CSCua29504 - 802.11w-capable client fails pairwise key handshake with AES - 9

Even i am facing same issue, we have in our office various client varied from Mobiles (new Lumia series), TABS, Laptops. Currently CUWN is configured with WPA/WPA2 with AES. On the WLC side 4400 with 7.0.235 IOS.
Whenever this clients tries to connect the Wireless say "can't connected to Wireless" .
Please suggest what to do.
Ankit shah

See if this thread
https://supportforums.cisco.com/thread/2168606
answers your quesiton.

Similar Messages

  • Client failing to recieve update via WSUS

    I have created a virtual lab environment and I am testing WSUS.
    I have deployed and configured my WSUS server as well as creating a GPO to point clients to my server.
    When manually checking for updates through windows update I receive error code 80244019.
    I have reviewed the update logs and feel there is an issue contacting my WSUS server. Any suggestions would be greatly appreciated
    2014-04-02 00:13:00:860 848 798 AU Triggering AU detection through DetectNow API
    2014-04-02 00:13:00:860 848 798 AU Additional Service {117CAB2D-82B1-4B5A-A08C-4D62DBEE7782} with Approval type {Scheduled} added to AU services list
    2014-04-02 00:13:00:860 848 798 AU Triggering Online detection (interactive)
    2014-04-02 00:13:00:989 848 51c AU #############
    2014-04-02 00:13:00:989 848 51c AU ## START ## AU: Search for updates
    2014-04-02 00:13:00:989 848 51c AU #########
    2014-04-02 00:13:01:001 848 51c AU Additional Service {117CAB2D-82B1-4B5A-A08C-4D62DBEE7782} with Approval type {Scheduled} added to AU services list
    2014-04-02 00:13:01:001 848 51c IdleTmr WU operation (CSearchCall::Init ID 45) started; operation # 322; does use network; is not at background priority
    2014-04-02 00:13:01:001 848 51c IdleTmr Incremented PDC RefCount for Network to 1
    2014-04-02 00:13:01:001 848 51c IdleTmr Incremented idle timer priority operation counter to 2
    2014-04-02 00:13:01:001 848 51c Agent *** START *** Queueing Finding updates [CallerId = AutomaticUpdatesWuApp Id = 45]
    2014-04-02 00:13:01:001 848 51c AU <<## SUBMITTED ## AU: Search for updates [CallId = {4AA753DD-56B8-4DD2-BDC2-7FC77A75BEE4} ServiceId = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}]
    2014-04-02 00:13:01:001 848 81c Agent *** END *** Queueing Finding updates [CallerId = AutomaticUpdatesWuApp Id = 45]
    2014-04-02 00:13:01:001 848 81c Agent *************
    2014-04-02 00:13:01:001 848 81c Agent ** START ** Agent: Finding updates [CallerId = AutomaticUpdatesWuApp Id = 45]
    2014-04-02 00:13:01:001 848 81c Agent *********
    2014-04-02 00:13:01:001 848 81c Agent * Online = Yes; Ignore download priority = No
    2014-04-02 00:13:01:001 848 81c Agent * Criteria = "IsInstalled=0 and DeploymentAction='Installation' or IsPresent=1 and DeploymentAction='Uninstallation' or IsInstalled=1 and DeploymentAction='Installation' and RebootRequired=1 or IsInstalled=0 and DeploymentAction='Uninstallation' and RebootRequired=1"
    2014-04-02 00:13:01:001 848 81c Agent * ServiceID = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7} Managed
    2014-04-02 00:13:01:001 848 81c Agent * Search Scope = {Machine & All Users}
    2014-04-02 00:13:01:001 848 81c Agent * Caller SID for Applicability: S-1-5-21-2929840714-3911456617-1138986597-1106
    2014-04-02 00:13:01:001 848 81c EP Got WSUS Client/Server URL: "http://APP1.CORP.CONTOSO.COM/ClientWebService/client.asmx"
    2014-04-02 00:13:01:001 848 81c Setup Checking for agent SelfUpdate
    2014-04-02 00:13:01:048 848 81c Setup Client version: Core: 7.9.9600.16422 Aux: 7.9.9600.16384
    2014-04-02 00:13:01:048 848 81c EP Got WSUS SelfUpdate URL: "http://APP1.CORP.CONTOSO.COM/selfupdate"
    2014-04-02 00:13:01:064 848 81c Misc WARNING: WinHttp: SendRequestToServerForFileInformation failed with 0x80190194
    2014-04-02 00:13:01:064 848 81c Misc WARNING: WinHttp: ShouldFileBeDownloaded failed with 0x80190194
    2014-04-02 00:13:01:064 848 81c Misc WARNING: DownloadFileInternal failed for http://APP1.CORP.CONTOSO.COM/selfupdate/wuident.cab: error 0x80190194
    2014-04-02 00:13:01:064 848 81c Setup WARNING: SelfUpdate check failed to download package information, error = 0x80244019
    2014-04-02 00:13:01:064 848 81c Setup FATAL: SelfUpdate check failed, err = 0x80244019
    2014-04-02 00:13:01:079 848 81c Agent * WARNING: Skipping scan, self-update check returned 0x80244019
    2014-04-02 00:13:01:079 848 81c Agent * WARNING: Exit code = 0x80244019
    2014-04-02 00:13:01:079 848 81c Agent *********
    2014-04-02 00:13:01:079 848 81c Agent ** END ** Agent: Finding updates [CallerId = AutomaticUpdatesWuApp Id = 45]
    2014-04-02 00:13:01:079 848 81c Agent *************
    2014-04-02 00:13:01:079 848 81c Agent WARNING: WU client failed Searching for update with error 0x80244019
    2014-04-02 00:13:01:079 848 81c IdleTmr WU operation (CSearchCall::Init ID 45, operation # 322) stopped; does use network; is not at background priority
    2014-04-02 00:13:01:079 848 81c IdleTmr Decremented PDC RefCount for Network to 0
    2014-04-02 00:13:01:079 848 81c IdleTmr Decremented idle timer priority operation counter to 1
    2014-04-02 00:13:01:079 848 8e0 AU >>## RESUMED ## AU: Search for updates [CallId = {4AA753DD-56B8-4DD2-BDC2-7FC77A75BEE4} ServiceId = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}]
    2014-04-02 00:13:01:079 848 8e0 AU # WARNING: Search callback failed, result = 0x80244019
    2014-04-02 00:13:01:079 848 8e0 AU #########
    2014-04-02 00:13:01:079 848 8e0 AU ## END ## AU: Search for updates [CallId = {4AA753DD-56B8-4DD2-BDC2-7FC77A75BEE4} ServiceId = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}]
    2014-04-02 00:13:01:079 848 8e0 AU #############
    2014-04-02 00:13:01:079 848 8e0 AU All AU searches complete.
    2014-04-02 00:13:01:079 848 8e0 AU # WARNING: Failed to find updates with error code 80244019
    2014-04-02 00:13:01:079 848 8e0 AU Need to show Unable to Detect notification
    2014-04-02 00:13:01:079 848 8e0 AU AU setting next detection timeout to 2014-04-02 04:13:01
    2014-04-02 00:13:01:095 848 8e0 AU # Publishing WNF Per user update count event Count: 0 SID {S-1-5-21-2929840714-3911456617-1138986597-1106} Service {117CAB2D-82B1-4B5A-A08C-4D62DBEE7782}
    2014-04-02 00:13:01:095 848 8e0 AU # Publishing WNF Per user update count event Count: 0 SID {S-1-5-21-2929840714-3911456617-1138986597-1106} Service {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
    2014-04-02 00:13:01:095 848 8e0 AU # Publishing WNF Per user update count event Count: 0 SID {S-1-5-21-2929840714-3911456617-1138986597-1106} Service {9482F4B4-E343-43B6-B170-9A65BC822C77}
    2014-04-02 00:13:01:095 848 8e0 AU # Publishing WNF Per user update count event Count: 7 SID {S-1-5-21-1674019052-998012437-141338546-1001} Service {117CAB2D-82B1-4B5A-A08C-4D62DBEE7782}
    2014-04-02 00:13:01:095 848 8e0 AU # Publishing WNF Per user update count event Count: 0 SID {S-1-5-21-1674019052-998012437-141338546-1001} Service {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
    2014-04-02 00:13:01:095 848 8e0 AU # Publishing WNF Per user update count event Count: 0 SID {S-1-5-21-1674019052-998012437-141338546-1001} Service {9482F4B4-E343-43B6-B170-9A65BC822C77}
    2014-04-02 00:13:02:939 848 79c AU Triggering AU detection through DetectNow API
    2014-04-02 00:13:02:939 848 79c AU Additional Service {117CAB2D-82B1-4B5A-A08C-4D62DBEE7782} with Approval type {Scheduled} added to AU services list
