16,755 pts.
 Windows Server 2003 domain controller Event ID 675
I have a windows server 2003 domain controller and have been seeing alot of "Failure Audit" entries in the Security log. ID 675 "Pre-authentication failed:" Failure Code: 0x19 any suggested fixes

Software/Hardware used:
ASKED: January 20, 2009  2:41 PM
UPDATED: January 20, 2009  5:49 PM

Answer Wiki:
This event does not necessary means that you need to fix something. From <a href="http://support.microsoft.com/kb/230476/en-us">Microsoft Support</a>: Event id 675 with a failure code of “0x19” ( KDC_ERR_PREAUTH_REQUIRED): “The client did not send pre-authorization, or did not send the appropriate type of pre-authorization, to receive a ticket. The client will retry with the appropriate kind of pre-authorization (the KDC returns the pre-authentication type in the error). Many Kerberos implementations will start off without preauthenticated data and only add it in a subsequent request when it sees this error. In this case, this error can safely be ignored.” Some linux implementations of Kerberos work this way, so if the client machine is running linux, that could be the explanation. See the event details (User Id and Client Address) in order to identify the user/machine that is causing these events. If you confirm that no action is required and you do not want these events to keep coming, you could enable the “Do not require Kerberos preauthentication” option for that user account in Active directory users & computers -> <user> properties -> account” (but this will lower the security level for that account). You could also try removing the computer account from AD, and then creating a new one.
Last Wiki Answer Submitted:  January 20, 2009  5:49 pm  by  carlosdl   63,535 pts.
All Answer Wiki Contributors:  carlosdl   63,535 pts.
To see all answers submitted to the Answer Wiki: View Answer History.


Discuss This Question:
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _