Receiving Event ID 673 in Failure Aud 0x1B
I am receiving continues Event ID 673 in Windows 2003 Ent acting as GCS this error comes from a service account for Symantec EV application and the client address is the same IP for EV windows 2003 server, Failure Code: 0x1B caused by Kerberos error code KDC_ERR_MUST_USE_USER2USER please advice how can I solve this as I feel this error causing some other issues on EV side, thanks Event Type: Failure Audit Event Source: Security Event Category: Account Logon Event ID: 673 Date: 4/30/2010 Time: 5:49:10 PM User: NT AUTHORITY\SYSTEM Computer: XXXXXCDC01 Description: Service Ticket Request: User Name: evaultadmin@XXXXX.XX.COM User Domain: XXXXX.XXX.COM Service Name: evaultadmin Service ID: - Ticket Options: 0x40810000 Ticket Encryption Type: - Client Address: XXX.X.XXX.XX Failure Code: 0x1B Logon GUID: - Transited Services: -
May 3rd, 2010 8:36pm

Hi, Based current information, this error may be caused by incorrect SPN settings. Please refer to the following articles to check the Symantec service SPN. You may need contact Symantec Support to get information how to create SPN for EV. Service Logons Fail Due to Incorrectly Set SPNs http://technet.microsoft.com/en-us/library/cc772897(WS.10).aspx http://social.msdn.microsoft.com/forums/en-US/tfsadmin/thread/8ff15cd6-cdc8-47fe-bd7b-37a5ba26b174 Offline Vault hangs at the beginning of the initial download when Archive Explorer is enabled http://seer.entsupport.symantec.com/docs/295677.htm Thanks.This posting is provided "AS IS" with no warranties, and confers no rights.
Free Windows Admin Tool Kit Click here and download it now
May 4th, 2010 10:05am

Hi, Do you need any other assistance? If there is anything we can do for you, please let us know. Thanks.This posting is provided "AS IS" with no warranties, and confers no rights.
May 10th, 2010 4:35am

Thanks for replying me back, I am still reciving event id # 673 same cleitn ip address I have did set SPN name as Symantec advices me but still this didn't stop the error. any other idea?, Thanks
Free Windows Admin Tool Kit Click here and download it now
May 11th, 2010 7:12pm

Try contacting Symantec support.Paul Adare CTO IdentIT Inc. ILM MVP
May 11th, 2010 7:41pm

I've windows 2003 domain controller and logs come from Hyper-v 2008 R2 Core Servers. I've the exact event log on the domain controller coming from Hyper-V 2008 R 2 core servers. There 2 servers joined to domain and Failover Clustered. They logs on domain contorller. If so what kind of SPN do I need to register. What do I need to do? Event Type: Failure Audit Event Source: Security Event Category: Account Logon Event ID: 673 Date: 4/30/2010 Time: 5:49:10 PM User: NT AUTHORITY\SYSTEM Computer: XXXXXCDC01 Description: Service Ticket Request: User Name: evaultadmin@XXXXX.XX.COM User Domain: XXXXX.XXX.COM Service Name: evaultadmin Service ID: - Ticket Options: 0x40810000 Ticket Encryption Type: - Client Address: XXX.X.XXX.XX Failure Code: 0x1B Logon GUID: - Transited Services: -
Free Windows Admin Tool Kit Click here and download it now
July 22nd, 2010 10:09am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics