Article ID: 939088 - Last Review: July 26, 2007 - Revision: 1.1 You receive a Key Distribution Center "Event ID: 20" event message on a Windows Server 2003-based domain controller
SYMPTOMSConsider the following scenario. You are using a Microsoft Windows Server 2003-based domain controller. The domain controller is part of a domain that does not have a certification authority (CA) installed. You receive the following event message in the Event Viewer System log: Event Type: Warning CAUSEThis issue may occur because of invalid domain controller certificates. Domain controller certificates may become invalid if you remove a CA that was installed in the domain. After you remove the CA, the domain controller still tries to contact the CA. Therefore, you receive the error message that is mentioned in the "Symptoms" section. RESOLUTIONTo resolve this issue, remove all the invalid domain controller certificates, as follows:
MORE INFORMATION
For more information about related issues, click the following article numbers to view the articles in the Microsoft Knowledge Base:
887578
(http://support.microsoft.com/kb/887578/
)
You receive a "Logon failure" message when you use a smart card on a Windows Server 2003-based computer
892090
(http://support.microsoft.com/kb/892090/
)
Group Policy settings are not applied when a user in an external Kerberos realm logs on to a Windows XP Professional-based or to a Windows 2000 Professional-based computer in a child domain
929272
(http://support.microsoft.com/kb/929272/
)
Interactive logon styles and Key Distribution Center account lookup in Windows Server 2003
| Other Resources Other Support Sites
CommunityGet Help NowArticle Translations
|






Windows Live
Facebook
Twitter
Linkedin
Digg it
Yahoo
Delicious
StumbleUpon
Yammer
Reddit
Technorati
FriendFeed
Email
Back to the top
