDRefDom Starting test: CrossRefValidation ......................... DomainDnsZones passed test CrossRefValidation Running partition tests on : Schema Starting test: CheckSDRefDom ......................... Schema passed test CheckSDRefDom Starting test: CrossRefValidation ......................... Schema passed test CrossRefValidation Running partition tests on : Configuration Starting test: CheckSDRefDom ......................... Configuration passed test CheckSDRefDom Starting test: CrossRefValidation ......................... Configuration passed test CrossRefValidation Running partition tests on : XXXXXXXX Starting test: CheckSDRefDom ......................... XXXXXXXX passed test CheckSDRefDom Starting test: CrossRefValidation ......................... XXXXXXXX passed test CrossRefValidation Running enterprise tests on : XXXXXXXX.XXXXX.XXXX.XX Starting test: LocatorCheck [DC-SV-02] LDAP bind failed with error 8341, A directory service error has occurred.. Warning: DcGetDcName(TIME_SERVER) call failed, error 1355 A Time Server could not be located. The server holding the PDC role is down. Warning: DcGetDcName(GOOD_TIME_SERVER_PREFERRED) call failed, error 1355 A Good Time Server could not be located. ......................... XXXXXXXX.XXXXX.XXXX.XX failed test LocatorCheck Starting test: Intersite ......................... XXXXXXXX.XXXXX.XXXX.XX passed test Intersite Directory Server Diagnosis Performing initial setup: Trying to find home server... Home Server = DC-SV-01 * Identified AD Forest. Done gathering initial info. Doing initial required tests Testing server: Default-First-Site\DC-SV-01 Starting test: Connectivity ......................... DC-SV-01 passed test Connectivity Doing primary tests Testing server: Default-First-Site\DC-SV-01 Starting test: Advertising Warning: DsGetDcName returned information for \\DC-SV-02.XXXXXXXX.XXXXX.XXXX.XX, when we were trying to reach DC-SV-01. SERVER IS NOT RESPONDING or IS NOT CONSIDERED SUITABLE. ......................... DC-SV-01 failed test Advertising Starting test: FrsEvent There are warning or error events within the last 24 hours after the SYSVOL has been shared. Failing SYSVOL replication problems may cause Group Policy problems. ......................... DC-SV-01 passed test FrsEvent Starting test: DFSREvent ......................... DC-SV-01 passed test DFSREvent Starting test: SysVolCheck ......................... DC-SV-01 passed test SysVolCheck Starting test: KccEvent A warning event occurred. EventID: 0x80000677 Time Generated: 03/11/2014 13:07:53 Event String: Active Directory Domain Services attempted to communicate with the following global catalog and the attempts were unsuccessful. An error event occurred. EventID: 0xC0000466 Time Generated: 03/11/2014 13:07:53 Event String: Active Directory Domain Services was unable to establish a connection with the global catalog. A warning event occurred. EventID: 0x8000082C Time Generated: 03/11/2014 13:08:23 Event String: A warning event occurred. EventID: 0x8000082C Time Generated: 03/11/2014 13:09:23 Event String: A warning event occurred. EventID: 0x8000082C Time Generated: 03/11/2014 13:09:53 Event String: ......................... DC-SV-01 failed test KccEvent Starting test: KnowsOfRoleHolders ......................... DC-SV-01 passed test KnowsOfRoleHolders Starting test: MachineAccount ......................... DC-SV-01 passed test MachineAccount Starting test: NCSecDesc ......................... DC-SV-01 passed test NCSecDesc Starting test: NetLogons Unable to connect to the NETLOGON share! (\\DC-SV-01\netlogon) [DC-SV-01] An net use or LsaPolicy operation failed with error 67, The network name cannot be found.. ......................... DC-SV-01 failed test NetLogons Starting test: ObjectsReplicated ......................... DC-SV-01 passed test ObjectsReplicated Starting test: Replications [Replications Check,DC-SV-01] A recent replication attempt failed: From DC-SV-02 to DC-SV-01 Naming Context: DC=ForestDnsZones,DC=XXXXXXXX,DC=XXXXX,DC=sch,DC=uk The replication generated an error (1256): The remote system is not available. For information about network troubleshooting, see Windows Help. The failure occurred at 2014-03-11 12:52:53. The last success occurred at 2013-12-20 13:49:38. 24 failures have occurred since the last success. [DC-SV-02] DsBindWithSpnEx() failed with error -2146893022, The target principal name is incorrect.. [Replications Check,DC-SV-01] A recent replication attempt failed: From DC-SV-02 to DC-SV-01 Naming Context: DC=DomainDnsZones,DC=XXXXXXXX,DC=XXXXX,DC=sch,DC=uk The replication generated an error (1256): The remote system is not available. For information about network troubleshooting, see Windows Help. The failure occurred at 2014-03-11 12:52:53. The last success occurred at 2013-12-20 13:49:38. 