Home

Having problems with KRB_AP_ERR_MODIFIED error

%3CLINGO-SUB%20id%3D%22lingo-sub-212476%22%20slang%3D%22en-US%22%3EHaving%20problems%20with%20KRB_AP_ERR_MODIFIED%20error%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-212476%22%20slang%3D%22en-US%22%3E%3CP%3EMy%20domain%2Fservers%20have%20been%20running%20OK%20for%20awhile%20(years%20that%20is)%2C%20but%20recently%20servers%20started%20refusing%20logins%20with%20%22Password%20incorrect%22.%20And%20only%20way%20to%20fix%20that%20was%20server%20reboot.%20Then%20some%20servers%20would%20be%20OK%20for%20weeks%20before%20that%20happened%20again.%20Some%20would%20need%20restart%20every%20other%20day.%20No%2C%20pattern%20whatsoever!%20Then%20I%20logged%20in%20locally%20and%20found%20KRB_AP_ERR_MODIFIED%20error.%20Yes%2C%20there%20are%20many%20articles%20on%20how%20to%20fix%20that%2C%20but%20all%20of%20them%20go%20about%20different%20SPNs%20like%20HOST%2F%20or%20MSSQLSrv%2F%2C%20duplicate%20accounts%20present%20etc%20etc.%20I%20do%20not%20see%20any%20of%20that%20in%20event%20log.%20I%20have%20same%20server%20name%2C%20same%20domain.%20Only%20difference%20is%20server%20name%20is%20lowercase%2C%20target%20name%20uppercase.%20Any%20ideas%3F%3C%2FP%3E%3CP%3EThe%20Kerberos%20client%20received%20a%20KRB_AP_ERR_MODIFIED%20error%20from%20the%20server%3CSTRONG%3Ed365bi01%3C%2FSTRONG%3E%24.%20The%20target%20name%20used%20was%20%3CSTRONG%3ED365BI01%3C%2FSTRONG%3E%24.%20This%20indicates%20that%20the%20target%20server%20failed%20to%20decrypt%20the%20ticket%20provided%20by%20the%20client.%20This%20can%20occur%20when%20the%20target%20server%20principal%20name%20(SPN)%20is%20registered%20on%20an%20account%20other%20than%20the%20account%20the%20target%20service%20is%20using.%20Ensure%20that%20the%20target%20SPN%20is%20only%20registered%20on%20the%20account%20used%20by%20the%20server.%20This%20error%20can%20also%20happen%20if%20the%20target%20service%20account%20password%20is%20different%20than%20what%20is%20configured%20on%20the%20Kerberos%20Key%20Distribution%20Center%20for%20that%20target%20service.%20Ensure%20that%20the%20service%20on%20the%20server%20and%20the%20KDC%20are%20both%20configured%20to%20use%20the%20same%20password.%20If%20the%20server%20name%20is%20not%20fully%20qualified%2C%20and%20the%20target%20domain%20(%3CSTRONG%3EDOMAIN.COM%3C%2FSTRONG%3E)%20is%20different%20from%20the%20client%20domain%20(%3CSTRONG%3EDOMAIN.COM%3C%2FSTRONG%3E)%2C%20check%20if%20there%20are%20identically%20named%20server%20accounts%20in%20these%20two%20domains%2C%20or%20use%20the%20fully-qualified%20name%20to%20identify%20the%20server.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-267441%22%20slang%3D%22en-US%22%3ERe%3A%20Having%20problems%20with%20KRB_AP_ERR_MODIFIED%20error%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-267441%22%20slang%3D%22en-US%22%3E%3CP%3E(excerpt)%3C%2FP%3E%0A%3CP%3E%3CEM%3EService%20Principal%20Names%20(SPNs)%20are%20not%20case%20sensitive%20when%20used%20by%20Microsoft%20Windows-based%20computers.%20However%2C%20an%20SPN%20can%20be%20used%20by%20any%20type%20of%20computer%20system.%20Many%20of%20these%20computer%20systems%2C%20especially%20UNIX-based%20systems%2C%20are%20case-sensitive%20and%20require%20the%20proper%20case%20to%20function%20properly.%20Care%20should%20be%20taken%20to%20use%20the%20proper%20case%20particularly%20when%20an%20SPN%20can%20be%20used%20by%20a%20non-Windows-based%20computer.%3C%2FEM%3E%3C%2FP%3E%0A%3CP%3EThis%20one%20might%20help.%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fprevious-versions%2Fwindows%2Fit-pro%2Fwindows-server-2008-R2-and-2008%2Fcc731241(v%3Dws.10)%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fprevious-versions%2Fwindows%2Fit-pro%2Fwindows-server-2008-R2-and-2008%2Fcc731241(v%3Dws.10)%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%3CEM%3E%26nbsp%3B%3C%2FEM%3E%3C%2FP%3E%0A%3CP%3E%3CEM%3E%26nbsp%3B%3C%2FEM%3E%3C%2FP%3E%0A%3CP%3E%3CEM%3E%26nbsp%3B%3C%2FEM%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Raimonds Martinovs
Occasional Visitor

My domain/servers have been running OK for awhile (years that is), but recently servers started refusing logins with "Password incorrect". And only way to fix that was server reboot. Then some servers would be OK for weeks before that happened again. Some would need restart every other day. No, pattern whatsoever! Then I logged in locally and found KRB_AP_ERR_MODIFIED error. Yes, there are many articles on how to fix that, but all of them go about different SPNs like HOST/ or MSSQLSrv/, duplicate accounts present etc etc. I do not see any of that in event log. I have same server name, same domain. Only difference is server name is lowercase, target name uppercase. Any ideas?

The Kerberos client received a KRB_AP_ERR_MODIFIED error from the server d365bi01$. The target name used was D365BI01$. This indicates that the target server failed to decrypt the ticket provided by the client. This can occur when the target server principal name (SPN) is registered on an account other than the account the target service is using. Ensure that the target SPN is only registered on the account used by the server. This error can also happen if the target service account password is different than what is configured on the Kerberos Key Distribution Center for that target service. Ensure that the service on the server and the KDC are both configured to use the same password. If the server name is not fully qualified, and the target domain (DOMAIN.COM) is different from the client domain (DOMAIN.COM), check if there are identically named server accounts in these two domains, or use the fully-qualified name to identify the server.

1 Reply

(excerpt)

Service Principal Names (SPNs) are not case sensitive when used by Microsoft Windows-based computers. However, an SPN can be used by any type of computer system. Many of these computer systems, especially UNIX-based systems, are case-sensitive and require the proper case to function properly. Care should be taken to use the proper case particularly when an SPN can be used by a non-Windows-based computer.

This one might help.

https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc...

 

 

 

 

Related Conversations
Extentions Synchronization
ChirmyRam in Discussions on
3 Replies
Tabs and Dark Mode
cjc2112 in Discussions on
35 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies
Security Community Webinars
Valon_Kolica in Security, Privacy & Compliance on
9 Replies