Front End Services won't start with new cert, SChannel error about hostname

We have an existing Lync 2013 Enterprise system set up, and many of the servers are using certs issues by our local CA. I want to move several of the certs to third-party certificates so that non-domain machines can connect. The first change I'm making is
on our Edge pool. However, I'm having an issue. Here are the details:
Our internal domain space is int.domain.com. Our external domain space is domain.com. Our Lync FE server is LS01.int.pool.com and our FE pool is pool01.int.domain.com. I have generated a CSR and requested a certificate from Globalsign with the following
characteristics:
SN: pool01.int.domain.com
SAN: pool01.int.domain.com
SAN: domain.com (wildcard)
SAN: int.domain.com (wildcard)
After applying the new cert using the topology builder, I've rebooted and the Lync Front-End Server service will no longer start. The following SChannel error is in the event logs:
The certificate received from the remote server does not contain the expected name. It is therefore not possible to determine whether we are connecting to the correct server. The server name we were expecting is ls01.int.domain.com. The SSL connection request
has failed. The attached data contains the server certificate.
After reverting back to the original local CA cert, the services start. The local cert has a ton of individual SANs set up but I was under the impression that the wildcard SANs were supported and would be ok for the hostnames.
Why is it looking for my FE server name and not the pool? Is this an issue with my deployment, or is it with the cert? I'm not sure where to go from here.

Hey Matt,
As mentioned above wildcards are only supported for Lync web services such as lyncdiscover, dialin and meeting URL's. It is OK to have wildcards in the certificates SAN, but you must also specifically include the following:
SN: pool01.int.domain.com (SN must be pool)
SAN: pool01.int.domain.com (pool must also be included in SAN)
SAN: lync-fe-001.int.domain.com (the machine name of your front end server)
This should solve the issue for you.
Andrew Morpeth
Lync Server Specialist - Auckland, NZ
Check out my blog

Similar Messages

  • Lync Front-end service won't start

    Hello everybody
    I have this error when a I try to start Lync front-end service:
    Failed starting a worker process.
    Process: 'C:\Program Files\Microsoft Lync Server 2013\Server\Core\RtcHost.exe'  Exit Code: C3E8302D!_HRX! (The worker process failed to initialize itself in the maximum allowable time.!_HRM!).
    Cause: This could happen due to low resource conditions or insufficient privileges.
    Resolution:
    Try restarting the server. If the problem persists contact Product Support Services.
    event id: 12330 source LS Server
    and 
    An exception caused the process to stop.
    Exception Details. System.ApplicationException: Failed to start Fabric Pool Manager.
       at Microsoft.Rtc.AppDomainHost.Launcher.Initialize(String[] args)
       at Microsoft.Rtc.AppDomainHost.Launcher.Main(String[] args)
    Cause: Check the eventlog description.
    Resolution:
    Examine prior event log entries to find and resolve the problem. If the problem persists contact product support.
    event ID 500006 Source LS AppDomain Host Process
    When I try this powershell command  Reset-CsPoolRegistrarState -ResetType QuorumLossRecovery -poolfqdn poolfqdn
    I have this message
    Reset-CsPoolRegistrarState : Could not connect to any server in Pool lync2013servername during Phase 1.
    At line:1 char:1
    + Reset-CsPoolRegistrarState -ResetType QuorumLossRecovery
    + ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
        + CategoryInfo          : InvalidOperation: (:) [Reset-CsPoolRegistrarState], Exception
        + FullyQualifiedErrorId : Error resetting fabric state. For details, see inner exception.,Microsoft.Rtc.Management.Hadr.ResetPoolFabric 
       StateCmdlet
    Can you help me please

    Have you check your Sql database? Maybe a problem with correct accessing the SQL Database.
    How looks you Lync pool? Enterprise, Standard, how much FE server?
    regards Holger Technical Specialist UC

  • Front End Service is not starting

    Hi ,
    Any one can help me to resolve this issue.
    I have one enterprise edition front end server .if i try to start the front end service it give the following error
    Server startup is being delayed because fabric pool manager is initializing.
    Cause: This is normal when Pool is bootstrapped and indicates that the Front-End is waiting for a quorum of other Front-Ends to be started.
    Resolution:
    If this event recurs persistently, ensure that 85% of the Front-Ends configured for this Pool are up and running. For 2 or 3 machine Pools, initial cold-start of the Pool requires all machines to be started. If multiple Front-Ends have been recently decommissioned,
    run Reset-CsPoolRegistrarState -ResetType QuorumLossRecovery to enable the Pool to recover from Quorum Loss and make progress.

    If understand the problem Correctly You one Lync enterprise edition installed is that right?
    If yes Please note For a recommended Lync Server 2013 EE pool deployment, there should be at least three Lync Server 2013 front-end servers in the EE pool.
    http://technet.microsoft.com/en-us/library/gg412996.aspx
    We recommend that all your Enterprise Edition Front End pools include at least three Front End Servers
    Also refer Why 3 server pool?
    http://social.technet.microsoft.com/Forums/lync/en-US/1e277415-01b0-4123-a5bc-260909368d5b/why-3-server-pool?forum=lyncdeploy
    If you just want one Lync server please install Lync Standard Edition
    Front End Pools with Two Front End Servers
    We do not recommend deploying a Front End pool that contains only two Front End Servers. If you do ever need to deploy such a pool, follow these guidelines:
    If one of the two Front End Servers goes down, you should try to bring the failed server back up as soon as you can. Similarly, if you need to upgrade one of the two servers, bring it back online as soon as the upgrade is finished.
    If for some reason you need to bring both servers down at the same time, do the following when the downtime for the pool is finished:
    The best practice is to restart both Front End Servers at the same time.
    If the two servers cannot be restarted at the same time, you should bring them back up in the reverse order of the order they went down.
    If you cannot bring them back up in that order, then use the following cmdlet before bringing the pool back up:.
    Reset-CsPoolRegistrarState -ResetType QuorumLossRecovery -PoolFQDN <FQDN>
    Please remember, if you see a post that helped you please click ;Vote As Helpful" and if it answered your question please click "Mark As Answer"
    Regards Edwin Anthony Joseph

  • Satellite Pro 460 won't start with new hard drive in

    I recently got a Satellite Pro 460 but it had no hard drive in.
    It starts great with no drive in but as soon as I put a brand new hard drive in it won't start.
    I thought that it might be to new a hard drive so I took my old working drive out my old Toshiba Satellite and still it won't start.
    Any one got any ideas why this is and what can i do about it

    It sounds like 80GB is too large for that model, I really doubt the BIOS and Chipset can support more than 8GB HDD. 8GB may not even work.
    Here is some information regarding different HDD modes and limitations: http://www.adminxp.com/hardware/index.php?aid=129
    504MB - limitation where the system is limited by the compatibility with the values of the BIOS system and the ATA interface by help of using the CHS mode. This limitation is valid for older computers 286/386/486. (1024 cyl 16 heads x 63sectors/track x 512 = 528,482,304bytes - 504 MB). In many cases special programs will help (Disk Ontrack Manager - Seagate, Disk Wizard - WD). Some operating systems can have problems with this software support and can have higher requirements on your knowledge of the OS and used programs.
    2GB - Limitation of the maximal value of the FAT16 file system partition for DOS and Windows 9x. Some older computers cannot address more than 4095 cylinders (4,095 x 16 x 63x 512 - 2,113,413,120 bytes)
    4GB Limitation of Windows NT - Partition with the FAT16 system cannot be higher than 4GB - Fdisk cannot be used for creating, but the Disk manager is used (Disk management in Windows 2000)
    8GB - Limitation of the BIOS system. For the support of larger capacities you need extended functions of the BIOS system. Limitations valid for the x86 computers and some motherboards with Pentium and Pentium II processors. Some other operating systems must know how to use the extended BIOS functions (Extended Interrupt 13). We can use Windows NT 4.0 as an example where you need an updated disk driver or the Service Pack. (OS - DOS 6.xx and lower, Windows 3.x and lower and some other older OS do not have the support of the Ext. Int13).
    8 GB - Limitation of the FDISK program in the DOS 6.22 OS.
    ?? GB - Possible problem with disks larger than 67GB under Windows 9x... See article WD800
    32GB - (65535 x 16 x 63 x 512 - 33,822,351,360 bytes) other limitation of the BIOS system.
    68GB - Possible problem with disks larger than 67GB under Windows 9x... See article WD800
    137GB - Limit for the ATA specifications (28-bit addressing for particular sectors - 268435455 sectors - 137,438,952,960 bytes)
    2,2 TBytes - 32-bit addressing used by new operating systems (in Windows 98 by help of the FAT32 file system).
    144 PetaBytes - a limit for new ATA specification using 48-bit addressing, in peparation. Maxtor, Microsoft, VIA, Compaq and other companies under name Big Drives participate the development. The standard should be implemented and authorized by the ANSI NCITS T13 Technical Committee organization (www.t13.org) in the prepared ATA/ATAPI-6 standard (see www.maxtor.com/bigdrive)

