Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations John Tel on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Kerberos pre-authentication for 'computer' account

Status
Not open for further replies.

tony72000

IS-IT--Management
May 5, 2002
137
GB
Does any one know how to turn off Kerberos pre-authentication for computer account?

I have a UNIX file server that's given me pre-authentication failures in the event log. I know I can safely ignore these errors; I just want to keep the size of the event log to a minimum.

Thanks.
 
I am guessing this Unix computer is participating in your AD environment? If that's the case it relies on a Kerberos domain being available thus the error messages. I don't know if you can suppress them or not, unless the server stops participating in AD
 
It is participating in our AD environment. User accounts have this option, but computer accounts do not.

Will I have to ignore failure audits?
 
What is the Eventlog ID that is generated for these events?
 
This is the event that is logged:

Event Type: Failure Audit
Event Source: Security
Event Category: Account Logon
Event ID: 675
Date: 02/03/2007
Time: 16:23:40
User: NT AUTHORITY\SYSTEM
Computer: SERVERNAME
Description:
Pre-authentication failed:
User Name: FILESERVERNAME$
User ID: DOMAIN\FILESERVERNAME$
Service Name: krbtgt/DOMAIN.COM
Pre-Authentication Type: 0x0
Failure Code: 0x19
Client Address: ***.***.**.***


For more information, see Help and Support Center at
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top