{"id":519,"date":"2022-09-07T11:05:55","date_gmt":"2022-09-07T18:05:55","guid":{"rendered":"https:\/\/blog.iabsolute.com\/?p=519"},"modified":"2022-09-07T11:05:55","modified_gmt":"2022-09-07T18:05:55","slug":"event-id-29","status":"publish","type":"post","link":"https:\/\/blog.iabsolute.com\/?p=519","title":{"rendered":"Event ID &#8211; 29"},"content":{"rendered":"\n<p><strong>According to Microsoft :<\/strong><br><strong>Cause<\/strong><br>This event is logged when the Key Distribution Center (KDC) cannot find a suitable certificate to use for smart card logons, or the KDC certificate could not be verified.<br><strong>Resolution<\/strong><br><strong>Request a new domain controller certificate<\/strong><br>Kerberos uses a domain controller certificate to ensure that the authentication information sent over the network is encrypted. If the certificate is missing or is no longer valid, you must delete the domain controller certificate and then request a new one.<br>To resolve this issue:<br>Delete the domain controller certificate that is no longer valid.<br>Request a new certificate.<br>To perform these procedures, you must be a member of the Domain Admins group, or you must have been delegated the appropriate authority.<br><strong>Delete the domain controller certificate that is no longer valid<\/strong><br>To delete the domain controller certificate that is no longer valid:<br>1.On the domain controller in which the issue is occurring, click\u00a0<strong>Start<\/strong>, and then click\u00a0<strong>Run<\/strong>.<br>2.Type\u00a0<strong>mmc.exe<\/strong>, and then press ENTER.<br>3.If the\u00a0<strong>User Account Control<\/strong>\u00a0dialog box appears, confirm that the action it displays is what you want, and then click\u00a0<strong>Continue<\/strong>.<br>4.Click\u00a0<strong>File<\/strong>, and then click\u00a0<strong>Add\/Remove Snap-in<\/strong>.<br>5.Click\u00a0<strong>Certificates<\/strong>, and then click\u00a0<strong>Add<\/strong>.<br>6.Click\u00a0<strong>Computer account<\/strong>, click\u00a0<strong>Next<\/strong>, and then click\u00a0<strong>Finish<\/strong>.<br>7.Click\u00a0<strong>OK<\/strong>\u00a0to open the Certificates snap-in.<br>8.Expand\u00a0<strong>Certificates (Local computer)<\/strong>, expand\u00a0<strong>Personal<\/strong>, and then click\u00a0<strong>Certificates<\/strong>.<br>9.Right-click the old domain controller certificate, and then click\u00a0<strong>Delete<\/strong>.<br>10.Click\u00a0<strong>Yes<\/strong>, confirming that you want to delete the certificate.<br>11.After the certificate is deleted, follow the procedure in the &#8220;Request a new certificate&#8221; section.<br><strong>Request a new certificate<\/strong><br>To request a new certificate:<br>1.Expand\u00a0<strong>Certificates (Local computer)<\/strong>, right-click\u00a0<strong>Personal<\/strong>, and then click\u00a0<strong>Request New Certificate<\/strong>.<br>2.Complete the appropriate information in the Certificate Enrollment Wizard for a domain controller certificate.<br>3.Close the Certificates snap-in.<br><strong>Verify<\/strong><br>To perform this procedure, you must be a member of the\u00a0<strong>Domain Admins<\/strong>\u00a0group, or you must have been delegated the appropriate authority.<br>To verify that the Kerberos Key Distribution Center (KDC) certificate is available and working properly:<br>1.Log on to a computer within your domain.<br>2.Click\u00a0<strong>Start<\/strong>, point to\u00a0<strong>All Programs<\/strong>, click\u00a0<strong>Accessories<\/strong>, right-click\u00a0<strong>Command Prompt<\/strong>, and then click\u00a0<strong>Run as administrator<\/strong>.<br>3.If the\u00a0<strong>User Account Control<\/strong>\u00a0dialog box appears, confirm that the action it displays is what you want, and then click\u00a0<strong>Continue<\/strong>.<br>4.At the command prompt, type\u00a0<strong>certutil -dcinfo verify<\/strong>, and then press ENTER.<br>5.If you receive a successful verification, the Kerberos KDC certificate is installed and operating correctly.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>According to Microsoft :CauseThis event is logged when the Key Distribution Center (KDC) cannot find a suitable certificate to use for smart card logons, or the KDC certificate could not be verified.ResolutionRequest a new domain controller certificateKerberos uses a domain &hellip; <a href=\"https:\/\/blog.iabsolute.com\/?p=519\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[],"class_list":["post-519","post","type-post","status-publish","format-standard","hentry","category-windows"],"_links":{"self":[{"href":"https:\/\/blog.iabsolute.com\/index.php?rest_route=\/wp\/v2\/posts\/519","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.iabsolute.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.iabsolute.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.iabsolute.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.iabsolute.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=519"}],"version-history":[{"count":1,"href":"https:\/\/blog.iabsolute.com\/index.php?rest_route=\/wp\/v2\/posts\/519\/revisions"}],"predecessor-version":[{"id":520,"href":"https:\/\/blog.iabsolute.com\/index.php?rest_route=\/wp\/v2\/posts\/519\/revisions\/520"}],"wp:attachment":[{"href":"https:\/\/blog.iabsolute.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=519"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.iabsolute.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=519"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.iabsolute.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=519"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}