I demoted a DC a few days ago and am now getting an error:
Active Directory failed to construct a mutual authentication service principal name (SPN) for the following domain controller.
Domain controller:
c709ad6b-5222-450e-ba36-7c69be4f7d3a._msdcs.chemspec.com
The call was denied. Communication with this domain controller might be affected.
Additional Data
Error value:
8589 The DS cannot derive a service principal name (SPN) with which to mutually authenticate the target server because the corresponding server object in the local DS database has no serverReference attribute.
The c709... DC is the one I demoted...Should I check DNS, ADSIEDIT or ntdsutil? thanks!
Active Directory failed to construct a mutual authentication service principal name (SPN) for the following domain controller.
Domain controller:
c709ad6b-5222-450e-ba36-7c69be4f7d3a._msdcs.chemspec.com
The call was denied. Communication with this domain controller might be affected.
Additional Data
Error value:
8589 The DS cannot derive a service principal name (SPN) with which to mutually authenticate the target server because the corresponding server object in the local DS database has no serverReference attribute.
The c709... DC is the one I demoted...Should I check DNS, ADSIEDIT or ntdsutil? thanks!