Error Occurred During Logon
Contents |
be down. Please try the request again. Your cache administrator is webmaster. Generated Wed, 12 Oct 2016 20:39:13 GMT by s_ac4 (squid/3.5.20)
platform and distributed applications Kerberos Authentication failed due to time skew ★★★★★★★★★★★★★★★ APGC DSI TeamApril 26, 20092 0 0 0 Here is a case we recently worked on about Kerberos authentication an error occurred during logon 4625 issue. Symptoms: Assume there is a web site which provides search functions under an error occurred during logon 0xc00006d exchange virtual directory with the Integrated Windows authentication. When clients use FQDN access the web site from out-of-domain, they have to an error occurred during logon 0xc00002ee click “OK” button three times on popup authentication windows to get the result grid back. Analysis: In IIS log, it records "401 1 2148074241" that indicates the handle specified is invalid. http://answers.microsoft.com/en-us/windows/forum/windows_vista-security/where-can-i-find-the-full-list-of-failure-reasons/d0269426-2183-4d99-8af0-cc009dee6658 2009-04-15 00:30:26 W3SVC1 10.101.nn.nn GET /Portal/dddd.aspx - 80 - 10.1.19.53 Mozilla/4.0+(compatible;+MSIE+6.0;+Windows+NT+5.1;+SV1;+InfoPath.1) 401 2 2148074254 In Security log, the system was receiving Event ID 537 log. Event Type: Failure Audit Event Source:Security Event Category: (2) Event ID: 537 Date: 4/15/2009 Time: 3:47:32 PM User: NT AUTHORITY\SYSTEM Computer: XXX Description: Logon Failure: Reason: An error occurred during logon User Name: Domain: Logon Type: 3 https://blogs.msdn.microsoft.com/asiatech/2009/04/26/kerberos-authentication-failed-due-to-time-skew/ Logon Process: Kerberos Authentication Package: Kerberos Workstation Name: - Status code: 0xC000006D Substatus code: 0xC0000133 Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 10.101.nn.nn Source Port: 1310 Caller Process Name: %16 Generally, status code 0xC000006D means "STATUS_LOGON_FAILURE” and sub status code 0xC0000133 translate to “STATUS_TIME_DIFFERENCE_AT_DC”. The problem could be caused because there is a time difference (greater than 5 minutes) between the two computers. In the network trace, we also can see HTTP KRB Error: KRB5KRB_AP_ERR_SKEW (text/html) The KRB5KRB_AP_ERR_SKEW indicates clock skew too great. Check the timestamp between client and server network traces to verify that there is 13 minutes difference. Solution: It is clear now that the time difference (>5 min) between client and server causes the Kerberos authentication issue. Change the client machine time to synchronize with IIS server and resolve the issue. Refer to this article: Verifying Computer Settings for Troubleshooting Kerberos http://technet.microsoft.com/en-us/library/cc787535.aspx -------------------------------------------- Make sure that the clocks are synchronized across the domain. Many network services, including Kerberos authentication are depe
name 537: Logon failure - The logon attempt failed for other reasons. On this page Description of this event Field level details Examples Discuss this event Mini-seminars on this event Thanks toIsaac at Prism Microsystems (EventTracker) for this https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=537 explanation: Event ID 537 is a generic logon failure that most of the time that I've seen it has a blank user name, to figure out what the true underlying cause of the logon failure you need to https://www.experts-exchange.com/questions/20967341/Getting-a-lot-of-Kerberos-error-messages-from-the-same-client-every-day.html look at the Status Code and Substatus Code in the description. The codes that I see most often when talking to customers is: Status code: 0xC000006D Substatus code: 0xC0000133 These 2 codes indicate that the workstation clock is error occurred more than 5 mins out of sync with the Domain Controller. I have put together a blog entry on how to analyze event 537. Here's a link to the status codes