Showing posts with label Domain Controller. Show all posts
Showing posts with label Domain Controller. Show all posts

Friday, May 1, 2015

Active Directory upgrade 2003 to 2008R2 with error “An Authentication Error Has Occurred. The Encryption Type Requested Is not supported by the KDC”

we experinced that after upgraded the Domain and Forest Level from 2003 to 2008R2, after a day, I cannot connect to my Hyper V Virtual machines with following error ” An Authentication Error Has Occurred. The Encryption Type Requested Is not supported by the KDC”. On the Exchange 2010 server, the transport server stopped and follow error message on application event log,
“ Process MSEXCHANGEADTOPOLOGYSERVICE.EXE (PID=xxxx). Topology discovery failed, error 0×80040952 (LDAP_LOCAL_ERROR (Client-side internal error or bad LDAP message))….”
“Process STORE.EXE (PID=xxxx). All Global Catalog Servers in forest DC=xxx,DC=xx,DC=xx are not responding.”
”Process STORE.EXE (PID=xxxx). All Domain Controller Servers in use are not responding”

A simple resolution to all this trouble is to restart the KERBEROS DISTRIBUTION KEY or KDC service on all Domain controllers. While simply restarting the Service will solve the problem, probably better off just doing a proper restart after upgrading your functional levels, only from 2003 to 2008 / 2008 R2.

Image result for windows 2003 eos

Friday, April 17, 2015

NTP time for Domain Controller

Time in windows domain is crucial. 5 minutes different between server and client will not allowed client to login to the computer, subsequently all authentication and encryption might just failed. by default, all domain joined client will get their time from Domain controller. If your domain controller is virtualized, strongly suggest you don’t use any hypervisor tool(VMWare tool or HyperV integration tool) to sync time between domain controller and the hypervisor hosts. Time syncing option must unchecked.

 

To configure the domain controller to sync with external time source.

 

  1. Login to primary domain controller
  2. Start cmd or powershell with administrator privilege
  3. Execute to command as below,
    # w32tm.exe /config /manualpeerlist:”0.us.pool.ntp.org 1.us.pool.ntp.org 2.us.pool.ntp.org.us.pool.ntp.org” /syncfromflags:manual /reliable:YES /update
    image
  4. Notes: You can find the closest time server near you by browsing the following page and clicking on the nearest zone:!http://www.pool.ntp.org/zone/@

  5. run the command to update,
    # w32tm.exe /config /update
  6. Restart windows time service
    (For Powershell)
    # Restart-Service w32time
    (For CMD)
    # net stop w32time
    # net start w32time

    image

 

 

That’s all !

if you have any domain member, you can either wait until the next synchronization or restart w32time service to sync time with domain controller.