  • Sync on desktop manager won't start with new 9700

    I am attaching my 9700, with a USB cable, to my laptop. The Desktop Manager software opens but it will not start the sync'ing process with my device.
    - the little "check" box - "automatically synchronize device and computer when USB connected" is switched on
    - I am using the latest version of Desktop Manager
    - the "Synchronize" tab is in grey. It's grey'ed out. When my curser hovers over "Synchronize" it won't light up, as in, it won't let me press the Synchronize button to initiate the process.
    - my 9700 is brand new. I had no synchronizing problems with my previous model, the Curve.
    - my laptop is a great device, I don't currently, nor haven't had, any issues with it in the past - DELL D420 Latitude. I seem to have all the drivers I need
    - I am running Windows XP
    - I am not linking to a server at work. My Blackberry is set is purely a directly link from the 9700 device, to my computer, and syncs with the calendar, address book and tasks list (MS Outlook 2003 from MS Office)
    - my new 9700 - I bought it 2weeks ago. It did sync in the beginning. About three times successfully. But not now obviously.
    - on my Windows bar at the bottom of my computer screen it pops up "new hardware added" and the 9700 device is no longer described by its identity number (PIN ref?), it says "new hardware added, 'memory device'"
    - I've searched through the Blackberry help pages and so far, all I can come up with is that my computer can't seem to recognise now, for some unknown reason, that it is connected to my 9700. Blackberry help suggested I go to the "pairing" pages of the Help guide, but I thought "pairing" was only a subject that involves Bluetooth activities. Not a USB cable connection.
    Anyone got any ideas?

    Hey Graeme0309,
    If you disconnect the BlackBerry from your computer and open Desktop Manager, are you able to open Synchronize?
    What version of BlackBerry Desktop Manager are you using?
    -ViciousFerret
    Come follow your BlackBerry Technical Team on Twitter! @BlackBerryHelp
    Be sure to click Like! for those who have helped you.
    Click  Accept as Solution for posts that have solved your issue(s)!

  • Tomcat 5.5 service won't start with jmxremote.authenticate=true

    The Tomcat5 service (5.5.17) starts fine on XP if I set com.sun.management.jmxremote.authenticate=false in the Tomcat5W.exe (gui for setting properties of the service). However, when I set authenticate=true (or omit it), I get the error:
    "Could not start the Apache Tomcat Tomcat5 service on Local Computer. Error 1067: The process terminated unexpectedly." I have created a jmx.remote.password file from the jmx.remote.password.template. I left it in the default location in %JRE_HOME%\lib\management. I also set the file properties so that I am the only user on the security tab, and I have full control. Any ideas?

    Does using Tomcate5W.exe require uninstalling and then re-installing the service to take affect?
    I had a similar issue recently, but had the requirement that I could not uninstall and re-install the service. So I had to use the Tomcat5 service updater via command line. The main problem I ran into was getting the security set properly on the password file. Also, I did not use the default location for the files, but put them in the tomcat directory. Here's a summary of what I did
    1.     Stop the service.
    2.     run the command �service.bat remove� from the tomcat bin directory.
    3.     add the following java options to service.bat
    -Dcom.sun.management.jmxremote
    -Dcom.sun.management.jmxremote.port=1092
    -Dcom.sun.management.jmxremote.ssl=false
    -Dcom.sun.management.jmxremote.authenticate=true
    -Dcom.sun.management.jmxremote.password.file=c:\tomcat\Tomcat 5.5\conf\jmxremote.password
    -Dcom.sun.management.jmxremote.access.file=c:\tomcat\Tomcat 5.5\conf\jmxremote.access
    4.     Fllow the instructions to secure the password file: http://java.sun.com/j2se/1.5.0/docs/guide/management/security-windows.html
    5.     start the service
    I was not able to remove the service, so I actually did this:
    The following will update the windows service named Tomcat5 and add the jvm options to enable jmx remote monitoring with password authentication. Replace Tomcat5 with your service name, and also, you can change the listen port to your desired port.
    C:\>tomcat5 //US//Tomcat5 --JvmOptions="-Dcom.sun.management.jmxremote;-Dcom.sun.management.jmxremote.port=1092;-Dcom.sun.management.jmxremote.ssl=false;-Dcom.sun.management.jmxremote.authenticate=true;-Dcom.sun.management.jmxremote.password.file=c:\tomcat\Tomcat 5.5\conf\jmxremote.password;-Dcom.sun.management.jmxremote.access.file=c:\tomcat\Tomcat 5.5\conf\jmxremote.access"
    Lastly, I followed exactly these steps to secure the password file (which it seems you did).
    http://java.sun.com/j2se/1.5.0/docs/guide/management/security-windows.html
    - Alper

  • Pavilion HPe-510t won't start with new gtx660

    I recently got a new PSU and GPU to upgrade the PC's gaming ability. PC came with a gt440, and I am upgrading to a gtx660. Power supply was upgraded to a Corsair 750M. The problem is when I go to start I get to the blue HP start screen and it just sits there. There are three beeps spread out by ~30 seconds each, and then the screen goes black with a blinking cursor icon in the corner. The PC came with windows 7 so it is not an UEFI problem.  Everything works fine when the old card is put back in.
    Can anyone help me with this?