    2014-04-02 00:13:02:939 848 79c AU Triggering Online detection (interactive)
    2014-04-02 00:13:03:079 848 51c AU #############
    2014-04-02 00:13:03:079 848 51c AU ## START ## AU: Search for updates
    2014-04-02 00:13:03:079 848 51c AU #########
    2014-04-02 00:13:03:079 848 51c AU Additional Service {117CAB2D-82B1-4B5A-A08C-4D62DBEE7782} with Approval type {Scheduled} added to AU services list
    2014-04-02 00:13:03:079 848 51c IdleTmr WU operation (CSearchCall::Init ID 46) started; operation # 331; does use network; is not at background priority
    2014-04-02 00:13:03:079 848 51c IdleTmr Incremented PDC RefCount for Network to 1
    2014-04-02 00:13:03:079 848 51c IdleTmr Incremented idle timer priority operation counter to 2
    2014-04-02 00:13:03:079 848 51c Agent *** START *** Queueing Finding updates [CallerId = AutomaticUpdatesWuApp Id = 46]
    2014-04-02 00:13:03:079 848 51c AU <<## SUBMITTED ## AU: Search for updates [CallId = {BF690BA2-3D86-45C0-9A18-D8BC8BC47DAC} ServiceId = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}]
    2014-04-02 00:13:03:079 848 81c Agent *** END *** Queueing Finding updates [CallerId = AutomaticUpdatesWuApp Id = 46]
    2014-04-02 00:13:03:095 848 81c Agent *************
    2014-04-02 00:13:03:095 848 81c Agent ** START ** Agent: Finding updates [CallerId = AutomaticUpdatesWuApp Id = 46]
    2014-04-02 00:13:03:095 848 81c Agent *********
    2014-04-02 00:13:03:095 848 81c Agent * Online = Yes; Ignore download priority = No
    2014-04-02 00:13:03:095 848 81c Agent * Criteria = "IsInstalled=0 and DeploymentAction='Installation' or IsPresent=1 and DeploymentAction='Uninstallation' or IsInstalled=1 and DeploymentAction='Installation' and RebootRequired=1 or IsInstalled=0 and DeploymentAction='Uninstallation' and RebootRequired=1"
    2014-04-02 00:13:03:095 848 81c Agent * ServiceID = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7} Managed
    2014-04-02 00:13:03:095 848 81c Agent * Search Scope = {Machine & All Users}
    2014-04-02 00:13:03:095 848 81c Agent * Caller SID for Applicability: S-1-5-21-2929840714-3911456617-1138986597-1106
    2014-04-02 00:13:03:095 848 81c EP Got WSUS Client/Server URL: "http://APP1.CORP.CONTOSO.COM/ClientWebService/client.asmx"
    2014-04-02 00:13:03:095 848 81c Setup Checking for agent SelfUpdate
    2014-04-02 00:13:03:095 848 81c Setup Client version: Core: 7.9.9600.16422 Aux: 7.9.9600.16384
    2014-04-02 00:13:03:095 848 81c EP Got WSUS SelfUpdate URL: "http://APP1.CORP.CONTOSO.COM/selfupdate"
    2014-04-02 00:13:03:110 848 81c Misc WARNING: WinHttp: SendRequestToServerForFileInformation failed with 0x80190194
    2014-04-02 00:13:03:110 848 81c Misc WARNING: WinHttp: ShouldFileBeDownloaded failed with 0x80190194
    2014-04-02 00:13:03:110 848 81c Misc WARNING: DownloadFileInternal failed for http://APP1.CORP.CONTOSO.COM/selfupdate/wuident.cab: error 0x80190194
    2014-04-02 00:13:03:110 848 81c Setup WARNING: SelfUpdate check failed to download package information, error = 0x80244019
    2014-04-02 00:13:03:110 848 81c Setup FATAL: SelfUpdate check failed, err = 0x80244019
    2014-04-02 00:13:03:110 848 81c Agent * WARNING: Skipping scan, self-update check returned 0x80244019
    2014-04-02 00:13:03:110 848 81c Agent * WARNING: Exit code = 0x80244019
    2014-04-02 00:13:03:110 848 81c Agent *********
    2014-04-02 00:13:03:110 848 81c Agent ** END ** Agent: Finding updates [CallerId = AutomaticUpdatesWuApp Id = 46]
    2014-04-02 00:13:03:110 848 81c Agent *************
    2014-04-02 00:13:03:110 848 81c Agent WARNING: WU client failed Searching for update with error 0x80244019
    2014-04-02 00:13:03:110 848 81c IdleTmr WU operation (CSearchCall::Init ID 46, operation # 331) stopped; does use network; is not at background priority
    2014-04-02 00:13:03:110 848 81c IdleTmr Decremented PDC RefCount for Network to 0
    2014-04-02 00:13:03:110 848 81c IdleTmr Decremented idle timer priority operation counter to 1
    2014-04-02 00:13:03:110 848 8e0 AU >>## RESUMED ## AU: Search for updates [CallId = {BF690BA2-3D86-45C0-9A18-D8BC8BC47DAC} ServiceId = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}]
    2014-04-02 00:13:03:110 848 8e0 AU # WARNING: Search callback failed, result = 0x80244019
    2014-04-02 00:13:03:110 848 8e0 AU #########
    2014-04-02 00:13:03:110 848 8e0 AU ## END ## AU: Search for updates [CallId = {BF690BA2-3D86-45C0-9A18-D8BC8BC47DAC} ServiceId = {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}]
    2014-04-02 00:13:03:110 848 8e0 AU #############
    2014-04-02 00:13:03:110 848 8e0 AU All AU searches complete.
    2014-04-02 00:13:03:110 848 8e0 AU # WARNING: Failed to find updates with error code 80244019
    2014-04-02 00:13:03:110 848 8e0 AU Need to show Unable to Detect notification
    2014-04-02 00:13:03:110 848 8e0 AU AU setting next detection timeout to 2014-04-02 04:13:03
    2014-04-02 00:13:03:110 848 8e0 AU # Publishing WNF Per user update count event Count: 0 SID {S-1-5-21-2929840714-3911456617-1138986597-1106} Service {117CAB2D-82B1-4B5A-A08C-4D62DBEE7782}
    2014-04-02 00:13:03:110 848 8e0 AU # Publishing WNF Per user update count event Count: 0 SID {S-1-5-21-2929840714-3911456617-1138986597-1106} Service {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
    2014-04-02 00:13:03:110 848 8e0 AU # Publishing WNF Per user update count event Count: 0 SID {S-1-5-21-2929840714-3911456617-1138986597-1106} Service {9482F4B4-E343-43B6-B170-9A65BC822C77}
    2014-04-02 00:13:03:110 848 8e0 AU # Publishing WNF Per user update count event Count: 7 SID {S-1-5-21-1674019052-998012437-141338546-1001} Service {117CAB2D-82B1-4B5A-A08C-4D62DBEE7782}
    2014-04-02 00:13:03:110 848 8e0 AU # Publishing WNF Per user update count event Count: 0 SID {S-1-5-21-1674019052-998012437-141338546-1001} Service {3DA21691-E39D-4DA6-8A4B-B43877BCB1B7}
    2014-04-02 00:13:03:110 848 8e0 AU # Publishing WNF Per user update count event Count: 0 SID {S-1-5-21-1674019052-998012437-141338546-1001} Service {9482F4B4-E343-43B6-B170-9A65BC822C77}
    2014-04-02 00:13:06:079 848 8dc Report REPORT EVENT: {CC3A61B2-6D72-4EE5-8290-267C01BB971C} 2014-04-02 00:13:01:079+0100 1 148 [AGENT_DETECTION_FAILED] 101 {D67661EB-2423-451D-BF5D-13199E37DF28} 1 80244019 SelfUpdate Failure Software Synchronization Windows Update Client failed to detect with error 0x80244019.
    2014-04-02 00:13:06:079 848 8dc Report REPORT EVENT: {15E44187-2503-438C-9813-EB6D81BFEA23} 2014-04-02 00:13:03:110+0100 1 148 [AGENT_DETECTION_FAILED] 101 {D67661EB-2423-451D-BF5D-13199E37DF28} 1 80244019 SelfUpdate Failure Software Synchronization Windows Update Client failed to detect with error 0x80244019.
    2014-04-02 00:13:06:079 848 8dc Report WARNING: Failed to get ProtocolVersion: 8024043d
    2014-04-02 00:13:06:079 848 8dc Report WARNING: Failed to get ProtocolVersion: 8024043d
    2014-04-02 00:13:06:079 848 8dc Report CWERReporter::HandleEvents - WER report upload completed with status 0x8
    2014-04-02 00:13:06:079 848 8dc Report WER Report sent: 7.9.9600.16422 0x80244019(0) D67661EB-2423-451D-BF5D-13199E37DF28 Scan 101 Managed
    2014-04-02 00:13:06:142 848 8dc Report CWERReporter::HandleEvents - WER report upload completed with status 0x8
    2014-04-02 00:13:06:142 848 8dc Report WER Report sent: 7.9.9600.16422 0x80244019(0) D67661EB-2423-451D-BF5D-13199E37DF28 Scan 101 Managed
    2014-04-02 00:13:06:142 848 8dc Report CWERReporter finishing event handling. (00000000)

