Acutis Gate logo Acutis Gate Health check help

Health check › Active Directory

Gate's service account

Check id ad.keys

What it checks

Asks the domain controller for a Kerberos ticket as Gate's own account. On Windows that is the service's logon account (a gMSA); on Linux, the keys Gate stored for gate-svc.

What you might see

OKThe Gate service runs as CORP\acutisgate$ and the domain controller issues it Kerberos tickets.Fine.
ProblemClock skew too great / Preauthentication failed / KDC unreachableThe DC refused Gate, or Gate could not reach it.

How to fix it

Three causes cover almost every failure: the wrong logon account, the clock, and DNS.

Windows Server:

  1. Services → Acutis Gate → Properties → Log On: "This account" must be CORP\acutisgate$ with the password fields empty. Restart the service.
  2. Check the server clock is within 5 minutes of the domain controller.

Command line

Test-ADServiceAccount acutisgate          # True = this server may use the gMSA
sc.exe qc AcutisGate                       # SERVICE_START_NAME should be CORP\acutisgate$
w32tm /query /status
w32tm /resync

Linux appliance: if someone changed gate-svc's password in AD, reconnect on Identity → Active Directory with the new one.

Command line

timedatectl                                       # "System clock synchronized: yes"
nslookup -type=SRV _kerberos._tcp.corp.example   # the DCs must resolve
nc -vz dc1.corp.example 88

Related checks

Directory lookups (LDAP)Connected

Still stuck? Click Copy report on the Health check and send it to support@acutisgo.com. · Acutis Gate · Guides