DCdiag results:
An error event occurred. EventID: 0x000003EE
Time Generated: 06/19/2012 12:12:54
Event String:
The processing of Group Policy failed. Windows could not authenticat
e to the Active Directory service on a domain controller. (LDAP Bind function ca
ll failed). Look in the details tab for error code and description.
An error event occurred. EventID: 0x000003EE
Time Generated: 06/19/2012 12:17:58
Event String:
The processing of Group Policy failed. Windows could not authenticat
e to the Active Directory service on a domain controller. (LDAP Bind function ca
ll failed). Look in the details tab for error code and description.
An error event occurred. EventID: 0x40000004
Time Generated: 06/19/2012 12:23:03
Event String:
The Kerberos client received a KRB_AP_ERR_MODIFIED error from the se
rver host/chief.#####.###. The target name used was ldap/CHIEF.#####.###/#####.###@#####.###. This indicates that the target server failed to decrypt the ticket provide
d by the client. This can occur when the target server principal name (SPN) is r
egistered on an account other than the account the target service is using. Plea
se ensure that the target SPN is registered on, and only registered on, the acco
unt used by the server. This error can also happen when the target service is us
ing a different password for the target service account than what the Kerberos K
ey Distribution Center (KDC) has for the target service account. Please ensure t
hat the service on the server and the KDC are both updated to use the current pa
ssword. If the server name is not fully qualified, and the target domain (#####.###) is different from the client domain (#####.###), check if there are identically
named server accounts in these two domains, or use the fully-qualified name to
identify the server.