    During my initial investigation I had already confirmed both the background BITS and windows update services were running.
    I can confirm that after checking my policy and amending the "Specify intranet Microsoft update service location" to the following, to include the correct port
    http://App1.corp.contoso.com:8530
    I have been able to resolve the issue.
    Thank you for your comments
    Kind regards

  • The SMB client failed to resume a handle on a file share with continuous availability

    Hi.
    We have a 2-node WS2012 cluster that has a file server role with couple shares configured.
    We're however constantly getting spammed by the following errors in the eventlog:
    1) event 1002, source: SmbServer, message: "RKF failure - SRV2 failed to get acknowledgement from Resume Key filter for persistent handle request."
    2) SCOM has an alert opened with this description: "SMB client failed to resume Continuously Available (CA) handle as Resume Key Filter is not acknowledging the handle." Per the alert knowledge, we've inspected ResumeKeyFilter eventlog, but it
    contains only informational message and warnings and none of those are from the time the alert was created.

    Hi,<o:p></o:p>
    Please try applying the following hotfixes.<o:p></o:p>
    Update that improves cloud service provider resiliency in Windows Server 2012<o:p></o:p>
    http://support.microsoft.com/kb/2870270
    <o:p></o:p>
    Physical Disk resource move during the backup of a Cluster Shared Volume (CSV) may cause resource outage<o:p></o:p>
    http://support.microsoft.com/kb/2869923
    <o:p></o:p>
    Can't access a resource that is hosted on a Windows 8 or Windows Server 2012-based failover cluster<o:p></o:p>
    http://support.microsoft.com/kb/2838043
    <o:p></o:p>
    Best regards,
    Vincent Wu
    Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.

  • Jax-ws deployed in standalone client fails with nullpointerexception

    I have a project which has deployed successfully as a standalone client with deployed jar files wlfullclient.jar, etc. When I add the jax-ws functions that I require, the deployed client fails with a nullpointerexception that is generated from the constructor of the Service class. The project runs successfully within the JDeveloper 11.1.1.5 environment and on a weblogic 10.3 server platform, but fails when I deploy as a standalone client with the wlfullclient.jar. I'm using JDK 1.6.0_24. In testing, the error occurs when I replace the {WLHome}\server\lib\weblogic.jar entry in the classpath with the wlfullclient.jar.
    I tested from another angle by creating my jax-ws functions in a standalone deployment, and it works successfully communicates with the webservices. No additional entries on the classpath besides my deployed jar. I then added to my deployment a simple JMS context lookup:
    Hashtable ht = new Hashtable();
    ht.put(Context.INITIAL_CONTEXT_FACTORY, contextFactoryProvider);
    ht.put(Context.PROVIDER_URL, urlString);
    Context context = new InitialContext(ht);
    This test runs without error in the JDeveloper environment. As soon as I add the wlfullclient.jar in the standalone environment, I get the following exception:
    Exception in thread "main" java.lang.NoClassDefFoundError: com/sun/xml/ws/spi/ProviderImpl
    at java.lang.ClassLoader.defineClass1(Native Method)
    at java.lang.ClassLoader.defineClassCond(ClassLoader.java:630)
    at java.lang.ClassLoader.defineClass(ClassLoader.java:614)
    at java.security.SecureClassLoader.defineClass(SecureClassLoader.java:141)
    at java.net.URLClassLoader.defineClass(URLClassLoader.java:283)
    at java.net.URLClassLoader.access$000(URLClassLoader.java:58)
    at java.net.URLClassLoader$1.run(URLClassLoader.java:197)
    at java.security.AccessController.doPrivileged(Native Method)
    at java.net.URLClassLoader.findClass(URLClassLoader.java:190)
    at java.lang.ClassLoader.loadClass(ClassLoader.java:305)
    at sun.misc.Launcher$AppClassLoader.loadClass(Launcher.java:301)
    at java.lang.ClassLoader.loadClass(ClassLoader.java:246)
    at javax.xml.ws.spi.FactoryFinder.safeLoadClass(FactoryFinder.java:150)
    at javax.xml.ws.spi.FactoryFinder.newInstance(FactoryFinder.java:30)
    at javax.xml.ws.spi.FactoryFinder.find(FactoryFinder.java:90)
    at javax.xml.ws.spi.Provider.provider(Provider.java:83)
    at javax.xml.ws.Service.<init>(Service.java:56)
    Interestingly, there is a class com/sun/xml/internal/ws.spi/ProviderImpl in the {JAVA_HOME}/jre/lib/rt.jar file, and I suppose this is what is used by the jax-ws classes when the wlfullclient.jar is not present on the classpath.
    So, what is it that I am missing in how to get the jax-ws classes and the jms classes to work in the standalone deployment environment (outside of the JDeveloper environment).
    Edited by: user3653687 on Jan 9, 2012 1:38 PM
    Edited by: user3653687 on Jan 9, 2012 2:49 PM

    Here is how I solved this problem to execute the application from a jar file (using Oracle Fusion Middleware 11.1.1.5.0 distribution). The key seems to be to extract the contents of the wseeclient.zip file into the same directory as the wlfullclient.jar and ws.api_1.1.0.0.jar files and then ensure that these 2 jars are on the classpath.
    In JDeveloper, create a project that has the jms/jax-ws classes.
    Put the following text entries to form the classpath (along with other dependent jars, e.g. org.eclipse.persistence...) into a file which will be included in the manifest for the client jar. Be sure to separate entries with a space.
    lib/wlfullclient.jar lib/wseeclient.jar lib\ws.api_1.1.0.0.jar lib\org.eclipse.persistence_1.1.0.0_2-1.jar
    In the Edit Deployment Profile Properties, select Include Manifest File, specify the main class to execute, and Add the classpath file to be included in the manifest.
    Deploy the jar file.
    In a deployment area, create the directory that will contain all the classpath jars (e.g. ./lib).
    Within the directory ./lib, extract all files from wseeclient.zip (found in {weblogic home}/server/lib)
    Copy wlfullclient.jar into the directory ./lib from the {weblogic home}/server/lib
    Copy ws.api_1.1.0.0.jar into the directory ./lib from {oracle middleware home}modules
    Copy org.eclipse.persistence_1.1.0.0_2-1.jar (for jaxb support) itno the directory ./lib from {oracle middleware home}/modules
    Copy the deployed client jar to the deployment area and execute, e.g.:
    java -jar ClientTest.jar myArguments

  • EAP-TLS error .........failed SSL/TLS handshake because of an unknown CA in client certificate chain

    Hi,
    I am using 802.1x and EAP-TLS as authentication protocol. The clients are not able to pass the authentication the error log on ACS is
    Authentication failed: EAP-TLS handshake failed SSL/TLS handshake because of an unknown CA in the client certification chain.
    I have installed certificates on the WLC and ACS, however authentication is unsuccessful.
    Can anybody help regarding this issue.

