Click here to get back home

KDC service hangs on start + cert error in event log at every boot

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
KDC service hangs on start + cert error in event log at every boot Lucvdv 03-30-2007
Posted by Lucvdv on March 30, 2007, 2:58 am
Please log in for more thread options
After upgrading a Win2000 server (PDC) to Server 2003 R2, I get the old 'at
least one service or driver failed to start' popup on the logon screen at
every boot.

There are two messages in the event log that look related, an error and a
warning:

error
SCM event 7022,
"The Kerberos Key Distribution service hung on starting"

warning
KDC event 20,
"The currently selected KDC certificate was once valid, but now is
invalid and no replacement was found"


I ran 'netdiag /test:kerberos /v' and 'certutil -DCInfo', neither reports
an error.

I started MMC with the certificates plugin, and looked up the KDC
certificate by the serial number that certutil reported: it is OK and still
valid until February 2009, but after a new reboot the warning and the hang
at startup both just came back.


Does anyone have an idea what might cause this?

Posted by Lucvdv on March 30, 2007, 4:50 am
Please log in for more thread options
It's getting worse with every reboot (other errors start occurring), so I
guess I shouldn't have posted this to the security group. Crossposted now
and followups set to .general in an attempt to move the thread.

A small mistake in the original post: the problem didn't start after
upgrading to Server 2003 - it started after installing SP2.
The upgrade was a few days earlier, and everything looked fine then.


Now I'm wondering if it's a hardware problem (doesn't look like it - the
RAID controller the harddisks seem OK, and chkdsk finds no errors), or if
SP2 inflicted it on me.

More below the quote.



> After upgrading a Win2000 server (PDC) to Server 2003 R2, I get the old 'at
> least one service or driver failed to start' popup on the logon screen at
> every boot.
>
> There are two messages in the event log that look related, an error and a
> warning:
>
> error
> SCM event 7022,
> "The Kerberos Key Distribution service hung on starting"
>
> warning
> KDC event 20,
> "The currently selected KDC certificate was once valid, but now is
> invalid and no replacement was found"
>
>
> I ran 'netdiag /test:kerberos /v' and 'certutil -DCInfo', neither reports
> an error.
>
> I started MMC with the certificates plugin, and looked up the KDC
> certificate by the serial number that certutil reported: it is OK and still
> valid until February 2009, but after a new reboot the warning and the hang
> at startup both just came back.
>
>
> Does anyone have an idea what might cause this?



I changed the KDC service to manual start and rebooted, just to see what it
would give.

The service didn't start anymore, but
- the 'preparing network connections' boot phase took minutes to complete
- now the DNS server service hung on starting (which it didn't do before)??


Changed KDC back to auto-start, and changed the service startup timeout to
60 seconds.

Result: KDC no longer hangs (so 60 seconds seems to be enough).

But now I got a message saying the system just rebooted from an 'unexpected
shutdown' (which isn't true, it was a normal reboot), there are a ton of
error messages from DNS and DHCP services because they can't find the AD
anymore, and directory services in turn have an error saying connecting to
the global catalog failed because of an internal error.


I think it's reinstall/restore time - thank it's only a test setup.

Posted by Roger Abell [MVP] on March 30, 2007, 9:27 am
Please log in for more thread options
Lucvdv,

I am x-posting to the active_directory newsgroup which would
likely be a better choice than the general group you have added.

Roger

> It's getting worse with every reboot (other errors start occurring), so I
> guess I shouldn't have posted this to the security group. Crossposted now
> and followups set to .general in an attempt to move the thread.
>
> A small mistake in the original post: the problem didn't start after
> upgrading to Server 2003 - it started after installing SP2.
> The upgrade was a few days earlier, and everything looked fine then.
>
>
> Now I'm wondering if it's a hardware problem (doesn't look like it - the
> RAID controller the harddisks seem OK, and chkdsk finds no errors), or if
> SP2 inflicted it on me.
>
> More below the quote.
>
>
>
>> After upgrading a Win2000 server (PDC) to Server 2003 R2, I get the old
>> 'at
>> least one service or driver failed to start' popup on the logon screen at
>> every boot.
>>
>> There are two messages in the event log that look related, an error and a
>> warning:
>>
>> error
>> SCM event 7022,
>> "The Kerberos Key Distribution service hung on starting"
>>
>> warning
>> KDC event 20,
>> "The currently selected KDC certificate was once valid, but now is
>> invalid and no replacement was found"
>>
>>
>> I ran 'netdiag /test:kerberos /v' and 'certutil -DCInfo', neither reports
>> an error.
>>
>> I started MMC with the certificates plugin, and looked up the KDC
>> certificate by the serial number that certutil reported: it is OK and
>> still
>> valid until February 2009, but after a new reboot the warning and the
>> hang
>> at startup both just came back.
>>
>>
>> Does anyone have an idea what might cause this?
>
>
>
> I changed the KDC service to manual start and rebooted, just to see what
> it
> would give.
>
> The service didn't start anymore, but
> - the 'preparing network connections' boot phase took minutes to complete
> - now the DNS server service hung on starting (which it didn't do
> before)??
>
>
> Changed KDC back to auto-start, and changed the service startup timeout to
> 60 seconds.
>
> Result: KDC no longer hangs (so 60 seconds seems to be enough).
>
> But now I got a message saying the system just rebooted from an
> 'unexpected
> shutdown' (which isn't true, it was a normal reboot), there are a ton of
> error messages from DNS and DHCP services because they can't find the AD
> anymore, and directory services in turn have an error saying connecting to
> the global catalog failed because of an internal error.
>
>
> I think it's reinstall/restore time - thank it's only a test
> setup.



Similar ThreadsPosted
2K3 Cert Svcs gives invalid policy error on OpenSSL gen'd cert req June 4, 2007, 1:56 pm
cert submitt error July 18, 2005, 9:56 am
Error issuing certificates from WS03 cert svc April 17, 2007, 4:53 pm
Could not start the Windows Time Error 1300 June 22, 2005, 10:03 am
Boot Volume NTFS Permissions for Network Service July 3, 2006, 10:45 pm
server certificate from cert service August 22, 2006, 2:41 pm
Event ID: 40960 SPNEGO (Negotiator) authentication error April 7, 2006, 3:22 am
The privilege to start a Windows service June 13, 2006, 6:37 am
allow start/stop a specific service through GPO November 14, 2006, 8:37 am
set service start permissions to Administrator only August 17, 2007, 6:13 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap