Had an issue where a server would not allow logon via termian services each time you attempted to logon it would return this:
Soooooooooo, what to do here?
First, we made sure the account existed in the directory since that’s why it appeared to be complaining. So I opened LDP and verified it existed, and that all "checked out" with being healthy (stare and compare against a good object).
Second thing we did was crank up netlogon debug logging (nltest dbflag) and see what it showed. It was complaining of a lot of stuff but nothing conclusive unfortunately. So at that point it was time to move to event viewer. The "nice" thing about this issue was that the server was accessible via the network with the same account that was failing to TS so I could do some of the investigation remotely.
One event in particular struck me:
Log Name: System
Date: 7/31/2008 4:11:24 PM
Event ID: 3
Task Category: None
A Kerberos Error Message was received:
on logon session
Server Time: 23:11:24.0000 7/31/2008 Z
Error Code: 0x7 KDC_ERR_S_PRINCIPAL_UNKNOWN
Extended Error: 0xc0000035 KLIN(0)
Server Realm: braddom.bradforest.COM
Server Name: host/BRAD-SRV-01.braddom.bradforest.com
Target Name: host/BRAD-SRVfirstname.lastname@example.org.COM
Error Data is in record data.
Using err.exe I resolved the error code and found there was a collision:
# for hex 0xc0000035 / decimal -1073741771 :
# Object Name already exists.
# 1 matches found for "0xc0000035"
At this point it’s time to look for a collision of "host/BRAD-SRV-01.braddom.bradforest.com" in the forest. The easiest way to do it is use a nice script called querySPN.vbs.
C:\localbin>querySPN.vbs HOST/BRAD-SRV-01.braddom.bradforest.com braddom.bradforest.com
Microsoft (R) Windows Script Host Version 5.7
Copyright (C) Microsoft Corporation. All rights reserved.
User Logon: VLSBST
— host/BRAD-SRV-01.braddom.bradforest.com <—————————————————————– Bingo the SPN is registered for two objects!
Computer DNS: BRAD-SRV-01.braddom.bradforest.com
— HOST/BRAD-SRV-01.braddom.bradforest.com <—————————————————————–
Once we removed the SPN from the user account, logons began to immediately work.