    Hi Sandeep,
    Web auth certificate is defult certificate in wlc but you can also use your own(3rd party).
    http://www.cisco.com/c/en/us/support/docs/wireless-mobility/wlan-security/70584-csr-wlc-00.html
    Virtual interface : This interface handles any mobility management, VPN Termination, Web authentication, and is also a DHCP relay for WLAN clients.
    Yes its interconnected, the purpose for this entry is so that the controller knows the name of the of the certificates to virtual address translation.
    1. Guest Client go to google.com
    2. Client goes to DNS (the one its is assign in DHCP)
    3. DNS resolves the DNS for google.com
    4. Client then attempts to go to google.com
    5. Controller intercepts GET and replaces it with a 1.1.1.1
    6. Controller then takes the 1.1.1.1 and translates this to the DNS name to negat the (accpet this cert screen)
    7. DNS then gets resolve to the name (example guest.xxx.com)
    8. Controller presents the guest screen
    Hope it helps.
    Regards
    Dont forget to rate helpful posts

  • Wireless Clients failing to authenticate via the RADIUS

    Hi friends
    I am trying to use Radius server (NPS) to authenticate my wireless users using 1941W router.
    For some reason it cannot authenticate successfully. I checked the radius server is reachable but still I dont see any luck.
    the config is like this:
    ***************Config snap shot*********************
    aaa new-model
    aaa group server radius group1
    server 10.32.0.154 auth-port 1812 acct-port 1813
    aaa authentication login EAP group group1
    aaa session-id common
    dot11 syslog
    dot11 ssid CORP
       vlan 320
       authentication open eap EAP
       mbssid guest-mode
    interface Loopback1
    ip address 10.51.240.1 255.255.255.255
    no ip route-cache
    interface Dot11Radio0
    no ip address
    no ip route-cache
    encryption vlan 320 mode ciphers aes-ccm
    ssid CORP
    antenna gain 0
    mbssid
    station-role root
    interface Dot11Radio0.1
    encapsulation dot1Q 320 native
    no ip route-cache
    bridge-group 1
    bridge-group 1 subscriber-loop-control
    bridge-group 1 block-unknown-source
    no bridge-group 1 source-learning
    no bridge-group 1 unicast-flooding
    bridge-group 1 spanning-disabled
    interface GigabitEthernet0
    description the embedded AP GigabitEthernet 0 is an internal interface connecting AP with the host router
    no ip address
    no ip route-cache
    interface GigabitEthernet0.1
    encapsulation dot1Q 320 native
    no ip route-cache
    bridge-group 1
    no bridge-group 1 source-learning
    bridge-group 1 spanning-disabled
    interface BVI1
    ip address 10.51.246.2 255.255.255.0
    no ip route-cache
    ip default-gateway 10.51.246.1
    ip radius source-interface Loopback1
    radius-server host 10.32.0.154 auth-port 1812 acct-port 1646 key V3rv3@mc0m
    bridge 1 route ip
    *********************End of config snap shot*********************
    When i run the debug i see the following messages which I am still trying to understand thought it would be worthwhile mentioning here:
    *******************Debug**********************
    AP1#
    *Mar  1 01:04:41.951: AAA/BIND(0000001E): Bind i/f
    *Mar  1 01:04:41.951: dot11_auth_add_client_entry: Create new client 2477.037e.22d4 for application 0x1
    *Mar  1 01:04:41.951: dot11_auth_initialize_client: 2477.037e.22d4 is added to the client list for application 0x1
    *Mar  1 01:04:41.951: dot11_auth_add_client_entry: req->auth_type 0
    *Mar  1 01:04:41.951: dot11_auth_add_client_entry: auth_methods_inprocess: 2
    *Mar  1 01:04:41.951: dot11_auth_add_client_entry: eap list name: EAP
    *Mar  1 01:04:41.951: dot11_run_auth_methods: Start auth method EAP or LEAP
    *Mar  1 01:04:41.951: dot11_auth_dot1x_start: in the dot11_auth_dot1x_start
    *Mar  1 01:04:41.951: dot11_auth_dot1x_send_id_req_to_client: Sending identity request to 2477.037e.22d4
    *Mar  1 01:04:41.951: EAPOL pak dump tx
    *Mar  1 01:04:41.951: EAPOL Version: 0x1  type: 0x0  length: 0x002F
    *Mar  1 01:04:41.951: EAP code: 0x1  id: 0x1  length: 0x002F type: 0x1
    030017B0: 0100002F 0101002F 01006E65 74776F72  .../.../..networ
    030017C0: 6B69643D 56434F52 502C6E61 7369643D  kid=VCORP,nasid=
    030017D0: 4B414C2D 30322D41 50312C70 6F727469  KAL-02-AP1,porti
    030017E0: 643D30                               d=0
    *Mar  1 01:04:41.955: dot11_auth_send_msg:  sending data to requestor status 1
    *Mar  1 01:04:41.955: dot11_auth_send_msg: Sending EAPOL to requestor
    *Mar  1 01:04:41.955: dot11_auth_dot1x_send_id_req_to_client: Client 2477.037e.22d4 timer started for 30 seconds
    *Mar  1 01:04:41.955: dot11_auth_parse_client_pak: Received EAPOL packet from 2477.037e.22d4
    *Mar  1 01:04:41.955: EAPOL pak dump rx
    *Mar  1 01:04:41.955: EAPOL Version: 0x1  type: 0x1  length: 0x0000
    033E86E0:          01010000                        ....
    *Mar  1 01:04:41.955: dot11_auth_dot1x_run_rfsm: Executing Action(CLIENT_WAIT,EAP_START) for 2477.037e.22d4
    *Mar  1 01:04:41.955: dot11_auth_dot1x_send_id_req_to_client: Sending identity request to 2477.037e.22d4
    *Mar  1 01:04:41.959: EAPOL pak dump tx
    *Mar  1 01:04:41.959: EAPOL Version: 0x1  type: 0x0  length: 0x002F
    *Mar  1 01:04:41.959: EAP code: 0x1  id: 0x2  length: 0x002F type: 0x1
    03001A20: 0100002F 0102002F 01006E65 74776F72  .../.../..networ
    03001A30: 6B69643D 56434F52 502C6E61 7369643D  kid=VCORP,nasid=
    03001A40: 4B414C2D 30322D41 50312C70 6F727469  KAL-02-AP1,porti
    03001A50: 643D30                               d=0
    *Mar  1 01:04:41.959: dot11_auth_send_msg:  sending data to requestor status 1
    *Mar  1 01:04:41.959: dot11_auth_send_msg: Sending EAPOL to requestor
    *Mar  1 01:04:41.959: dot11_auth_dot1x_send_id_req_to_client: Client 2477.037e.22d4 timer started for 30 seconds
    *Mar  1 01:04:41.963: dot11_auth_parse_client_pak: Received EAPOL packet from 2477.037e.22d4
    *Mar  1 01:04:41.963: EAPOL pak dump rx
    *Mar  1 01:04:41.963: EAPOL Version: 0x1  type: 0x0  length: 0x0012
    *Mar  1 01:04:41.963: EAP code: 0x2  id: 0x1  length: 0x0012 type: 0x1
    033603C0:                            01000012              ....
    033603D0: 02010012 01564552 56455C47 30373532  .....VERVE\G0752
    033603E0: 3736                                 76
    *Mar  1 01:04:41.963: dot11_auth_parse_client_pak: id is not matching req-id:1resp-id:2, waiting for response
    *Mar  1 01:04:41.963: dot11_auth_parse_client_pak: Received EAPOL packet from 2477.037e.22d4
    *Mar  1 01:04:41.963: EAPOL pak dump rx
    *Mar  1 01:04:41.963: EAPOL Version: 0x1  type: 0x0  length: 0x0012
    *Mar  1 01:04:41.963: EAP code: 0x2  id: 0x2  length: 0x0012 type: 0x1
    033AEE90:                   01000012 02020012          ........
    033AEEA0: 01564552 56455C47 30373532 3736      .VERVE\G075276
    *Mar  1 01:04:41.963: dot11_auth_dot1x_run_rfsm: Executing Action(CLIENT_WAIT,CLIENT_REPLY) for 2477.037e.22d4
    *Mar  1 01:04:41.963: dot11_auth_dot1x_send_response_to_server: Sending client 2477.037e.22d4 data to server
    *Mar  1 01:04:41.963: AAA/AUTHEN/PPP (0000001E): Pick method list 'EAP'
    *Mar  1 01:04:41.963: dot11_auth_dot1x_send_response_to_server: Started timer server_timeout 60 seconds
    *Mar  1 01:04:41.963: %AAA-3-BADSERVERTYPEERROR: Cannot process authentication server type *invalid_group_handle*
    *Mar  1 01:04:41.963: dot11_auth_dot1x_parse_aaa_resp: Received server response: FAIL
    *Mar  1 01:04:41.963: dot11_auth_dot1x_parse_aaa_resp: found eap pak in server response
    *Mar  1 01:04:41.963: Client 2477.037e.22d4 failed: EAP reason 2
    *Mar  1 01:04:41.963: dot11_auth_dot1x_parse_aaa_resp: Failed client 2477.037e.22d4 with aaa_req_status_detail 2
    *Mar  1 01:04:41.963: dot11_auth_dot1x_run_rfsm: Executing Action(SERVER_WAIT,SERVER_FAIL) for 2477.037e.22d4
    *Mar  1 01:04:41.963: dot11_auth_dot1x_send_response_to_client: Forwarding server message to client 2477.037e.22d4
    *Mar  1 01:04:41.963: EAPOL pak dump tx
    *Mar  1 01:04:41.963: EAPOL Version: 0x1  type: 0x0  length: 0x0004
    *Mar  1 01:04:41.963: EAP code: 0x4  id: 0x2  length: 0x0004
    03001DC0:                   01000004 04020004          ........
    03001DD0:
    *Mar  1 01:04:41.963: dot11_auth_send_msg:  sending data to requestor status 1
    *Mar  1 01:04:41.967: dot11_auth_send_msg: Sending EAPOL to requestor
    *Mar  1 01:04:41.967: dot11_auth_dot1x_send_response_to_client: Started timer client_timeout 30 seconds
    *Mar  1 01:04:41.967: dot11_auth_dot1x_send_client_fail: Authentication failed for 2477.037e.22d4
    *Mar  1 01:04:41.967: dot11_auth_send_msg:  sending data to requestor status 0
    *Mar  1 01:04:41.967: dot11_auth_send_msg: client FAILED to authenticate 2477.037e.22d4, node_type 64 for application 0x1
    *Mar  1 01:04:41.967: dot11_auth_delete_client_entry: 2477.037e.22d4 is deleted for application 0x1
    *Mar  1 01:04:41.967: %DOT11-7-AUTH_FAILED: Station 2477.037e.22d4 Authentication failed
    *Mar  1 01:04:41.967: dot11_auth_client_abort: Received abort request for client 2477.037e.22d4
    *Mar  1 01:04:41.967: dot11_auth_client_abort: No client entry to abort: 2477.037e.22d4 for application 0x1
    Any Idea where the problem could be?
    Regards,
    Mohit