    Hi,
    Trying running a full set of diagnostics without the gtx660 installed to make sure that your hardware is good.
    It could be an incompatibilty with the video card and the UEFI level in your PC.  Your PC does have partial UEFI support.  Some NVIDIA 660s may have shipped with a video bios that require full UEFI support which your PC lacks.   You will have to check that possible issue with the video card manufacturer.
    I did update the video bios on my GTX660 to allow for full UEFI support. I was informed by the manufacturer that my particular video card was not shipped with the full UEFI video bios support as it would not work in older PCs that were not a full UEFI support.
    There is a bios update listed for your PC so be sure that you are at that level.
    Try clearing the CMOS and see if that solves your problem.
    HP DV9700, t9300, Nvidia 8600, 4GB, Crucial C300 128GB SSD
    HP Photosmart Premium C309G, HP Photosmart 6520
    HP Touchpad, HP Chromebook 11
    Custom i7-4770k,Z-87, 8GB, Vertex 3 SSD, Samsung EVO SSD, Corsair HX650,GTX 760
    Custom i7-4790k,Z-97, 16GB, Vertex 3 SSD, Plextor M.2 SSD, Samsung EVO SSD, Corsair HX650, GTX 660TI
    Windows 7/8 UEFI/Legacy mode, MBR/GPT

  • Premiere CS5 won't start with new UAD drivers

    Any workarounds? Can I change my vst folder prior to starting the program?
    Windows 7 64 bit

    I would say roll back a driver as CS5 is quite old and it was working ok.

  • SP1 for Exchange 2013 install fails with ECP virtual directory issues and now transport service won't start and mail is unavailable

    SP1 for Exchange 2013 install failed on me with ECP virtual directory issues:
    Error:
    The following error was generated when "$error.Clear();
              $BEVdirIdentity = $RoleNetBIOSName + "\ecp (name)";
              $be = get-EcpVirtualDirectory -ShowMailboxVirtualDirectories -Identity $BEVdirIdentity -DomainController $RoleDomainController -ErrorAction SilentlyContinue;
              if ($be -eq $null)
              new-EcpVirtualDirectory -Role Mailbox -WebSiteName "name" -DomainController $RoleDomainController;
              set-EcpVirtualdirectory -Identity $BEVdirIdentity -FormsAuthentication:$false -WindowsAuthentication:$true;
              set-EcpVirtualdirectory -Identity $BEVdirIdentity -InternalUrl $null -ExternalUrl $null;
              . "$RoleInstallPath\Scripts\Update-AppPoolManagedFrameworkVersion.ps1" -AppPoolName:"MSExchangeECPAppPool" -Version:"v4.0";
            " was run: "The virtual directory 'ecp' already exists under 'server/name'.
    Parameter name: VirtualDirectoryName".
    Error:
    The following error was generated when "$error.Clear();
              $BEVdirIdentity = $RoleNetBIOSName + "\ECP (name)";
              $be = get-EcpVirtualDirectory -ShowMailboxVirtualDirectories -Identity $BEVdirIdentity -DomainController $RoleDomainController -ErrorAction SilentlyContinue;
              if ($be -eq $null)
              new-EcpVirtualDirectory -Role Mailbox -WebSiteName "name" -DomainController $RoleDomainController;
              set-EcpVirtualdirectory -Identity $BEVdirIdentity -FormsAuthentication:$false -WindowsAuthentication:$true;
              set-EcpVirtualdirectory -Identity $BEVdirIdentity -InternalUrl $null -ExternalUrl $null;
              . "$RoleInstallPath\Scripts\Update-AppPoolManagedFrameworkVersion.ps1" -AppPoolName:"MSExchangeECPAppPool" -Version:"v4.0";
            " was run: "The operation couldn't be performed because object 'server\ECP (name)' couldn't be found on 'DC0xx.domain.com'.".
    Error:
    The following error was generated when "$error.Clear();
              $BEVdirIdentity = $RoleNetBIOSName + "\ECP (name)";
              $be = get-EcpVirtualDirectory -ShowMailboxVirtualDirectories -Identity $BEVdirIdentity -DomainController $RoleDomainController -ErrorAction SilentlyContinue;
              if ($be -eq $null)
              new-EcpVirtualDirectory -Role Mailbox -WebSiteName "name" -DomainController $RoleDomainController;
              set-EcpVirtualdirectory -Identity $BEVdirIdentity -FormsAuthentication:$false -WindowsAuthentication:$true;
              set-EcpVirtualdirectory -Identity $BEVdirIdentity -InternalUrl $null -ExternalUrl $null;
              . "$RoleInstallPath\Scripts\Update-AppPoolManagedFrameworkVersion.ps1" -AppPoolName:"MSExchangeECPAppPool" -Version:"v4.0";
            " was run: "The operation couldn't be performed because object 'server\ECP (name)' couldn't be found on 'DC0xx.domain.com'.".
    !! And now transport service won't start and mail is unavailable !!
    Any help would be appreciated.
    I have removed the ecp site from default site and attempting to rerun SP1 now. I do not have high hopes. :(

