Thursday, September 6, 2007

There are multiple accounts with name cifs/102-PC12.domain.edu of type DS_SERVICE_PRINCIPAL_NAME

I've been having the following error logging on my domain controllers about every hour for quite some time now and finally got around to drilling down to figure it out.

Type: Error
Event: 11
Date Time: 8/29/2007 7:46:33 AM
Source: KDC
ComputerName: DC2
Category: None
User: N/A
Description: There are multiple accounts with name cifs/102-PC12.domain.edu of type DS_SERVICE_PRINCIPAL_NAME.

After a little research and lots of luck... I decided to use ldp.exe to do a quick search of the (serivce
principal=*.102-PC12.domain.edu). What do you know... it came up with 2 accounts sharing that name. I quickly found the one that was a problem and deleted it. It turns out somebody put an image on a few machines without first pulling the source from the domain... not a good idea.


1 comment:

  1. Hi,

    There's no way to get CIFS SPNs as they're not registeres in AD.

    With that search you'd just get for instance HOST SPNs.

    ReplyDelete