Receiving Event ID 673 in Failure Aud 0x1B
I am receiving continues Event ID 673 in Windows 2003 Ent acting as GCS this error comes from a service account for Symantec EV application and the client address is the same IP for EV windows
2003 server, Failure Code: 0x1B caused by Kerberos error code KDC_ERR_MUST_USE_USER2USER please advice how can I solve this as I feel this error causing some other issues on EV side, thanks
Event Type: Failure Audit
Event Source: Security
Event Category: Account Logon
Event ID: 673
Date: 4/30/2010
Time: 5:49:10 PM
User: NT AUTHORITY\SYSTEM
Computer: XXXXXCDC01
Description:
Service Ticket Request:
User Name: evaultadmin@XXXXX.XX.COM
User Domain: XXXXX.XXX.COM
Service Name: evaultadmin
Service ID: -
Ticket Options: 0x40810000
Ticket Encryption Type: -
Client Address: XXX.X.XXX.XX
Failure Code: 0x1B
Logon GUID: -
Transited Services: -
May 3rd, 2010 8:36pm
Hi,
Based current information, this error may be caused by incorrect SPN settings. Please refer to the following articles to check the Symantec service SPN. You may need contact Symantec Support to get information how to create SPN for EV.
Service Logons Fail Due to Incorrectly Set SPNs
http://technet.microsoft.com/en-us/library/cc772897(WS.10).aspx
http://social.msdn.microsoft.com/forums/en-US/tfsadmin/thread/8ff15cd6-cdc8-47fe-bd7b-37a5ba26b174
Offline Vault hangs at the beginning of the initial download when Archive Explorer is enabled
http://seer.entsupport.symantec.com/docs/295677.htm
Thanks.This posting is provided "AS IS" with no warranties, and confers no rights.
Free Windows Admin Tool Kit Click here and download it now
May 4th, 2010 10:05am
Hi,
Do you need any other assistance? If there is anything we can do for you, please let us know.
Thanks.This posting is provided "AS IS" with no warranties, and confers no rights.
May 10th, 2010 4:35am
Thanks for replying me back, I am still reciving event id # 673 same cleitn ip address I have did set SPN name as Symantec advices me but still this didn't stop the error. any other idea?,
Thanks
Free Windows Admin Tool Kit Click here and download it now
May 11th, 2010 7:12pm
Try contacting Symantec support.Paul Adare CTO IdentIT Inc. ILM MVP
May 11th, 2010 7:41pm
I've windows 2003 domain controller and logs come from Hyper-v 2008 R2 Core Servers.
I've the exact event log on the domain controller coming from Hyper-V 2008 R 2 core servers. There 2 servers joined to domain and Failover Clustered. They logs on domain contorller.
If so what kind of SPN do I need to register. What do I need to do?
Event Type: Failure Audit
Event Source: Security
Event Category: Account Logon
Event ID: 673
Date: 4/30/2010
Time: 5:49:10 PM
User: NT AUTHORITY\SYSTEM
Computer: XXXXXCDC01
Description:
Service Ticket Request:
User Name: evaultadmin@XXXXX.XX.COM
User Domain: XXXXX.XXX.COM
Service Name: evaultadmin
Service ID: -
Ticket Options: 0x40810000
Ticket Encryption Type: -
Client Address: XXX.X.XXX.XX
Failure Code: 0x1B
Logon GUID: -
Transited Services: -
Free Windows Admin Tool Kit Click here and download it now
July 22nd, 2010 10:09am