    Hi,
    Thanks for your response.
    From the error description, you need to manually remove the ECP with IIS manager in both the Default Web Site and the Exchange Back End firstly. And then continue the upgrade to check the result.
    Hope this can be helpful to you.
    Best regards,
    Amy Wang
    TechNet Community Support

  • The Lync Server Front-End service terminated with service-specific error %%-1008124893.

    Hello, everyone
    I've installed Lync Server 2010. There was no error during installation. But when i start Lync Server Front End Server, i'm getting following error:
    The Lync Server Front-End service terminated with service-specific error %%-1008124893.
    In event viewer:
    The evaluation period for Microsoft Lync Server 2010  has expired. Please upgrade from the evaluation version to the fully licensed version of the product. Look at help for Setup.exe to learn how to upgrade from evaluation version to the licensed version.
    Cause: The evaluation period for Microsoft Lync Server 2010  has expired.
    I've upgraded Lync Server according to http://technet.microsoft.com/en-us/library/gg521005.aspx?ppud=4
    Also I've installed all Lync Server updates.
    But I still could not start Lync Front End Sever. How can I solve this problem?
    Thanks

    Hi,
    Can you try to run
    start-cswindowsservice -report c:\report.html
    and post the report so we can have more information about your problem ?
    Regards,
    Adrian TUPPER - ABC Systemes - http://thelyncexperience.blog.com/ If answer is helpful, please hit the green arrow on the left, or mark as answer Thank you

  • Design Question: Can I use Rest-CsPoolRegisterState command in order start Front End Service when Quorum is lost and less than 85% of FES are available?

    Hi, 
    Assuming below setup for Enterprise edition Lync 2013
    Single Pool Stretched architecture with 4 FES servers
    Site A Data Center
    Site B Data Center
    FES
    2
    2
    SQL
    1 Primary
    1 Mirror
    Fact: In a situation when we lose network connectivity to Site A DC, and due to less than 50% FES servers, Quorum will be lost and as a result Front End Service will stop after 5 minutes. 
    The question is, would I be able to do a manual intervention by using this command
    Reset-CsPoolRegistrarState –PoolFqdn <pool name fqdn> –ResetType QuorumLossRecovery , and start FES with just 2 FES servers in Site B DC and 1 SQL
    Server?
    The reason I am asking this question is because it is mentioned in one of the Lync manuals that at least 85% of the servers must be available to recover once the Quorum has lost. The same manual also mentions to use above
    mentioned command in order to recover from Quorum Loss despite the fact that the lost FES servers are still not available.
    Thanks in Advance

    Hi,
    In Lync server 2013 Stretched pools are not supported for the Front End, Edge, Mediation, and Director server roles. It need two Lync pools.
    If one pool fail to connect, An administrator can declare an emergency and fail over the pool to the backup pool.  That is done by using the:
    Invoke-CsPoolFailover –PoolFQDN <Pool fqdn> –DisasterMode –Verbose
    More details:
    http://blog.avtex.com/2012/07/26/understanding-lync-2013-server-failover/
    Note: Microsoft is providing this information as a convenience to you. The sites are not controlled by Microsoft. Microsoft cannot make any representations regarding the quality, safety, or suitability of any software or information
    found there. Please make sure that you completely understand the risk before retrieving any suggestions from the above link.
    Best Regards,
    Eason Huang
    Eason Huang
    TechNet Community Support

  • Front-End Service Starup Error: Store procedure to GET progress vector failed.

    Hi,
    We have a two front end servers in our Lync deployment and I'm getting an interesting error message on one of the servers when the "Lync Server Front-End Service" is starting up. All the services on that server will eventually start but I'm pretty
    sure it's affecting users in some way.
    Here is the error message in the Event Viewer:
    Log Name:      Lync Server
    Source:        LS User Services
    Date:          2013-09-17 8:00:32 AM
    Event ID:      32194
    Task Category: (1006)
    Level:         Error
    Keywords:      Classic
    User:          N/A
    Computer:      BGC-VAN-LYNC2.domain.ca
    Description:
    Store procedure to GET progress vector failed.
    Execution Error: 0x00000000(ERROR_SUCCESS).
    Native Error: 8144.
    Error Details: [# [Microsoft][SQL Server Native Client 11.0][SQL Server]Procedure or function SyncReplicationGetProgressVector has too many arguments specified. #].
    Cause: This may indicate a problem with connectivity to local database or some unknown product issue.
    Resolution:
    Ensure that connectivity to local database is proper. If the error persists, please contact product support with server traces.
    Event Xml:
    <Event xmlns=>
      <System>
        <Provider Name="LS User Services" />
        <EventID Qualifiers="50158">32194</EventID>
        <Level>2</Level>
        <Task>1006</Task>
        <Keywords>0x80000000000000</Keywords>
        <TimeCreated SystemTime="2013-09-17T15:00:32.000000000Z" />
        <EventRecordID>16971</EventRecordID>
        <Channel>Lync Server</Channel>
        <Computer>BGC-VAN-LYNC2.domain.ca</Computer>
        <Security />
      </System>
      <EventData>
        <Data>0x00000000(ERROR_SUCCESS)</Data>
        <Data>8144</Data>
        <Data>[# [Microsoft][SQL Server Native Client 11.0][SQL Server]Procedure or function SyncReplicationGetProgressVector has too many arguments specified. #]</Data>
      </EventData>
    </Event>
    The error happens 15 times every minute, following with this event:
    Name:      Lync Server
    Source:        LS User Services
    Date:          2013-09-17 8:23:46 AM
    Event ID:      32189
    Task Category: (1006)
    Level:         Information
    Keywords:      Classic
    User:          N/A
    Description:
    The following Fabric service for routing groups have been closed:
    {F515134C-71B7-52FD-B0C3-6A9DB39CF750}
    {8A5D6B36-2A01-53DB-BC4E-3286C05E0836}
    {B35AAFC9-F6BF-5FFE-8C31-4AA5C36B2065}
    {69223418-78DC-5066-81A8-78E05914EC7B}
    {80414C96-1137-5DDC-8387-C3EA7A54B078}
    {641E6ABD-B862-55A1-B1B1-C83BC92D2F85}
    {1EA68EA4-77F7-5CFC-B781-0093CBC18403}
    {2FDE333D-FF7F-5D6A-B85B-93ADC1EAC12A}
    {A43BBA3A-8963-51C4-BD7A-19E1EC3DDFDB}
    {D3F4532F-61C8-5072-9B3B-3E2CCF15442F}
    {4449243E-5E96-56AC-AB6B-C5E785543542}
    {58B30261-65B6-5F6A-BC50-60F85782D052}
    {DB4B76B0-2510-5BF8-A7B1-8B37BD3AA7B9}
    {917CC217-966B-56AC-A912-97BA64BA13EB}
    Anyone knows what this is about and how to resolve this?
    Thanks,
    VH.

    Hi,
    Please try to reset registrar state:
    http://tsoorad.blogspot.in/2013/04/lync-2013-ee-pool-wont-start.html
    Note: Microsoft is providing this information as a convenience to you. The sites are not controlled by Microsoft. Microsoft cannot make any representations regarding the quality, safety, or suitability of any software or information found there. Please make
    sure that you completely understand the risk before retrieving any suggestions from the above link.
    Kent Huang
    TechNet Community Support