    Just to add here, i ran another command on the AP/Router which indicates to me that there was no response from the Radius server.
    KAL-02-AP1#sh radius statistics
                                      Auth.      Acct.       Both
             Maximum inQ length:         NA         NA          1
           Maximum waitQ length:         NA         NA          2
           Maximum doneQ length:         NA         NA          1
           Total responses seen:          0          0          0
         Packets with responses:          0          0          0
      Packets without responses:         12          0         12
      Access Rejects           :          0
    Average response delay(ms):          0          0          0
    Maximum response delay(ms):          0          0          0
      Number of Radius timeouts:         48          0         48
           Duplicate ID detects:          0          0          0
    Buffer Allocation Failures:          0          0          0
    Maximum Buffer Size (bytes):        186          0        186
    Source Port Range: (2 ports only)
    1645 - 1646
    Last used Source Port/Identifier:
    1645/12
    1646/0
      Elapsed time since counters last cleared: 1h52m

  • Logon of user in client failed when starting a step

    Hi All,
    I have a question. (Might be simple to many).
    <b>Logon of user in client failed when starting a step.</b>
    Some of my scheduled jobs are getting cancelled due to the above error. It has been noted that the user corresponding to that job has been locked.
    Can anybody suggest how to change the user of a Background Job (without deleting and re-creating the same).
    Thanks and Regards
    Devanand

    Hi
    You cannot change the owner of the job once it is in released status.
    Better, create the job with same varient by an existing user and delete the cancelled job.
    regards,
    Vinodh.

  • ConfigMgr 2012 R2 Client Failes to Install on HP EliteBook laptops with Synaptics Touchpad drivers