24 failures have occurred since the last success. [Replications Check,DC-SV-01] A recent replication attempt failed: From DC-SV-02 to DC-SV-01 Naming Context: CN=Schema,CN=Configuration,DC=XXXXXXXX,DC=XXXXX,DC=sch,DC=uk The replication generated an error (-2146893022): The target principal name is incorrect. The failure occurred at 2014-03-11 12:52:53. The last success occurred at 2013-12-20 13:49:38. 24 failures have occurred since the last success. [Replications Check,DC-SV-01] A recent replication attempt failed: From DC-SV-02 to DC-SV-01 Naming Context: CN=Configuration,DC=XXXXXXXX,DC=XXXXX,DC=sch,DC=uk The replication generated an error (-2146893022): The target principal name is incorrect. The failure occurred at 2014-03-11 12:52:53. The last success occurred at 2013-12-20 13:49:38. 24 failures have occurred since the last success. [Replications Check,DC-SV-01] A recent replication attempt failed: From DC-SV-02 to DC-SV-01 Naming Context: DC=XXXXXXXX,DC=XXXXX,DC=sch,DC=uk The replication generated an error (-2146893022): The target principal name is incorrect. The failure occurred at 2014-03-11 12:52:53. The last success occurred at 2013-12-20 14:05:09. 24 failures have occurred since the last success. ......................... DC-SV-01 failed test Replications Starting test: RidManager The DS has corrupt data: rIDPreviousAllocationPool value is not valid No rids allocated -- please check eventlog. ......................... DC-SV-01 failed test RidManager Starting test: Services ......................... DC-SV-01 passed test Services Starting test: SystemLog An error event occurred. EventID: 0x40000004 Time Generated: 03/11/2014 12:27:21 Event String: The Kerberos client received a KRB_AP_ERR_MODIFIED error from the server print-sv-01$. The target name used was cifs/print-sv-01.XXXXXXXX.XXXXX.XXXX.XX. This indicates that the target server failed to decrypt the ticket provided by the client. This can occur when the target server principal name (SPN) is registered on an account other than the account the target service is using. Ensure that the target SPN is only registered on the account used by the server. This error can also happen if the target service account password is different than what is configured on the Kerberos Key Distribution Center for that target service. Ensure that the service on the server and the KDC are both configured to use the same password. If the server name is not fully qualified, and the target domain (XXXXXXXX.XXXXX.XXXX.XX) is different from the client domain (XXXXXXXX.XXXXX.XXXX.XX), check if there are identically named server accounts in these two domains, or use the fully-qualified name to identify the server. A warning event occurred. EventID: 0x000003F6 Time Generated: 03/11/2014 12:28:53 Event String: Name resolution for the name 10.in-addr.arpa timed out after none of the configured DNS servers responded. An error event occurred. EventID: 0x40000004 Time Generated: 03/11/2014 12:52:53 Event String: The Kerberos client received a KRB_AP_ERR_MODIFIED error from the server dc-sv-02$. The target name used was E3514235-4B06-11D1-AB04-00C04FC2DCD2/bd4c0c59-1269-49f0-bda5-b5b15cf57edb/XXXXXXXX.XXXXX.XXXX.XX@XXXXXXXX.XXXXX.XXXX.XX. This indicates that the target server failed to decrypt the ticket provided by the client. This can occur when the target server principal name (SPN) is registered on an account other than the account the target service is using. Ensure that the target SPN is only registered on the account used by the server. This error can also happen if the target service account password is different than what is configured on the Kerberos Key Distribution Center for that target service. Ensure that the service on the server and the KDC are both configured to use the same password. If the server name is not fully qualified, and the target domain (XXXXXXXX.XXXXX.XXXX.XX) is different from the client domain (XXXXXXXX.XXXXX.XXXX.XX), check if there are identically named server accounts in these two domains, or use the fully-qualified name to identify the server. An error event occurred. EventID: 0x0000410B Time Generated: 03/11/2014 12:53:22 Event String: The request for a new account-identifier pool failed. The operation will be retried until the request succeeds. The error is An error event occurred. EventID: 0x00000423 Time Generated: 03/11/2014 12:53:28 Event String: The DHCP service failed to see a directory server for authorization. An error event occurred. EventID: 0x40000004 Time Generated: 03/11/2014 12:54:21 Event String: The Kerberos client received a KRB_AP_ERR_MODIFIED error from the server dc-sv-02$. The target name used was LDAP/DC-SV-02.XXXXXXXX.XXXXX.XXXX.XX/XXXXXXXX.XXXXX.XXXX.XX@XXXXXXXX.XXXXX.XXXX.XX. This indicates that the target server failed to decrypt the ticket provided by the client. This can occur when the target server principal name (SPN) is registered on an account other than the account the target service is using. Ensure that the target SPN is only registered on the account used by the server. This error can also happen if the target service