The kpasswd protocol fails with a KDC_ERR_S_PRINCIPAL_UNKNOWN error after you perform an authoritative restore on the krbtgt account in a Windows Server 2008 domain

Symptoms

You perform an authoritative restore on the krbtgt account in a Windows Server 2008 domain. After you do this, the kpasswd protocol fails with a KDC_ERR_S_PRINCIPAL_UNKNOWN error.

This prevents you from joining UNIX-based computers to your Windows Server 2008 domain. Additionally, this blocks kpasswd interoperability between the Windows Server 2008 domain and an MIT realm. For example, you cannot change passwords by using the kpasswd command.

Resolution

Hotfix information

Important Windows Vista and Windows Server 2008 hotfixes are included in the same packages. However, only one of these products may be listed on the “Hotfix Request” page. To request the hotfix package that applies to both Windows Vista and Windows Server 2008, just select the product that is listed on the page.

A supported hotfix is available from Microsoft. However, this hotfix is intended to correct only the problem that is described in this article. Apply this hotfix only to systems that are experiencing the problem described in this article. This hotfix might receive additional testing. Therefore, if you are not severely affected by this problem, we recommend that you wait for the next software update that contains this hotfix.

If the hotfix is available for download, there is a "Hotfix download available" section at the top of this Knowledge Base article. If this section does not appear, contact Microsoft Customer Service and Support to obtain the hotfix.

Note If additional issues occur or if any troubleshooting is required, you might have to create a separate service request. The usual support costs will apply to additional support questions and issues that do not qualify for this specific hotfix. For a complete list of Microsoft Customer Service and Support telephone numbers or to create a separate service request, visit the following Microsoft Web site:

http://support.microsoft.com/contactus/?ws=supportNote The "Hotfix download available" form displays the languages for which the hotfix is available. If you do not see your language, it is because a hotfix is not available for that language.

Prerequisites

No prerequisites are required for Windows Server 2008-based computers.

Restart requirement

You must restart the computer after you apply this hotfix.

Hotfix replacement information

This hotfix does not replace any other hotfixes.

File information

The Global version of this hotfix has the file attributes (or later file attributes) that are listed in the following table.

Windows Vista and Windows Server 2008 file information notes

  • The files that apply to a specific product, SR_Level (RTM, SPn), and service branch (LDR, GDR) can be identified by examining the file version numbers as shown in the following table.

    Version

    Product

    SR_Level

    Service branch

    6.0.6000.16xxx

    Windows Vista

    RTM

    GDR

    6.0.6000.20xxx

    Windows Vista

    RTM

    LDR

    6.0.6001.18xxx

    Windows Vista and Windows Server 2008

    SP1

    GDR

    6.0.6001.22xxx

    Windows Vista and Windows Server 2008

    SP1

    LDR

    6.0.6002.18xxx

    Windows Vista and Windows Server 2008

    SP2

    GDR

    6.0.6002.22xxx

    Windows Vista and Windows Server 2008

    SP2

    LDR

  • Service Pack 1 is integrated into the original release of Windows Server 2008.

  • The MANIFEST files (.manifest) and MUM files (.mum) installed for each environment are listed separately. MUM and MANIFEST files, and the associated security catalog (.cat) files, are critical to maintaining the state of the updated component. The security catalog files (attributes not listed) are signed with a Microsoft digital signature.

The Global version of this hotfix has the file attributes (or later file attributes) that are listed in the following table. The dates and times for these files are listed in Coordinated Universal Time (UTC). When you view the file information, it is converted to local time. To find the difference between UTC and local time, use the Time Zone tab in the Date and Time item in Control Panel.

For all supported x86-based versions of Windows Server 2008

File name

File version

File size

Date

Time

Platform

Kdcsvc.dll

6.0.6001.22424

311,296

01-May-2009

14:24

x86

Kdcsvc.mof

Not Applicable

5,300

01-Apr-2009

19:14

Not Applicable

Kdcsvc.dll

6.0.6002.22127

311,296

01-May-2009

14:19

x86

Kdcsvc.mof

Not Applicable

5,300

03-Apr-2009

21:47

Not Applicable

For all supported x64-based versions of Windows Server 2008

File name

File version

File size

Date

Time

Platform

Kdcsvc.dll

6.0.6001.22424

404,480

01-May-2009

14:47

x64

Kdcsvc.mof

Not Applicable

5,300

01-Apr-2009

16:43

Not Applicable

Kdcsvc.dll

6.0.6002.22127

404,480

01-May-2009

14:19

x64

Kdcsvc.mof

Not Applicable

5,300

03-Apr-2009

21:07

Not Applicable

Status

Microsoft has confirmed that this is a problem in the Microsoft products that are listed in the "Applies to" section.

