Skip to content

Troubleshooting PKINIT

Troubleshooting PKINIT Issues

PKINIT (Public Key Infrastructure Initialization) relies on secure certificate-based authentication between clients and domain controllers. Failures in PKINIT can stem from misconfigured certificates, network issues, or Kerberos misconfigurations. Below are steps to diagnose and resolve common PKINIT authentication problems.


1. Verify Certificate Validity and Trust Chain

Ensure the client certificate is valid, trusted, and properly configured:
- Check certificate validity:

Get-ADCertEnrollment -ComputerName <DCName> | Select-Object ValidFrom, ValidTo
Ensure the certificate is not expired and is valid for the intended purpose (e.g., KDC Authentication).

  • Validate trust chain:
    Use certutil to verify the certificate chain:

    certutil -verify <CertificateThumbprint>
    
    Ensure all intermediate and root certificates are trusted by the client’s certificate store.

  • Confirm certificate store location:
    Certificates must be placed in the LocalMachine\My store for PKINIT to recognize them.


2. Check KDC Configuration

Verify the Key Distribution Center (KDC) settings on domain controllers:
- Confirm KDC role:
Ensure the domain controller has the KDC role enabled via:

Get-ADDomainController | Select-Object Name, KDCRole

  • Validate KDC trust settings:
    Use ksetup to check KDC trust configuration:
    ksetup /showkdc
    
    Ensure the KDC is correctly configured with the domain’s DNS name and CA trust settings.

3. Validate Time Synchronization

PKINIT requires precise time synchronization between clients and domain controllers:
- Check NTP configuration:
Ensure all systems are synchronized with a reliable NTP source:

w32tm /query /status
Use w32tm /resync to force resynchronization if drift exceeds 5 minutes.

  • Verify time zone consistency:
    Ensure all systems are set to the same time zone and regional settings.

4. Review Event Logs for Errors

Check the Security and System event logs on both clients and domain controllers for PKINIT-related errors:
- Common error codes:
- Event ID 4768: "A Kerberos authentication ticket was issued." (Normal, but verify if it’s a one-time event.)
- Event ID 4769: "A Kerberos authentication ticket was revoked." (Indicates certificate revocation issues.)
- Event ID 4766: "A Kerberos authentication ticket was issued for a user account." (Normal, but check for repeated occurrences.)

  • Query specific logs:
    Get-WinEvent -FilterHashtable @{LogName='Security'; ID=4768,4769,4766} | Format-List
    

5. Test Network Connectivity and Firewall Rules

Ensure network connectivity and firewall rules allow PKINIT traffic:
- Test ports 88 (Kerberos) and 464 (Kerberos) UDP/TCP:

Test-NetConnection -ComputerName <DCName> -Port 88
Test-NetConnection -ComputerName <DCName> -Port 464

  • Check firewall exceptions:
    Ensure the domain controller’s firewall allows inbound traffic on ports 88 and 464 for the client’s IP or subnet.

6. Client-Side Configuration

Ensure the client is properly configured for PKINIT:
- Enroll certificate:
Use certutil or the Certification Authority snap-in to enroll a certificate for the client.

  • Verify certificate enrollment:

    Get-ADCertEnrollment -ComputerName <DCName> | Select-Object Certificate, Status
    

  • Check client’s certificate store:
    Confirm the certificate is present in the LocalMachine\My store and marked as trusted for KDC Authentication.


Key takeaways

  • Certificates must be valid, trusted, and correctly stored in the client’s certificate store.
  • KDC configuration on domain controllers must align with the domain’s DNS and CA trust settings.
  • Time synchronization within 5 minutes is critical for PKINIT to function.
  • Event logs provide actionable insights into Kerberos and certificate-related failures.
  • Network connectivity and firewall rules must allow Kerberos traffic (ports 88 and 464).