account password is different than what is configured on the Kerberos Key Distribution Center for that target service. Ensure that the service on the server and the KDC are both configured to use the same password. If the server name is not fully qualified, and the target domain (XXXXXXXX.XXXXX.XXXX.XX) is different from the client domain (XXXXXXXX.XXXXX.XXXX.XX), check if there are identically named server accounts in these two domains, or use the fully-qualified name to identify the server. An error event occurred. EventID: 0x40000004 Time Generated: 03/11/2014 12:54:48 Event String: The Kerberos client received a KRB_AP_ERR_MODIFIED error from the server dc-sv-02$. The target name used was LDAP/DC-SV-02.XXXXXXXX.XXXXX.XXXX.XX. This indicates that the target server failed to decrypt the ticket provided by the client. This can occur when the target server principal name (SPN) is registered on an account other than the account the target service is using. Ensure that the target SPN is only registered on the account used by the server. This error can also happen if the target service account password is different than what is configured on the Kerberos Key Distribution Center for that target service. Ensure that the service on the server and the KDC are both configured to use the same password. If the server name is not fully qualified, and the target domain (XXXXXXXX.XXXXX.XXXX.XX) is different from the client domain (XXXXXXXX.XXXXX.XXXX.XX), check if there are identically named server accounts in these two domains, or use the fully-qualified name to identify the server. An error event occurred. EventID: 0xC00038D6 Time Generated: 03/11/2014 12:56:53 Event String: The DFS Namespace service could not initialize cross forest trust information on this domain controller, but it will periodically retry the operation. The return code is in the record data. An error event occurred. EventID: 0x40000004 Time Generated: 03/11/2014 12:57:55 Event String: The Kerberos client received a KRB_AP_ERR_MODIFIED error from the server dc-sv-02$. The target name used was XXXXXXXX\DC-SV-02$. This indicates that the target server failed to decrypt the ticket provided by the client. This can occur when the target server principal name (SPN) is registered on an account other than the account the target service is using. Ensure that the target SPN is only registered on the account used by the server. This error can also happen if the target service account password is different than what is configured on the Kerberos Key Distribution Center for that target service. Ensure that the service on the server and the KDC are both configured to use the same password. If the server name is not fully qualified, and the target domain (XXXXXXXX.XXXXX.XXXX.XX) is different from the client domain (XXXXXXXX.XXXXX.XXXX.XX), check if there are identically named server accounts in these two domains, or use the fully-qualified name to identify the server. An error event occurred. EventID: 0x40000004 Time Generated: 03/11/2014 12:58:40 Event String: The Kerberos client received a KRB_AP_ERR_MODIFIED error from the server dc-sv-02$. The target name used was cifs/DC-SV-02.XXXXXXXX.XXXXX.XXXX.XX. This indicates that the target server failed to decrypt the ticket provided by the client. This can occur when the target server principal name (SPN) is registered on an account other than the account the target service is using. Ensure that the target SPN is only registered on the account used by the server. This error can also happen if the target service account password is different than what is configured on the Kerberos Key Distribution Center for that target service. Ensure that the service on the server and the KDC are both configured to use the same password. If the server name is not fully qualified, and the target domain (XXXXXXXX.XXXXX.XXXX.XX) is different from the client domain (XXXXXXXX.XXXXX.XXXX.XX), check if there are identically named server accounts in these two domains, or use the fully-qualified name to identify the server. An error event occurred. EventID: 0x40000004 Time Generated: 03/11/2014 12:58:48 Event String: The Kerberos client received a KRB_AP_ERR_MODIFIED error from the server deploy-sv-01$. The target name used was cifs/DEPLOY-SV-01.XXXXXXXX.XXXXX.XXXX.XX. This indicates that the target server failed to decrypt the ticket provided by the client. This can occur when the target server principal name (SPN) is registered on an account other than the account the target service is using. Ensure that the target SPN is only registered on the account used by the server. This error can also happen if the target service account password is different than what is configured on the Kerberos Key Distribution Center for that target service. Ensure that the service on the server and the KDC are both configured to use the same password. If the server name is not fully qualified, and the target domain (XXXXXXXX.XXXXX.XXXX.XX) is