  • Password service won't start

    Following an unplanned hard restart of our server (Mac OS X 10.9.5, Server 3.2.2), the password service won't start, so our staff can't log into mail, calendars or file sharing.
    When I launch Open Directory, the main window has the message "Unable to load replica list", then it switches itself off after a minute or so.
    I've looked at the certificates in Server and they have the green tick so presumably are OK.
    DNS is working OK and running the command "sudo changeip -checkhostname" reports success.
    Here's the section of log that repeats every few seconds as PasswordService repeatedly starts up and exits:
    13/03/2015 20:55:00.617 com.apple.launchd[1]: (com.apple.PasswordService[5890]) Exited with code: 1
    13/03/2015 20:55:00.617 com.apple.launchd[1]: (com.apple.PasswordService) Throttling respawn: Will start in 10 seconds
    13/03/2015 20:55:02.540 xscertd[249]: Failed sending LookupCRLByCARecordName command to com.apple.xscertd.helper: The operation couldn’t be completed. (com.apple.certificateserver error 42005.)
    13/03/2015 20:55:08.708 com.apple.launchd[1]: (org.openldap.slapd[5894]) Exited with code: 1
    13/03/2015 20:55:08.708 com.apple.launchd[1]: (org.openldap.slapd) Throttling respawn: Will start in 7 seconds
    13/03/2015 20:55:10.206 xscertd-helper[5897]: ldap_search_ext_s returned -1 - Can't contact LDAP server when searching for bdb suffix, exiting
    13/03/2015 20:55:10.207 com.apple.launchd[1]: (com.apple.xscertd-helper[5897]) Exited with code: 1
    13/03/2015 20:55:10.207 com.apple.launchd[1]: (com.apple.xscertd-helper) Throttling respawn: Will start in 10 seconds
    13/03/2015 20:55:10.639 PasswordService[5901]: -[PasswordServerPrefsObject getSearchBase]: Unable to locate search base: -1 Can't contact LDAP server
    13/03/2015 20:55:10.639 PasswordService[5901]: -[PasswordServerPrefsObject loadXMLData]: Unable to locate passwordserver config record's plist attribute: -1 Can't contact LDAP server
    13/03/2015 20:55:10.640 PasswordService[5901]: -[PasswordServerPrefsObject getSearchBase]: Unable to locate search base: -1 Can't contact LDAP server
    13/03/2015 20:55:10.640 PasswordService[5901]: -[PasswordServerPrefsObject saveXMLData]: ldap_modify_ext_s of the passwordserver config record's plist attribute: -1 Can't contact LDAP server
    13/03/2015 20:55:10.684 PasswordService[5901]: int pwsf_GetPublicKey(char *): ldap_search_ext_s cn=authdata for Public Key returned -1
    13/03/2015 20:55:10.687 com.apple.launchd[1]: (com.apple.PasswordService[5901]) Exited with code: 1
    I have backups (both Time Machine and clones of the hard drive) that I could use to restore the corrupted bit of the configuration, if necessary, but I don't know what to restore.

    Many Open Directory problems can be resolved by taking the following steps. Test after each one, and back up all data before making any changes.
    1. The OD master must have a static IP address on the local network, not a dynamic address. It must not be connected to the same network with more than one interface; e.g., Ethernet and Wi-Fi.
    2. You must have a working DNS service, and the server's hostname must match its fully-qualified domain name. To confirm, select the server by name in the sidebar of the Server application window, then select the Overview tab. Click the Edit button on the Host Name line. On the Accessing your Server sheet, Domain Name should be selected. Change the Host Name, if necessary. The server must have at least a three-level name (e.g. "server.yourdomain.com"), and the name must not be in the ".local" top-level domain, which is reserved for Bonjour.
    3. The primary DNS server used by the server must be itself, unless you're using another server for internal DNS. The only DNS server set on the clients should be the internal one, which they should get from DHCP if applicable.
    4. If you have accounts with network home directories, make sure the URL's are correct in the user settings. A return status of 45 from the authorizationhost daemon in the log may mean that the URL for mounting the home directory was not updated after a change in the hostname.
    5. Only if you're still running Mavericks server, follow these instructions to rebuild the Kerberos configuration on the server.
    6. If you use authenticated binding, check the validity of the master's certificate. The common name must match the hostname and domain name. Deselecting and then reselecting the certificate in Server.app has been reported to have an effect in some cases. Otherwise delete all certificates and create new ones.
    7. Unbind and then rebind the clients in the Users & Groups preference pane. Use the fully-qualified domain name of the master.
    8. Reboot the master and the clients.
    9. Don't log in to the server with a network user's account.
    10. Disable any internal firewalls in use, including third-party "security" software.
    11. If you've created any replica servers, delete them.
    12. If OD has only recently stopped working when it was working before, you may be able to restore it from the automatic backup in /var/db/backups, or from a Time Machine snapshot of that backup.
    13. As a last resort, export all OD users. In the Open Directory pane of Server, delete the OD server. Then recreate it and import the users. Ensure that the UID's are in the 1001+ range.
    If you get this far without solving the problem, then you'll need to examine the logs in the Open Directory section of the log list in the Server app, and also the system log on the clients.

  • Microsoft Forefront Server Protection Eventing Service won't start?

