Health check › Active Directory
Gate's service account
Check id ad.keys
What it checks
Asks the domain controller for a Kerberos ticket as Gate's own account. On Windows that is the service's logon account (a gMSA); on Linux, the keys Gate stored for gate-svc.
What you might see
| OK | The Gate service runs as CORP\acutisgate$ and the domain controller issues it Kerberos tickets. | Fine. |
| Problem | Clock skew too great / Preauthentication failed / KDC unreachable | The DC refused Gate, or Gate could not reach it. |
How to fix it
Three causes cover almost every failure: the wrong logon account, the clock, and DNS.
Windows Server:
- Services → Acutis Gate → Properties → Log On: "This account" must be
CORP\acutisgate$with the password fields empty. Restart the service. - Check the server clock is within 5 minutes of the domain controller.
Command line
Test-ADServiceAccount acutisgate # True = this server may use the gMSA sc.exe qc AcutisGate # SERVICE_START_NAME should be CORP\acutisgate$ w32tm /query /status w32tm /resync
Linux appliance: if someone changed gate-svc's password in AD, reconnect on Identity → Active Directory with the new one.
Command line
timedatectl # "System clock synchronized: yes" nslookup -type=SRV _kerberos._tcp.corp.example # the DCs must resolve nc -vz dc1.corp.example 88
Related checks
Directory lookups (LDAP)Connected
Still stuck? Click Copy report on the Health check and send it to support@acutisgo.com. · Acutis Gate · Guides
Acutis