different from the client domain (XXXXXXXX.XXXXX.XXXX.XX), check if there are identically named server accounts in these two domains, or use the fully-qualified name to identify the server. An error event occurred. EventID: 0x40000004 Time Generated: 03/11/2014 13:07:53 Event String: The Kerberos client received a KRB_AP_ERR_MODIFIED error from the server dc-sv-02$. The target name used was GC/DC-SV-02.XXXXXXXX.XXXXX.XXXX.XX/XXXXXXXX.XXXXX.XXXX.XX@XXXXXXXX.XXXXX.XXXX.XX. This indicates that the target server failed to decrypt the ticket provided by the client. This can occur when the target server principal name (SPN) is registered on an account other than the account the target service is using. Ensure that the target SPN is only registered on the account used by the server. This error can also happen if the target service account password is different than what is configured on the Kerberos Key Distribution Center for that target service. Ensure that the service on the server and the KDC are both configured to use the same password. If the server name is not fully qualified, and the target domain (XXXXXXXX.XXXXX.XXXX.XX) is different from the client domain (XXXXXXXX.XXXXX.XXXX.XX), check if there are identically named server accounts in these two domains, or use the fully-qualified name to identify the server. An error event occurred. EventID: 0x40000004 Time Generated: 03/11/2014 13:07:58 Event String: The Kerberos client received a KRB_AP_ERR_MODIFIED error from the server dc-sv-02$. The target name used was ldap/DC-SV-02.XXXXXXXX.XXXXX.XXXX.XX/XXXXXXXX.XXXXX.XXXX.XX@XXXXXXXX.XXXXX.XXXX.XX. This indicates that the target server failed to decrypt the ticket provided by the client. This can occur when the target server principal name (SPN) is registered on an account other than the account the target service is using. Ensure that the target SPN is only registered on the account used by the server. This error can also happen if the target service account password is different than what is configured on the Kerberos Key Distribution Center for that target service. Ensure that the service on the server and the KDC are both configured to use the same password. If the server name is not fully qualified, and the target domain (XXXXXXXX.XXXXX.XXXX.XX) is different from the client domain (XXXXXXXX.XXXXX.XXXX.XX), check if there are identically named server accounts in these two domains, or use the fully-qualified name to identify the server. An error event occurred. EventID: 0x40000004 Time Generated: 03/11/2014 13:08:39 Event String: The Kerberos client received a KRB_AP_ERR_MODIFIED error from the server dc-sv-02$. The target name used was LDAP/bd4c0c59-1269-49f0-bda5-b5b15cf57edb._msdcs.XXXXXXXX.XXXXX.XXXX.XX. This indicates that the target server failed to decrypt the ticket provided by the client. This can occur when the target server principal name (SPN) is registered on an account other than the account the target service is using. Ensure that the target SPN is only registered on the account used by the server. This error can also happen if the target service account password is different than what is configured on the Kerberos Key Distribution Center for that target service. Ensure that the service on the server and the KDC are both configured to use the same password. If the server name is not fully qualified, and the target domain (XXXXXXXX.XXXXX.XXXX.XX) is different from the client domain (XXXXXXXX.XXXXX.XXXX.XX), check if there are identically named server accounts in these two domains, or use the fully-qualified name to identify the server. An error event occurred. EventID: 0x40000004 Time Generated: 03/11/2014 13:08:39 Event String: The Kerberos client received a KRB_AP_ERR_MODIFIED error from the server dc-sv-02$. The target name used was ldap/dc-sv-02.XXXXXXXX.XXXXX.XXXX.XX. This indicates that the target server failed to decrypt the ticket provided by the client. This can occur when the target server principal name (SPN) is registered on an account other than the account the target service is using. Ensure that the target SPN is only registered on the account used by the server. This error can also happen if the target service account password is different than what is configured on the Kerberos Key Distribution Center for that target service. Ensure that the service on the server and the KDC are both configured to use the same password. If the server name is not fully qualified, and the target domain (XXXXXXXX.XXXXX.XXXX.XX) is different from the client domain (XXXXXXXX.XXXXX.XXXX.XX), check if there are identically named server accounts in these two domains, or use the fully-qualified name to identify the server. An error event occurred. EventID: 0x40000004 Time Generated: 03/11/2014 13:09:36 Event String: The Kerberos client received a KRB_AP_ERR_MODIFIED error from the server dc-sv-02$. The target name used was DNS/dc-sv-02.XXXXXXXX.XXXXX.XXXX.XX. This indicates