    I've come across a fairly frustrating issue that has been taking up way too much of my time that past week or so. The issue started a little after some of our larger sites were migrated from SCCM 2007 to SCCM 2012. I started getting complaints that one of
    our technical workstations (HP 8770w) was not deploying properly. I started investigating the issue and the problem involved the removal of the old ConfigMgr 2007 client and install of the new SCCM 2012 R2 client.
    The Windows 7 x64 OS WIM that I am using is one that was migrated from the 07 to 2012 environment and it has been working fine. During the Setup Windows and ConfigMgr step the old client is removed and the new one for the 2012 environment installs. There
    has not been any issues with this, but I feel something has changed now that we are deploying the 2012 R2 client.
    Back to the issue, what happens is that the ConfigMgr client fails to uninstall the old client. Looking in the client.msi_uninstall file you will see that it is unable to locate a couple of SCCM 2007 configmgr client patches that were installed so it can
    uninstall it. I get the "Couldn't find local patch ''. Looking for it at its source." line in the uninstall file. When I look for that under HKEY_CLASSES_ROOT\Installer\Patches the ENTIRE directory structure is empty. There is not a single item
    listed under patches.
    Since the only thing that happens in between the pushing down of the WIM and installing the configmgr client is the drivers that is where I started to look. I started over with the basics (disk and network driver) and it was able to complete the OSD process
    (like the other 30+ models we currently support). I added drivers one by one having the system re-image each time. When I got to the Synaptics TouchPad drivers the issue would return. I've tried around 5 different drivers offered from the vendor and they
    all result in the same behavior.
    I'm still actively troubleshooting how to FIX this issue, but I have no idea why this is going on. I thought I would share with the community on this issue and see if anyone else has observed this VERY odd behavior.
    Here is a snippet from the client.msi_uninstall log:
    === Verbose logging started: 1/15/2014  22:59:34  Build type: SHIP UNICODE 5.00.7601.00  Calling process: D:\_SMSTaskSequence\OSD\GAS000EF\ccmsetup.exe ===
    MSI (c) (6C:BC) [22:59:34:264]: Resetting cached policy values
    MSI (c) (6C:BC) [22:59:34:264]: Machine policy value 'Debug' is 0
    MSI (c) (6C:BC) [22:59:34:264]: ******* RunEngine:
               ******* Product: {2609EDF1-34C4-4B03-B634-55F3B3BC4931}
               ******* Action:
               ******* CommandLine: **********
    MSI (c) (6C:BC) [22:59:34:264]: Client-side and UI is none or basic: Running entire install on the server.
    MSI (c) (6C:BC) [22:59:34:264]: Grabbed execution mutex.
    MSI (c) (6C:BC) [22:59:34:264]: Cloaking enabled.
    MSI (c) (6C:BC) [22:59:34:264]: Attempting to enable all disabled privileges before calling Install on Server
    MSI (c) (6C:BC) [22:59:34:264]: Incrementing counter to disable shutdown. Counter after increment: 0
    MSI (s) (00:80) [22:59:34:264]: Running installation inside multi-package transaction {2609EDF1-34C4-4B03-B634-55F3B3BC4931}
    MSI (s) (00:80) [22:59:34:264]: Grabbed execution mutex.
    MSI (s) (00:D4) [22:59:34:264]: Resetting cached policy values
    MSI (s) (00:D4) [22:59:34:264]: Machine policy value 'Debug' is 0
    MSI (s) (00:D4) [22:59:34:264]: ******* RunEngine:
               ******* Product: {2609EDF1-34C4-4B03-B634-55F3B3BC4931}
               ******* Action:
               ******* CommandLine: **********
    MSI (s) (00:D4) [22:59:34:264]: Machine policy value 'DisableUserInstalls' is 0
    MSI (s) (00:D4) [22:59:34:405]: SRSetRestorePoint skipped for this transaction.
    MSI (s) (00:D4) [22:59:34:405]: End dialog not enabled
    MSI (s) (00:D4) [22:59:34:405]: Original package ==> C:\Windows\Installer\b8ba.msi
    MSI (s) (00:D4) [22:59:34:405]: Package we're running from ==> C:\Windows\Installer\b8ba.msi
    MSI (s) (00:D4) [22:59:34:405]: APPCOMPAT: Uninstall Flags override found.
    MSI (s) (00:D4) [22:59:34:405]: APPCOMPAT: Uninstall VersionNT override found.
    MSI (s) (00:D4) [22:59:34:405]: APPCOMPAT: Uninstall ServicePackLevel override found.
    MSI (s) (00:D4) [22:59:34:405]: APPCOMPAT: looking for appcompat database entry with ProductCode '{2609EDF1-34C4-4B03-B634-55F3B3BC4931}'.
    MSI (s) (00:D4) [22:59:34:405]: APPCOMPAT: no matching ProductCode found in database.
    MSI (s) (00:D4) [22:59:34:420]: MSCOREE not loaded loading copy from system32
    MSI (s) (00:D4) [22:59:34:420]: Note: 1: 2262 2: MsiFileHash 3: -2147287038
    MSI (s) (00:D4) [22:59:34:420]: Couldn't find local patch ''. Looking for it at its source.
    MSI (s) (00:D4) [22:59:34:420]: Resolving Patch source.
    MSI (s) (00:D4) [22:59:34:420]: User policy value 'SearchOrder' is 'nmu'
    MSI (s) (00:D4) [22:59:34:420]: User policy value 'DisableMedia' is 0
    MSI (s) (00:D4) [22:59:34:420]: Machine policy value 'AllowLockdownMedia' is 0
    MSI (s) (00:D4) [22:59:34:420]: SOURCEMGMT: Media enabled only if package is safe.
    MSI (s) (00:D4) [22:59:34:420]: SOURCEMGMT: Looking for sourcelist for product {D478B8EE-EE0A-4004-980B-4D55533EE3C2}
    MSI (s) (00:D4) [22:59:34:420]: Note: 1: 1706 2: {D478B8EE-EE0A-4004-980B-4D55533EE3C2} 3: 
    MSI (s) (00:D4) [22:59:34:420]: SOURCEMGMT: Failed to resolve source
    MSI (s) (00:D4) [22:59:34:420]: Searching provided command line patches for patch code {D478B8EE-EE0A-4004-980B-4D55533EE3C2}
    MSI (s) (00:D4) [22:59:34:420]: Could not find source for missing patch {D478B8EE-EE0A-4004-980B-4D55533EE3C2} -- orphaning this patch
    MSI (s) (00:D4) [22:59:34:420]: Couldn't find local patch ''. Looking for it at its source.
    MSI (s) (00:D4) [22:59:34:420]: Resolving Patch source.
    MSI (s) (00:D4) [22:59:34:420]: User policy value 'SearchOrder' is 'nmu'
    MSI (s) (00:D4) [22:59:34:420]: SOURCEMGMT: Media enabled only if package is safe.
    MSI (s) (00:D4) [22:59:34:420]: SOURCEMGMT: Looking for sourcelist for product {599B62C0-F1BE-4FE8-80D9-36937D5DDBFE}
    MSI (s) (00:D4) [22:59:34:420]: Note: 1: 1706 2: {599B62C0-F1BE-4FE8-80D9-36937D5DDBFE} 3: 
    MSI (s) (00:D4) [22:59:34:420]: SOURCEMGMT: Failed to resolve source
    MSI (s) (00:D4) [22:59:34:420]: Searching provided command line patches for patch code {599B62C0-F1BE-4FE8-80D9-36937D5DDBFE}
    MSI (s) (00:D4) [22:59:34:420]: Could not find source for missing patch {599B62C0-F1BE-4FE8-80D9-36937D5DDBFE} -- orphaning this patch
    MSI (s) (00:D4) [22:59:34:420]: SequencePatches starts. Product code: {2609EDF1-34C4-4B03-B634-55F3B3BC4931}, Product version: 4.00.6487.2000, Upgrade code: {252DA259-82CA-4177-B8D0-49C78937BA3E}, Product language 1033
    MSI (s) (00:D4) [22:59:34:420]: SequencePatches returns success.
    MSI (s) (00:D4) [22:59:34:420]: Final Patch Application Order:
    MSI (s) (00:D4) [22:59:34:420]: Other Patches:
    MSI (s) (00:D4) [22:59:34:420]: Internal Exception during install operation: 0xc0000005 at 0x000007FEFDBF35E1.
    MSI (s) (00:D4) [22:59:34:420]: WER report disabled for silent install.
    MSI (s) (00:D4) [22:59:34:420]: Internal MSI error. Installer terminated prematurely.
    MSI (s) (00:D4) [22:59:34:420]: MainEngineThread is returning 1603
    MSI (s) (00:80) [22:59:34:420]: No System Restore sequence number for this installation.
    Unexpected Termination
    MSI (s) (00:80) [22:59:34:420]: User policy value 'DisableRollback' is 0
    MSI (s) (00:80) [22:59:34:420]: Machine policy value 'DisableRollback' is 0
    MSI (s) (00:80) [22:59:34:420]: Incrementing counter to disable shutdown. Counter after increment: 0
    MSI (s) (00:80) [22:59:34:420]: Note: 1: 1402 2: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts 3: 2
    MSI (s) (00:80) [22:59:34:420]: Note: 1: 1402 2: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts 3: 2
    MSI (s) (00:80) [22:59:34:420]: Note: 1: 1402 2: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\InProgress 3: 2
    MSI (s) (00:80) [22:59:34:420]: Note: 1: 1402 2: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\InProgress 3: 2
    MSI (s) (00:80) [22:59:34:420]: Decrementing counter to disable shutdown. If counter >= 0, shutdown will be denied.  Counter after decrement: -1
    MSI (s) (00:80) [22:59:34:420]: Restoring environment variables
    MSI (c) (6C:BC) [22:59:34:420]: Decrementing counter to disable shutdown. If counter >= 0, shutdown will be denied.  Counter after decrement: -1
    MSI (c) (6C:BC) [22:59:34:420]: MainEngineThread is returning 1603
    === Verbose logging stopped: 1/15/2014  22:59:34 ===

    @Narcoticoo
    I've not used the tool. This issue has also expanded since the original title as I'm getting the same behavior with the driver package that does not include the Touchpad driver anymore. I'm currently going back to just the network and storage driver to see
    if it works or not.
    However, this is the bigger issue I have:
    I have an older build called Build 5.7 internally. Using that WIM and the same driver package (original one that has the Touchpad driver included) it works without issue. Never had a problem.
    The new build is called Build 6.0 internally. This WIM and the same driver package has not been working at all.
    We support about 35 models with our current Windows 7 x64 image and I am having the same failure issue on four different HP models. They are the 8770w, ZBook 17, Z600 and Z820. The majority of the other systems are Dell devices. Just for transparency sakes,
    nothing Dell specific is in the core WIM that is captured.
    So, Build 5.7 can deploy just fine on all pieces of hardware with their old driver packages. The new Build 6.0 intalls on almost every platform fine with their old driver packages. These four HP systems are nothing but trouble though. I've opened a case
    with HP to see if they have noticed anything internally. I'm not too hopeful, but at least it is something. Maybe there is some odd conflict with a newer Windows patch or some odd dependency on older HP drivers. The new image has .NET 4.5.1, IE 10 and so forth.

