I’ve got 4 DC’s, 2 in each site for DR purposes.
Replication is failing from server A in subnet 1 to server B in subnet 2 with the following error:
Event ID 1411:
Active Directory Domain Services failed to construct a mutual authentication service principal name (SPN) for the following directory service.
Directory service:
c4b8f557-85f2-4eed-a2d9-b4e8f13fc5e0._msdcs.domain.local
The call was denied. Communication with this directory service might be affected.
Additional Data
Error value:
8589 The DS cannot derive a service principal name (SPN) with which to mutually authenticate the target server because the corresponding server object in the local DS database has no serverReference attribute.
repadmin /showreps show ‘The target principal name is incorrect’.
I’ve looked at http://support.microsoft.com/kb/938704
however, this related to Server 2003 or Server 2000, has anyone had any luck in Server 2008 or any ideas?
I’m thinking of demoting the DC and dcpromo, What are your thoughts?