Jump to content

miljw002

Members
  • Posts

    5
  • Joined

  • Last visited

Reputation

10 Good

About miljw002

Personal Information

  • Location
    Adelaide
  1. I've been getting the same error (below) since upgrading my DC's to 2025 as well. system: error - 2025/02/19 21:00:06 - KDC (7) - n/a "The Security Account Manager failed a KDC request in an unexpected way. The error is in the data field. The account name was ? and lookup type 0x108. Which is a bit unhelpful as it's supposed to include the computer name and not just a "?". I've got a mix of Windows Server 2025, Windows 10, Redhat 9, ESXi 7, UnRAID as Domain joined, so could be any number of them. This is looking like one of the symptoms of how Kerberos is broken on Windows Server 2025. I was running Windows Server 2025 as a member for months before upgrading, and had none of the issues being described here. They all started when I upgraded the DCs. The Feb update doesn't appear to have helped. I'm just hoping that the March or April one will fix Kerberos in Server 2025. James
  2. Hi Again, I did more testing on Linux (Redhat 9) trying to join with SSSD and it's still failing with the same errors after the CU update for Jan 2025. Did some more Googling and it looks like there is a regression in Windows Server 2025's Kerberos implementation. https://gitlab.freedesktop.org/realmd/adcli/-/issues/40 The prediction in that thread is it may take until the March CU to fix this.
  3. Hi, Your idea was the first good lead I’d seen of what’s different but it’s not the complete picture. Enabling the old methods allowed ESXi to update their passwords and those errors are gone. The bad news is Linux in general still isn’t working with SSSD (still password change errors), and I’m still seeing KDC errors. Microsoft has certainly broken this well, and seems really slow to fix.
  4. Hi All, I’ve just reviewed the thread over on Microsoft (https://answers.microsoft.com/en-us/windowserver/forum/all/server-2025-domain-controllers-trust-relationship/4ef17f8e-8677-4ecd-a675-e5df1f4b48cf?page=2) people were referring to. Based on one post in there, I could see Server 2025 has now blocked by default old/legacy/less secure methods to remotely change passwords. As of about 30 minutes I’ve changed this on my DC’s and ESXi has stopped the constant errors about can’t change passwords. I’ll need to monitor and test more, but enabling the old methods seems to have at least stopped the ESXi errors. Also, looking in AD at the ESXi computer objects I can see the password last updated value finally updated.
  5. Hi All, I’ve just signed up as I’ve been reading this thread and wanted to contribute. This is the only discussion on this issue I’ve found so far. I’ve got a home lab and it appears impacted by this. Started out life as Server 2016, and has gone through upgrades to 2019, 2022, and now 2025. It’s got RedHat 9, macOS, ESXi domain members and all are presenting different errors about computer account password changes. On the Linux side, if I try and join a member using SSSD it failed with the message stream issue. If I join using the “samba-client” option it joins successfully. On the ESXi side, they are all complaining every 30 minutes they can’t change their machine account passwords. I’ve checked various settings, but not tried to remove and readd or similar yet. The Event Log on the DC’s have a KDC/Kerberos error about once a day about a lookup failure, but the error doesn’t include any account/computer details. 3 days after I’d upgraded the DCs I noticed replication issues, and these appeared to be related to DNS lookup failures. I run IPv6 at home and server 2025 seems to have another strange issue. With the firewall on, clients fail to access the DNS server on IPv6. Works on IPv4. I’ve checked the built in rules, and tried making a custom allow for DNS over IPv6. Only thing that allowed DNS on IPv6 to start working was to disable the firewall completely. I’m still at the investigation stage, as I’m finding various strange issues with server 2025. Part of why I upgraded the homelab was to see what this is like before experiencing this in PROD
×
×
  • Create New...