  • Windows Update Client failed to detect with error 0xc8000247 after using Lenovo System Update 5

    My Windows 7, SP1 was running fine, until I installed few updates on 10/15 using Lenovo System Update 5 then Windows Update stopped working, shows as RED:
    {CE3119AD-35EF-41CF-9C21-C7698FEB8393}    2013-10-14 21:53:00:256-0700    1    147    101    {00000000-0000-0000-0000-000000000000}    0    0    AutomaticUpdates    Success    Software Synchronization    Windows Update Client successfully detected 4 updates.
    {EB17A01A-EB6E-49FF-9EA2-AA0DD063B4B1}    2013-10-15 04:15:54:069-0700    1    162    101    {C61A0D00-3E51-48AC-B0AF-1D3E02B9E5D3}    201    0    AutomaticUpdates    Success    Content Download    Download succeeded.
    {77DAE88F-2795-4258-8BBF-8D27E53662CF}    2013-10-15 12:10:38:196-0700    1    193    102    {00000000-0000-0000-0000-000000000000}    0    0    AutomaticUpdates    Success    Content Install    Restart Required: To complete the installation of the following updates, the computer must be restarted. Until this computer has been restarted, Windows cannot search for or download new updates:  - Security Update for Windows 7 for x64-based Systems (KB2862330)
    {1398F777-3AEF-4D1D-BE4C-407EC4AEAD4C}    2013-10-15 12:15:25:676-0700    1    183    101    {C61A0D00-3E51-48AC-B0AF-1D3E02B9E5D3}    201    0    AutomaticUpdates    Success    Content Install    Installation Successful: Windows successfully installed the following update: Security Update for Windows 7 for x64-based Systems (KB2862330)
    {A220898A-E5FE-4FE7-8413-2B0C7B4013D0}    2013-10-15 12:15:25:766-0700    1    202    102    {00000000-0000-0000-0000-000000000000}    0    0    AutomaticUpdates    Success    Content Install    Reboot completed.
    {A5400FF2-33ED-4A47-8409-13E5DFE16A6D}    2013-10-15 19:29:31:486-0700    1    147    101    {00000000-0000-0000-0000-000000000000}    0    0    ChkWuDrv    Success    Software Synchronization    Windows Update Client successfully detected 0 updates.
    {43C533EE-775D-445E-A652-06648B72DE65}    2013-10-15 19:29:49:702-0700    1    147    101    {00000000-0000-0000-0000-000000000000}    0    0    ChkWuDrv    Success    Software Synchronization    Windows Update Client successfully detected 0 updates.
    {D6AAAFFB-7F18-4A7E-B39D-1BA09CDC5E6D}    2013-10-15 19:30:05:744-0700    1    147    101    {00000000-0000-0000-0000-000000000000}    0    0    AutomaticUpdates    Success    Software Synchronization    Windows Update Client successfully detected 3 updates.
    {4E73B1C1-5BA2-415D-AB34-92F7AB3DB418}    2013-10-15 19:30:08:753-0700    1    147    101    {00000000-0000-0000-0000-000000000000}    0    0    ChkWuDrv    Success    Software Synchronization    Windows Update Client successfully detected 0 updates.
    {51248882-41AC-4E59-B813-87AD326310AD}    2013-10-15 20:00:05:044-0700    1    183    101    {DBD3B4E9-0357-47DA-8317-D0CF2163BFE6}    501    0    wusa    Success    Content Install    Installation Successful: Windows successfully installed the following update: Hotfix for Windows (KB2661796)
    {FB2B8E5E-442C-4E76-B23D-6A41B4324C9D}    2013-10-16 00:11:39:832-0700    1    148    101    {00000000-0000-0000-0000-000000000000}    0    c8000247    AutomaticUpdates    Failure    Software Synchronization    Windows Update Client failed to detect with error 0xc8000247.
    Lenovo Thinkpad W500, Intel (R), Windows 7, SP1, latest updates as of Oct 15
    (1) Checked Setting,  set to automatic update whenever, even changed to never update, rebooted the OS and changed back to automatic update and rebooted the OS.
    (2) Stopped Windows Update Services, renamed SoftwareDistribution folder and started the window update services and rebooted.
    (3) Ran MS FIXIT
    (4) Ran System File checker Scan (sfc /scannow)
    (5) Ran CHKDSK /F
    (6) Installed "Intel Rapid Storage Technology" drivers from Lenovo site
    (7) Ran Update for Windows 7 for x64-based Systems (KB971033)
    None of the above possible recommended solutions were able to fix the issue yet and now I am getting a message your Window is Not Genuine!
    Any help or guidance is appreciated.
    Solved!
    Go to Solution.

    The Lenovo System Update installed the "Intel Matrix Storage Manager driver 8.9.2.1002" right before the Windows Upgrade got broken. So in the Device Manager under IDE ATA/ATAPI Controllers, I choose Intel ICH9M-E/M SATA AHCI Controller, on the Driver Tab, I choose the option "Roll Back Driver" and after rolling back the driver and restarting the OS, now Windows Update is working like a Champ!
    The End!

  • DVD Burn fail, Sense Key = Hardware Error, Sense Code = 0x09, 0x01, TRACKING SERVO FAILURE, What could be the solution?

    DVD Burn fail, Sense Key = Hardware Error, Sense Code = 0x09, 0x01, TRACKING SERVO FAILURE, What could be the solution?

    There is only one option and that is to replace the drive. It is not expensive to perform the replacement yourself if you so choose.

  • Archive log missing on standby: FAL[client]: Failed to request gap sequence

    My current environment is Oracle 10.2.0.4 with ASM 10.2.0.4 on a 2 node RAC in production and a standby that is the same setup. I'm also running on Oracle Linux 5. Almost daily now an archivelog doesnt make it to the standby and oracle doesnt seem to resolve the gap sequence from the primary. If I stop and restart recovery it gets the logfile and continues recovery just fine. I have checked my fal_client and fal_server settings and they look good. The logs after this error do continue to get written to the standby but the standby wont continue recovery until I stop and restart recovery and it fetches this missing log.
    The only thing I know thats happening is that the firewall people are disconnecting any connections that are inactive for 60 minutes and recently did an upgrade that they are claiming didnt change anything:)  I dont know if this is causing this problem or not. Any thoughts on what might be happening?
    Error in standby alert.log:
    Tue Jun 29 23:15:35 2010
    RFS[258]: Possible network disconnect with primary database
    Tue Jun 29 23:15:36 2010
    Fetching gap sequence in thread 2, gap sequence 9206-9206
    Tue Jun 29 23:16:46 2010
    FAL[client]: Failed to request gap sequence
    GAP - thread 2 sequence 9206-9206
    DBID 661398854 branch 714087609
    FAL[client]: All defined FAL servers have been attempted.
    Error on primary alert.log:
    Tue Jun 29 23:00:07 2010
    ARC0: Creating remote archive destination LOG_ARCHIVE_DEST_2: 'WSSPRDB' (thread 1 sequence 9265)
    (WSSPRD1)
    ARC0: Transmitting activation ID 0x29c37469
    Tue Jun 29 23:00:07 2010
    Errors in file /u01/app/oracle/admin/WSSPRD/bdump/wssprd1_arc0_14024.trc:
    ORA-03135: connection lost contact
    FAL[server, ARC0]: FAL archive failed, see trace file.
    Tue Jun 29 23:00:07 2010
    Errors in file /u01/app/oracle/admin/WSSPRD/bdump/wssprd1_arc0_14024.trc:
    ORA-16055: FAL request rejected
    ARCH: FAL archive failed. Archiver continuing
    Tue Jun 29 23:00:07 2010
    ORACLE Instance WSSPRD1 - Archival Error. Archiver continuing.
    Tue Jun 29 23:00:41 2010
    Redo Shipping Client Connected as PUBLIC
    -- Connected User is Valid
    Tue Jun 29 23:00:41 2010
    FAL[server, ARC2]: Begin FAL archive (dbid 0 branch 714087609 thread 2 sequence 9206 dest WSSPRDB)
    FAL[server, ARC2]: FAL archive failed, see trace file.
    Tue Jun 29 23:00:43 2010
    Errors in file /u01/app/oracle/admin/WSSPRD/bdump/wssprd1_arc2_14028.trc:
    ORA-16055: FAL request rejected
    ARCH: FAL archive failed. Archiver continuing
    Tue Jun 29 23:00:43 2010
    ORACLE Instance WSSPRD1 - Archival Error. Archiver continuing.
    Tue Jun 29 23:01:16 2010
    Redo Shipping Client Connected as PUBLIC
    -- Connected User is Valid
    Tue Jun 29 23:15:01 2010
    Thread 1 advanced to log sequence 9267 (LGWR switch)
    I have checked the trace files that get spit out but they arent anything meaningful to me as to whats really happening. Snipit of the trace file:
    tkcrrwkx: Starting to process work request
    tkcrfgli: SRL header: 0
    tkcrfgli: SRL tail: 0
    tkcrfgli: ORL to arch: 4
    tkcrfgli: le# seq thr for bck tba flags
    tkcrfgli: 1 359 1 2 0 3 0x0008 ORL active cur
    tkcrfgli: 2 358 1 0 1 1 0x0000 ORL active
    tkcrfgli: 3 361 2 4 0 0 0x0008 ORL active cur
    tkcrfgli: 4 360 2 0 3 2 0x0000 ORL active
    tkcrfgli: 5 -- entry deleted --
    tkcrfgli: 6 -- entry deleted --
    tkcrfgli: 7 -- entry deleted --
    tkcrfgli: 8 -- entry deleted --
    tkcrfgli: 9 -- entry deleted --
    tkcrfgli: 191 -- entry deleted --
    tkcrfgli: 192 -- entry deleted --
    *** 2010-03-27 01:30:32.603 20998 kcrr.c
    tkcrrwkx: Request from LGWR to perform: <startup>
    tkcrrcrlc: Starting CRL ARCH check
    *** 2010-03-27 01:30:32.603 66085 kcrr.c
    Beginning controlfile transaction 0x0x7fffd0b53198 [kcrr.c:20395 (14011)]
    *** 2010-03-27 01:30:32.645 66173 kcrr.c
    Acquired controlfile transaction 0x0x7fffd0b53198 [kcrr.c:20395 (14024)]
    *** 2010-03-27 01:30:32.649 66394 kcrr.c
    Ending controlfile transaction 0x0x7fffd0b53198 [kcrr.c:20397]
    tkcrrasgn: Checking for 'no FAL', 'no SRL', and 'HB' ARCH process
    # HB NoF NoS CRL Name
    29 NO NO NO NO ARC0
    28 NO YES YES NO ARC1
    27 NO NO NO NO ARC2
    26 NO NO NO NO ARC3
    25 YES NO NO NO ARC4
    24 NO NO NO NO ARC5
    23 NO NO NO NO ARC6
    22 NO NO NO NO ARC7
    21 NO NO NO NO ARC8
    20 NO NO NO NO ARC9
    Thanks.
    Kristi