More Information

For more information about software update terminology, click the following article number to view the article in the Microsoft Knowledge Base:

824684 Description of the standard terminology that is used to describe Microsoft software updates

Additional file information for Windows Server 2008

Additional files for all supported x86-based versions of Windows Server 2008

File name

File version

File size

Date

Time

Platform

Package_for_kb968140_sc_0~31bf3856ad364e35~x86~~6.0.1.0.mum

Not Applicable

1,430

04-May-2009

05:31

Not Applicable

Package_for_kb968140_sc_1~31bf3856ad364e35~x86~~6.0.1.0.mum

Not Applicable

1,527

04-May-2009

05:31

Not Applicable

Package_for_kb968140_sc~31bf3856ad364e35~x86~~6.0.1.0.mum

Not Applicable

1,701

04-May-2009

05:31

Not Applicable

Package_for_kb968140_server_0~31bf3856ad364e35~x86~~6.0.1.0.mum

Not Applicable

1,427

04-May-2009

05:31

Not Applicable

Package_for_kb968140_server_1~31bf3856ad364e35~x86~~6.0.1.0.mum

Not Applicable

1,531

04-May-2009

05:31

Not Applicable

Package_for_kb968140_server~31bf3856ad364e35~x86~~6.0.1.0.mum

Not Applicable

1,712

04-May-2009

05:31

Not Applicable

X86_microsoft-windows-k..distribution-center_31bf3856ad364e35_6.0.6001.22424_none_8c2fcc1dad6b1769.manifest

Not Applicable

42,276

01-May-2009

15:57

Not Applicable

X86_microsoft-windows-k..distribution-center_31bf3856ad364e35_6.0.6002.22127_none_8e193ee3aa8eb892.manifest

Not Applicable

42,276

01-May-2009

15:50

Not Applicable

Additional files for all supported x64-based versions of Windows Server 2008

File name

File version

File size

Date

Time

Platform

Amd64_microsoft-windows-k..distribution-center_31bf3856ad364e35_6.0.6001.22424_none_e84e67a165c8889f.manifest

Not Applicable

42,320

01-May-2009

16:42

Not Applicable

Amd64_microsoft-windows-k..distribution-center_31bf3856ad364e35_6.0.6002.22127_none_ea37da6762ec29c8.manifest

Not Applicable

42,320

01-May-2009

15:27

Not Applicable

Package_for_kb968140_sc_0~31bf3856ad364e35~amd64~~6.0.1.0.mum

Not Applicable

1,438

04-May-2009

05:31

Not Applicable

Package_for_kb968140_sc_1~31bf3856ad364e35~amd64~~6.0.1.0.mum

Not Applicable

1,537

04-May-2009

05:31

Not Applicable

Package_for_kb968140_sc~31bf3856ad364e35~amd64~~6.0.1.0.mum

Not Applicable

1,711

04-May-2009

05:31

Not Applicable

Package_for_kb968140_server_0~31bf3856ad364e35~amd64~~6.0.1.0.mum

Not Applicable

1,435

04-May-2009

05:31

Not Applicable

Package_for_kb968140_server_1~31bf3856ad364e35~amd64~~6.0.1.0.mum

Not Applicable

1,541

04-May-2009

05:31

Not Applicable

Package_for_kb968140_server~31bf3856ad364e35~amd64~~6.0.1.0.mum

Not Applicable

1,722

04-May-2009

05:31

Not Applicable

Need more help?

Expand your skills
Explore Training
Get new features first
Join Microsoft Insiders

Was this information helpful?

Thank you for your feedback!

Thank you for your feedback! It sounds like it might be helpful to connect you to one of our Office support agents.

×