#Requires -Version 5.1 <# JbTecWiz Support Centre -- generated fix script Fault : Kerberos failures -- clock skew, SPN duplicates and KDC errors Fix : Fix the time hierarchy, not just the clock Source: https://jbtecwiz.com/support/srv-id-kerberos-skew Run as : Elevated PowerShell Expect : 40 minutes Risk : medium Reversible : yes WHEN THIS IS THE RIGHT FIX Clock skew errors. HOW TO UNDO IT w32tm /config /syncfromflags:domhier restores the default behaviour on a member. This script walks the fix one step at a time and asks before each one. Steps with no command are things you do yourself -- it prints those and waits. Run with -DryRun to print without executing. -------------------------------------------------------------------- NO WARRANTY - USE AT YOUR OWN RISK This script is provided by JbTecWiz as-is and with no warranty of any kind, express or implied. You run it entirely at your own risk. JbTecWiz accepts no liability for any loss or damage arising from its use, including but not limited to data loss, downtime, or configuration changes that turn out to be wrong for your system. You are responsible for reading this script before running it, for satisfying yourself that it suits the machine in front of you, and for having a working backup first. Some steps cannot be undone. -------------------------------------------------------------------- #> [CmdletBinding()] param( # Print every step and command without running anything. [switch]$DryRun, # Do not ask before each step. Read the script first if you use this. [switch]$Unattended ) $ErrorActionPreference = 'Stop' $script:Failed = 0 function Write-Rule { param([string]$Text) Write-Host '' Write-Host ('-' * 70) -ForegroundColor DarkGray if ($Text) { Write-Host $Text -ForegroundColor Cyan } } function Show-Prose { param([string]$Text, [string]$Colour = "Gray") if (-not $Text) { return } $words = $Text -split "\s+"; $line = " " foreach ($w in $words) { if (($line.Length + $w.Length) -gt 74) { Write-Host $line -ForegroundColor $Colour; $line = " " } $line += "$w " } if ($line.Trim()) { Write-Host $line -ForegroundColor $Colour } } function Invoke-Step { param( [int]$Number, [string]$Do, [string]$Why, [scriptblock]$Command, [switch]$Manual, [string]$Shell = "powershell" ) Write-Rule " Step $Number of 5" Show-Prose $Do "White" if ($Why) { Write-Host ""; Show-Prose $Why "DarkGray" } if ($Manual) { Write-Host '' Write-Host ' -> Do this yourself, then press Enter to carry on.' -ForegroundColor Yellow if (-not $Unattended -and -not $DryRun) { [void](Read-Host) } return } Write-Host '' foreach ($l in ($Command.ToString().Trim() -split "`n")) { Write-Host (" " + $l.Trim()) -ForegroundColor Green } Write-Host '' if ($DryRun) { Write-Host " (dry run -- not executed)" -ForegroundColor DarkGray; return } if (-not $Unattended) { $a = Read-Host " Run this step? [Y]es / [S]kip / [Q]uit" if ($a -match "^[Qq]") { Write-Host " Stopped at your request."; exit 0 } if ($a -match "^[Ss]") { Write-Host " Skipped." -ForegroundColor DarkGray; return } } try { & $Command } catch { $script:Failed++ Write-Host (" Step $Number failed: " + $_.Exception.Message) -ForegroundColor Red Show-Prose "The rest of the fix may depend on this. Read the write-up before carrying on." "Red" if (-not $Unattended) { $c = Read-Host " Carry on anyway? [y/N]" if ($c -notmatch "^[Yy]") { exit 1 } } } } Write-Rule Write-Host ' Kerberos failures -- clock skew, SPN duplicates and KDC errors' -ForegroundColor White Write-Host ' Fix the time hierarchy, not just the clock' -ForegroundColor Cyan Write-Host '' Write-Host ' Risk: medium Reversible 40 minutes' Write-Host '' Show-Prose 'No warranty. Use at your own risk - JbTecWiz accepts no liability. Read it before you run it, and have a backup.' 'DarkYellow' Write-Rule if (-not $Unattended -and -not $DryRun) { $go = Read-Host ' Ready? [y/N]' if ($go -notmatch "^[Yy]") { Write-Host " Nothing was changed."; exit 0 } } Invoke-Step -Number 1 -Do 'Check the skew from a client against the domain controller.' -Command { w32tm /stripchart /computer:dc01.example.local /samples:5 /dataonly } Invoke-Step -Number 2 -Do 'Check the PDC emulator''s configuration -- the whole domain follows it and it is the only machine that should look outside.' -Why 'The domain time hierarchy is PDC emulator to an external source, every other controller to the PDC, every member to a controller. One machine configured differently -- usually a controller pointed at time.windows.com -- puts the whole domain into a disagreement it cannot resolve.' -Command { netdom query fsmo w32tm /query /configuration w32tm /query /status } Invoke-Step -Number 3 -Do 'Set the PDC emulator to a reliable external source.' -Command { w32tm /config /manualpeerlist:"time.nist.gov,0x8 ntp2.npl.co.uk,0x8" /syncfromflags:manual /reliable:yes /update Restart-Service w32time w32tm /resync /rediscover } Invoke-Step -Number 4 -Do 'Set every other machine to follow the domain hierarchy.' -Command { w32tm /config /syncfromflags:domhier /update Restart-Service w32time w32tm /resync } Invoke-Step -Number 5 -Do 'On a virtualised controller, disable host time synchronisation -- the host and the domain hierarchy both correcting the clock is a common cause of persistent skew.' -Command { Get-VMIntegrationService -VMName DC01 -Name 'Time Synchronization' | Format-List VMName,Name,Enabled } Write-Rule " Confirm it worked" Show-Prose 'Every machine reports a source consistent with the hierarchy and a small offset.' 'White' Write-Host '' if (-not $DryRun) { w32tm /query /status | Select-String 'Source|Last Successful' w32tm /monitor } Write-Rule if ($script:Failed -gt 0) { Write-Host (" Finished with " + $script:Failed + " failed step(s).") -ForegroundColor Yellow Show-Prose 'Read the full write-up at https://jbtecwiz.com/support/srv-id-kerberos-skew' 'Yellow' } else { Write-Host ' Finished.' -ForegroundColor Green } Write-Host '' Show-Prose 'To undo: w32tm /config /syncfromflags:domhier restores the default behaviour on a member.' 'DarkGray' Write-Rule