    Hi Guys,
    When Forefront Protection for Exchange was integrated/enabled on our SBS 2008 server, Microsoft Forefront Server Protection Eventing Service won’t start. Even when we try to start it manually we are getting this message (see attached). During this attempt,
    we got these events in the event viewer. In this case, in order to have our email working, we have to temporarily disable Forefront. Any suggestion how to fix this? Please advise.
    Event 465
    Source: ESENT
    FSCEventing (9324) Corruption was detected during soft recovery in logfile C:\Program Files (x86)\Microsoft Forefront Protection for Exchange Server\Data\Incidents\inc.log. The failing checksum record is located at position END. Data not matching the log-file
    fill pattern first appeared in sector 450 (0x000001C2). This logfile has been damaged and is unusable.
    Event 301
    Source: ESENT
    FSCEventing (9324) The database engine has begun replaying logfile C:\Program Files (x86)\Microsoft Forefront Protection for Exchange Server\Data\Incidents\inc.log.
    Event 454
    Source: ESENT
    FSCEventing (9324) Database recovery/restore failed with unexpected error - 501.
    Event 1076
    Source: FSCEventing
    The Forefront Protection Eventing Service has stopped.
    Thank you very much!
    Arnel

    Hi Arnel,
    Based on error messages, it indicates a log file (inc.log) has become corrupted. Please restore the log file
    from a backup copy, and then check if this issue can be solved. For more details, please refer to the following article.
    Event Id 465
    Hope this helps.
    Best regards,
    Justin Gu

  • Can't Update to 10.0.1, Bonjour Service Won't Start--PLEASE help!

    All I want to do is update my iTunes but I cannot. It won't work from within iTunes, and when I try to do it manually it said "The Service Bonjour Service" won't start." In Services, I could not start it either, though I am admin.
    So I deleted Bonjour (from within the Control Panel), thinking that'd take care of it, but it did not. I still get ALL the same messages. I even tried re-installing Bonjour (bonjour64.msi), and I get the same "won't start" message. It's not my firewall--I set that to always allow.
    What is going on here? I've searched and searched, but to no avail (though they are plenty of Bonjour problems out there), and I really don't want to uninstall/reinstall iTunes, if that would even do it. I'm new to Apple, and this just makes no sense to me.
    Please, help?? THANKS in advance~

    There are remants of Bonjour in the program files, and I guess I could delete these to clean it up, but I doubt that would make the difference.
    Actually, that could make a difference. If there is leftover componentry from the previous version still on the PC when the new version tries to install, the version mismatch could cause trouble with the new service starting. That could then roll back the attempted install.
    There's a bunch of different stuff on 64-bit systems for BonJour (there's both 64-bit and 32-bit componentry stashed on a 64-bit system. We'll also try a cleaner version of an uninstall than the Apple instructions provide.
    In Computer, open your C drive (or whichever drive your program files are installed on).
    Open the "Program Files" folder.
    Right-click on the "BonJour" folder (if it still exists) and select "Delete".
    Go back into your C drive (or whichever drive your program files are installed on).
    Open the "Program Files (x86)" folder.
    Right-click on the "BonJour" folder (if it still exists) and select "Delete".
    Go back into your C drive (or whichever drive your operating system is installed on).
    Open the "Windows" folder.
    Open the "System32" folder.
    Right-click on the dnssd.dll and dns-sd.exe files (if they still exist), and select "Delete".
    Go back into the "Windows" folder.
    Open the "SysWOW64" folder.
    Right-click on the dnssd.dll and dns-sd.exe files (if they still exist), and select "Delete".
    Empty your recycle bin.
    Restart the PC and try another BonJour install. Any better luck restarting the service this time?

Maybe you are looking for

  • How do I get a new AdMin User to have same desktop with all apps?, How do I get a new AdMin User to have same desktop with all apps?

    I recently switched from a MacBook Air to MacBook Pro.  When I transferred my Adobe Creative Cloud account to the MBP, I started having "User Privileges" problems with Photoshop. Adobe Support suggested I create a new AdMin User.  I did that, but whe

  • How to decide the last page in smartforms

    Hi experts, I want to display a signature block only in the last page, can anybody tells me the perfect way to decide when it's the last page? Now I'm using a window with the check EVENT "Only Before End of Main Window", a flag is set in this window,

  • Can't edit network passwords. Networks locked?

    Running Leopard on 1.5GHz PB. Airport recognizes wireless router but can't get online or connect to server. It requires WPA2 personal login but when I select advanced options in network preferences and select the network I want to edit, it appears wi

  • Error when inserting more than 500 characters

    Hello all, I am not sure if I should be posting here or in the Flex Forum, so I apologize ahead of time if I am in the wrong place. I am Using a Flex frontend and a ColdFusion backend to edit data in a simple Access Database (for testing). I have a C

  • HTTPS access and device id[PIN]

    I am not able to extract the Device-ID from HTTP header.I am accessing my https corporate site.when I try with HTTP ,i get the Device-id.But when I try accessing HTTPS I am not able to.I need this Device Id for further authentication of a blackberry