that the target server failed to decrypt the ticket provided by the client. This can occur when the target server principal name (SPN) is registered on an account other than the account the target service is using. Ensure that the target SPN is only registered on the account used by the server. This error can also happen if the target service account password is different than what is configured on the Kerberos Key Distribution Center for that target service. Ensure that the service on the server and the KDC are both configured to use the same password. If the server name is not fully qualified, and the target domain (XXXXXXXX.XXXXX.XXXX.XX) is different from the client domain (XXXXXXXX.XXXXX.XXXX.XX), check if there are identically named server accounts in these two domains, or use the fully-qualified name to identify the server. An error event occurred. EventID: 0x40000004 Time Generated: 03/11/2014 13:10:34 Event String: The Kerberos client received a KRB_AP_ERR_MODIFIED error from the server adminsvr1$. The target name used was cifs/ADMINSVR1.XXXXXXXX.XXXXX.XXXX.XX. This indicates that the target server failed to decrypt the ticket provided by the client. This can occur when the target server principal name (SPN) is registered on an account other than the account the target service is using. Ensure that the target SPN is only registered on the account used by the server. This error can also happen if the target service account password is different than what is configured on the Kerberos Key Distribution Center for that target service. Ensure that the service on the server and the KDC are both configured to use the same password. If the server name is not fully qualified, and the target domain (XXXXXXXX.XXXXX.XXXX.XX) is different from the client domain (XXXXXXXX.XXXXX.XXXX.XX), check if there are identically named server accounts in these two domains, or use the fully-qualified name to identify the server. An error event occurred. EventID: 0x40000004 Time Generated: 03/11/2014 13:10:52 Event String: The Kerberos client received a KRB_AP_ERR_MODIFIED error from the server file-sv-01$. The target name used was cifs/file-sv-01.XXXXXXXX.XXXXX.XXXX.XX. This indicates that the target server failed to decrypt the ticket provided by the client. This can occur when the target server principal name (SPN) is registered on an account other than the account the target service is using. Ensure that the target SPN is only registered on the account used by the server. This error can also happen if the target service account password is different than what is configured on the Kerberos Key Distribution Center for that target service. Ensure that the service on the server and the KDC are both configured to use the same password. If the server name is not fully qualified, and the target domain (XXXXXXXX.XXXXX.XXXX.XX) is different from the client domain (XXXXXXXX.XXXXX.XXXX.XX), check if there are identically named server accounts in these two domains, or use the fully-qualified name to identify the server. ......................... DC-SV-01 failed test SystemLog Starting test: VerifyReferences ......................... DC-SV-01 passed test VerifyReferences Running partition tests on : ForestDnsZones Starting test: CheckSDRefDom ......................... ForestDnsZones passed test CheckSDRefDom Starting test: CrossRefValidation ......................... ForestDnsZones passed test CrossRefValidation Running partition tests on : DomainDnsZones Starting test: CheckSDRefDom ......................... DomainDnsZones passed test CheckSDRefDom Starting test: CrossRefValidation ......................... DomainDnsZones passed test CrossRefValidation Running partition tests on : Schema Starting test: CheckSDRefDom ......................... Schema passed test CheckSDRefDom Starting test: CrossRefValidation ......................... Schema passed test CrossRefValidation Running partition tests on : Configuration Starting test: CheckSDRefDom ......................... Configuration passed test CheckSDRefDom Starting test: CrossRefValidation ......................... Configuration passed test CrossRefValidation Running partition tests on : XXXXXXXX Starting test: CheckSDRefDom ......................... XXXXXXXX passed test CheckSDRefDom Starting test: CrossRefValidation ......................... XXXXXXXX passed test CrossRefValidation Running enterprise tests on : XXXXXXXX.XXXXX.XXXX.XX Starting test: LocatorCheck [DC-SV-02] LDAP bind failed with error 8341, A directory service error has occurred.. Warning: DcGetDcName(TIME_SERVER) call failed, error 1355 A Time Server could not be located. The server holding the PDC role is down. Warning: DcGetDcName(GOOD_TIME_SERVER_PREFERRED) call failed, error 1355 A Good Time Server could not be located. ......................... XXXXXXXX.XXXXX.XXXX.XX failed test LocatorCheck Starting test: Intersite ......................... XXXXXXXX.XXXXX.XXXX.XX passed test Intersite