CompTIA Network+ (N10-009)Network TroubleshootingMedium
Users across a domain report intermittent authentication failures when logging into workstations. Event logs on affected machines show Kerberos errors referencing clock skew. The affected workstations are not synchronized to the same time source as the domain controller. Which issue is most likely responsible?
- AAn expired SSL certificate on the domain controller
- BMTU mismatch between workstations and the domain controller
- CDNS resolution failure for the domain controller
- DWorkstation clocks have drifted more than the Kerberos time-skew tolerance from the domain controller
Show answer & explanationAnswer & explanation
Correct answer: D. Workstation clocks have drifted more than the Kerberos time-skew tolerance from the domain controller
Kerberos authentication requires client and server clocks to be within a defined tolerance (default 5 minutes) of each other. If NTP synchronization fails and clocks drift beyond this tolerance, authentication tickets are rejected, producing clock-skew errors — exactly matching the symptoms described.
Why the other options are wrong
- A. Certificate expiration would generate certificate trust errors, not clock skew messages.
- B. MTU mismatches cause fragmentation/connectivity issues, not authentication clock errors.
- C. DNS failures would cause name resolution errors, not clock-skew-specific Kerberos errors.
Kerberos Clock Skew
Kerberos authentication fails if the client and server system clocks differ by more than the configured tolerance (default 5 minutes), since timestamps are used to prevent replay attacks.
- Default max clock skew tolerance is 5 minutes.
- NTP synchronization keeps domain member clocks aligned.
- Symptoms include login failures with explicit clock-skew error messages.
Memory trick: 'No ticket if your watch is off by too much.'