    It's the network that's messing up; unlikely due to firewall timeout as it waits for 60 minutes and you are switching every 15 minutes. There may be some other network glitch that needs rectified.
    In any case - arch file missing/ corrupt / halfway through - FAL setting should have refetched the problematic archive log automatically.
    As many had suggested already, the best way to resolve RFS issues I believe is to use real-time apply by configuring standby redo logs. It's very easy to configure it and you can opt for real-time apply even in max-performance mode that you are using right now.
    Even though you are maintaining (I guess) 1-1 between primary & standby instances, you can provide both primary instances in fal_server (like fal_server=string1,string2). See if that helps.
    lastly, check if you are having simiar issue at other times as well that might be getting rectified automatically as expected.
    col message for a80
    col time for a20
    select message, to_char(timestamp,'dd-mon-rr hh24:mi:ss') time
    from v$dataguard_status
    where severity in ('Error','Fatal')
    order by timestamp;
    Cheers.

  • ISE Problem: EAP-TLS failed SSL/TLS handshake because of an unknown CA in the client certificates chain

    Hello, I´m stucked with this problem for 3 weeks now.
    I´m not able to configure the EAP-TLS autentication.
    In the "Certificate Store" of the ISE server I have Installed the Root, policy and the Issuing certificates as "trust for client authentication",and in the Local store I have a certificate issuing for the same issuing authority which sign the thw client ones.
    The ISE´s certificate has been issued with the "server Authentication certificate" template.
    The clients have installed the certificates  also the certificate chain.
    When I try to authenticate the wireless clients I allways get the same error: "     Authentication failed : 12514 EAP-TLS failed SSL/TLS handshake because of an unknown CA in the client certificates chain"
    and "OpenSSLErrorMessage=SSL alert
    code=0x230=560 ; source=local ; type=fatal ; message="Unknown CA - error self-signed certificate in chain",OpenSSLErrorStack=  1208556432:error:140890B2:SSL routines:SSL3_GET_CLIENT_CERTIFICATE:no certificate returned:s3_srvr.c:2720"
    I don´t know what else can I do.
    Thank you
    Jorge

    Hi Rik,
    the Below are the certificate details
    ISE Certificate Signed by XX-CA-PROC-06
    User PKI Signed by XX-CA-OTHER-08
    In ISE certificate Store i have the below certificates
    XX-CA-OTHER-08 signed by XX-CA-ROOT-04
    XX-CA-PROC-06 signed by XX-CA-ROOT-04
    XX-CA-ROOT-04 signed by XX-CA-ROOT-04
    ISE certificate signed by XX-CA-PROC-06
    I have enabled - 'Trust for client authentication' on all three certificates
    this is unchecked - 'Enable Validation of Certificate Extensions (accept only valid certificate)'
    when i check the certificates of current user in the Client PC this is how it shows.
    XX-CA-ROOT-04 is listed in Trusted root Certification Authority
    and XX-CA-PROC-06 and XX-CA-OTHER-08  are in Intermediate Certificate Authorities

  • 12520 EAP-TLS failed SSL/TLS handshake because the client rejected the ISE local-certificate

    Hi guys,
    I have root CA and intermediate CA in ISE local certificate store trusted for client authentication.
    I have imported both root ca and client certificate in the device I want to authenticate, but ISE keeps spitting out this error :
    12520 EAP-TLS failed SSL/TLS handshake because the client rejected the ISE local-certificate

    Refer the link for troubleshooting in page no 22 the issue is mentioned, check it: http://www.cisco.com/c/dam/en/us/solutions/collateral/enterprise/design-zone-security/howto_81_troubleshooting_failed_authc.pdf

  • IAS and CTA 802.1x wired client?

    Hi,
    We have IAS working with 802.1X authentication. All is good except when we enable dynamic VLAN assignment we come across the Winlogon issue as per MS KB article 935638.
    We do however have available the CTA 802.1X wired client. From what I have read though it requires ACS due to use of EAP-FAST. Is this correct or is there some way I can get CTA 802.1X wired client working with MS IAS RADIUS?
    Thank you

    You will have to use ACS for authenticating using EAP-FAST for CTA 802.1x wired clients. It is not possible to get CTA 802.1X wired client working with MS IAS RADIUS.

  • Warning: untrusted X11 forwarding setup failed: xauth key data not generate

    Upon connecting to a RedHat Enterprise Linux server via ssh -X I get the following:
    Warning: untrusted X11 forwarding setup failed: xauth key data not generated
    Warning: No xauth data; using fake authentication data for X11 forwarding.
    I have previously (as in last week, ending 11/1/2008) been able to use x11 forwarding from the machine I'm trying to connect to. This problem also occurs with other servers, meaning it must be a problem with my local machine. Any suggestions are welcome.

    I get that if I use
    ssh -Y ...
    but NOT with -X.
    Do you have a $HOME/.ssh/config or /etc/ssh_config file that is specifying ForwardX11Trusted?
    Mostly I ignore the message when I get it as, my X11 forwarding works OK, AND I'm in an environment where my fellow employees could do much naster things to me (and get fired for it), than spoofing my X11 sessions.

Maybe you are looking for

  • A few questions about Arrays and Array Methods.

    I have 2 dimentional arrays in a number of classes, and I wish to pass them about as variables, however, I can only seem to send int[], rather than int[][]. Gives me some compile errors. Another thing. How do i get the length of an array? I've tried:

  • Can't WATCH videos ONLINE.why?

    i cant watch online videos in my NOKIA 6303 classic.. any help?

  • Logic Express 9 won't intall on new iMac

    My copy of Logic Express 9 seems to install OK on my new iMac 27in i7 BUT when I then search for it on HDD its no where to be found ?

  • Importing keyword list from Photoshop CS1 is possible

    Amongst all this gloom on a more positive note I thought people might be interested to know that I have successfully managed to import my long keywords list from Photoshop CS1 into the keywords hud. It is fiddly and I'm sure there must be a more grac

  • Run time error equals shortdumps

    Hi ALL, While monitoring  SM21 & ST22 , we crosscheck that, NO of "run time errors" in SM21 which should match equal  to the  NO of "short dumps" in ST22 for that   particular date. Today i am getting 9 run time errors & 8 short dumps. 1 run time err