at MSDN Free Security Log Quick Reference Chart Description Fields in 537 User Name: Domain: Logon Type: Logon Process: Authentication Package: Workstation Name: The following fields are added in Windows Server 2003: Caller User Name: Caller Domain: Caller Logon ID: Caller Process ID: Transited Services: error occurred during Source Network Address: Source Port: Top 10 Windows Security Events to Monitor Examples of 537 Event Type: Failure Audit Event Source: Security Event ID:537 User:NT AUTHORITY\SYSTEM Computer: DC1 Description: Logon Failure: Reason: An error occurred during logon User Name: Domain: Logon Type: 3 Logon Process: Kerberos Authentication Package:Kerberos Workstation Name: - Status code: 0xC000006D Substatus code:0xC0000133 Caller User Name:- Caller Domain: - Caller Logon ID: - Caller Process ID:- Transited Services: - Source Network Address:192.168.1.144 Source Port: 0 Keep me up-to-date on the Windows Security Log. Email*: Bad email address *We will NOT share this Mini-Seminars Covering Event ID 537 Top 6 Security Events You Only Detect by Monitoring Workstation Security Logs Discussions on Event ID 537 • Event : 537 - Blank user name Upcoming Webinars How to Detect SQL Server Hacking without Crippling Performance or Impacting Availability Understanding Office 365 Unified Audit Logging 14 Group Policy Security Risks and How to Control them Additional Resources Security Log Quick Reference ChartThe Leftovers: A Data Recovery Study Encyclopedia •All Event IDs•Audit Policy Go To Event ID: Must be a 2-5 digit number No such event ID Security Log Quick Reference Chart Download now! Tweet Home > Security Log > Encyclopedia > Event ID 537 User name: Password: / Forgot? Register October 2016 Patch Tuesday "Patch Tuesday: New Patching Process and 0 days " - sponsored by Shavlik
for Help Receive Real-Time Help Create a Freelance Project Hire for a Full Time Job Ways to Get Help Ask a Question Ask for Help Receive Real-Time Help Create a Freelance Project Hire for a Full Time Job Ways to Get Help Expand Search Submit Close Search Login Join Today Products BackProducts Gigs Live Careers Vendor Services Groups Website Testing Store Headlines Experts Exchange > Questions > Getting a lot of Kerberos error messages from the same client every day!!! Want to Advertise Here? Solved Getting a lot of Kerberos error messages from the same client every day!!! Posted on 2004-04-26 Windows Server 2003 1 Verified Solution 4 Comments 16,179 Views Last Modified: 2011-08-18 Hi, heres the log files from the security-log. Event Type: Failure Audit Event Source: Security Event Category: Logon/Logoff Event ID: 537 Date: 26-04-2004 Time: 09:45:22 User: NT AUTHORITY\SYSTEM Computer: STOHNSERVER Description: Logon Failure: Reason: An error occurred during logon User Name: Domain: Logon Type: 3 Logon Process: Kerberos Authentication Package: Kerberos Workstation Name: - Status code: 0xC000006D Substatus code: 0xC0000133 Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.0.21 Source Port: 0 For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp. ---------------------------------------------------------------------- Event Type: Failure Audit Event Source: Security Event Category: Logon/Logoff Event ID: 537 Date: 26-04-2004 Time: 09:45:21 User: NT AUTHORITY\SYSTEM Computer: STOHNSERVER Description: Logon Failure: Reason: An error occurred during logon User Name: Domain: Logon Type: 3 Logon Process: Kerberos Authentication Package: Kerberos Workstation Name: - Status code: 0xC000006D Substatus code: 0xC0000133 Caller User Name: - Caller Domain: - Caller Logon ID: - Caller Process ID: - Transited Services: - Source Network Address: 192.168.0.21 Source Port: 1212 For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp. ------------------------------------------------------------ Event Type: Failure Audit Event Source: Security Event Category: Logon/Logoff Event ID: 537 Date: 26-04-2004 Time: 09:45: