The Kerbtray tool is included in the Windows Server 2003 Resource Kit Tools package. Data: 0000: 6d 00 00 c0 m..À ----------------------------------------------------------------------------------------------------------------------------- Event Type: Warning Event Source: LSASRV Event Category: SPNEGO (Negotiator) Event ID: 40961 Date: 6/26/2006 Time: 8:13:15 AM User: N/A Computer: PREPSERVER3 Description: This is either due to a bad username or authentication information. (0xc000006d)" - See ME938702. - Error: "The name or SID of the domain specified is inconsistent with the trust information I don't think this is the issue here since there are lots of exchange servers that are not having issues. @Ace.

x 13 Patrick I have had the issue where at random intervals one computer user would have their account locked out, with event ID 40961. It turned out that the Password Manager on that that user profile on that computer had an old record for that server.

I had this fixed as follows: 1. The user placeholder in the /UserO:user parameter represents the user account that connects to the trusting domain.

There are no known mail flow issues. It couldn't connect to the SQL database since the account was locked. The Security System Detected An Authentication Error For The Server Cifs/servername This is either due to a bad username or authentication information. (0xc000006d)".

This is either due to a bad username or authentication information. (0xc000006d)". Lsasrv 40960 Automatically Locked The domain admin password was changed recently so i THINK it has something to do with this, if that's the cause then i can't figure out what app or service on If the server is not but the local DNS server then it is possible that one of the services that is registering DNS records is running with an invalid account. The fix was changing the DNS settings to point to a Win2k DNS which was tied into Active Directory.

After the restart the same problem remained. Event Id 40960 Buffer Too Small This inability to authenticate might be caused by another computer on the same network using the same name or the password for this computer account is not recognized. Here is the solution! We are going to wait until the next scheduled reboot and see if it goes away as it doesnt appear to be affecting exchange in anyway.

This article guides you through accessing and editing a registry of a non-primary drive. Besides the suggestions already provided, take a look at these, that is ifyou haven't already looked at them: EventID 4 Microsoft - Event ID 4 — Kerberos Client Configuration To resolve this issue create the proper reverse lookup zones for the private IP subnets used on your network.

In the eventlog on my remote pc's, I found the following events: Event ID: 40960 Source: LsaSrv Type: Warning Category: SPNEGO (Negotiator) Description: The Security System detected an attempted downgrade attack I would check your AD for expired accounts. Data: 0000: 22 00 00 c0 "..À ----------------------------------------------------------------------------------------------------------------------------- Event Type: Warning Event Source: LSASRV Event Category: SPNEGO (Negotiator) Event ID: 40960 Date: 6/26/2006 Time: 9:13:24 AM User: N/A Computer: PREPSERVER3 Description:

This is either due to a bad username or authentication information. (0xc000006d)". Simple solution was to finally install SP4 for Win2k on the domain controllers which we hadn't done before.

The workstations could initially be connected to the Windows Small Business Server 2003 domain, but after a reboot, the domain was not accessible (logon, network drive mapping, etc.). x 9 K-Man I experienced this problem on Windows XP workstations, when users logged into a terminal server and terminal sessions were disconnected (but not terminated). There were also issues with communication with Kerberos, SPN ( even SPN was set correctly in schema ) recprds, and NLTEST was always unsuccessful.

Thanks, Ryan .

Relateddirectly to Event 40961 - LsaSrv x 9 Anonymous In our case, one of our customer reports that they are periodically seeing slow logon times, (defined as the time between entering This fixed the problem for me. The domain controllers could ping each other, connect to network shares, but could not get objects from AD. The Security System Detected An Authentication Error For The Server Dns Are these systems using DHCP?

And see if the error goes way. After several tries, I was able to figure it the cause for this out by enabling failure auditing on all Domain Controllers (Domain Controller Security - Security Settings - Local Policies This solved our issue.

TECHNOLOGY IN THIS DISCUSSION Microsoft Windows Server 2003 Microsoft Windows Server Join the Community! Group Policy processing aborted. I am still receiving the same error.