Ldasearch against Microsoft AD - authentication error

Hi,
I'm having a strange issue with ldapsearch against Microsoft AD.
I'm using this query:
ldapsearch -p 389 -h <ad_host> \
-D "CN=oraclesso,OU=Service Accounts,OU=Admin,DC=<domain>,DC=<domain>" \
-w "<the_correct_password>" -s sub -b "DC=<domain>,DC=<domain>" "(&(objectcategory=person)(objectclass=user)(iceNc=1)" dn
This query correctly returns the DNs I'm looking for on AD, but strangely ad the end of the command the following error message il also reported:
LDAP AuthenticationException javax.naming.AuthenticationException: [LDAP: error code 49 - 80090308: LdapErr: DSID-0C090334, comment: AcceptSecurityContext error, data 525, vece^@]
I've researched the "data 525" error and it means "user not found" and this is very strange because I'm sure that the "oraclesso" user exists on AD (this user is member of the Domain Admins group) and also I can successfully bind using that DN:
ldapbind -D "CN=oraclesso,OU=Service Accounts,OU=Admin,DC=<domain>,DC=<domain>" -h <ad_host> -p 389 -q
Please enter bind password: <the_correct_password>
bind successful
And if I use a wrong username I correctly get this message:
ldapbind -D "CN=<wrong_username>,OU=Service Accounts,OU=Admin,DC=<domain>,DC=<domain>" -h <ad_host> -p 389 -q
Please enter bind password: <a_wrong_password>
ldap_bind: Invalid credentials
ldap_bind: additional info: 80090308: LdapErr: DSID-0C090334, comment: AcceptSecurityContext error, data 52e, vece
If the "oraclesso" user doesn't exist on AD (as indicated by the "data 525" error) I should not get any result from the ldapsearch command or at least I should only get an authentication error message. Instead I'm getting the correct list of users plus the authentication error at the end. I cannot explain this.
This is preventing me from configuring the OID-AD integration because the initial bootstrap of the users is failing as the authentication fails.
Can you help?
Thank you

I assume the same user definitions will exist both in AD and internal store
If so can achieve as follows:
- define an i]dentity sequence. Select Password Based authentication method and select AD in list of "Authentication and Attribute Retrieval Search List". Select "Internal Users" in list of 'Additional Attribute Retrieval Search List". Can also select the option "If internal user/host not found or disabled then exit sequence and treat as "User Not Found" to ensure that only users defined in the internal store get access
- Select the defined Identity Sequence as result in the Identity Policy for the TACACS+ service
This means that when TACACS+ request is received, authentication will be performed against AD. If that succeeds then attributes will be retrieved for the internal user and can be used in policy

Similar Messages

  • Administrators accounts integration/authentication in ACS5.3 against Microsoft AD

    Hello security guru!
    Please advise me if I can authenticate users/administrators managing ACS5.3 via GUI and CLI against Microsoft AD. I think I heard it from someone from Cisco when a lot of improvements were introduced in ACS5.3 that I can do it. Doesn't seem to be available still
    Eugene

    GUI admin authentication against an external database will be included in ACS 5.4

  • RDS 2012 (An Authentication error has occurred 0x607) - WINDOWS 8 ONLY

    Hi - please help. I've read many posts relating to this error, but none have fixed my issue.
    We have an RDS 2012 setup.  2 Servers.  Both session hosts.  only 1 is the broker.  Cert from official CA.
    My authentication is set to ONLY allow devices with Network Level Authority.  I don't want to remove this.
    Windows XP and Windows 7 can connect both internally, and externally via the RDWeb address perfectly fine, but all Win8 machines get the error "An authentication error has occurred. Code 0x607.
    Can anyone please advise why?
    Many thanks

    Hi,
    I have seen other similar cases got resolved by setting the encryption level to low and security layer to Negotiate.
    Here is a thread below:
    An authentication error has occured (Code: 0x607)
    https://social.technet.microsoft.com/Forums/windowsserver/en-US/94780a11-23ba-4a3c-b11a-734007c2d2fd/an-authentication-error-has-occured-code-0x607?forum=winserverTS
    If it is not an option for you, I suggest you check whether the SSL certificate used by RDWeb access is trusted by the Windows 8 clients. There should be a corresponding root CA certificate installed in the Trusted Certification Authorities store.
    Best Regards,
    Amy
    Please remember to mark the replies as answers if they help and un-mark them if they provide no help. If you have feedback for TechNet Subscriber Support, contact [email protected]

  • Authentication error trying to download and open a book from my library using Windows 8 on my Surface2 tablet.

    When I chose ePUB as the download option for books from my library, the Overdrive Media Console application times out and locks up.  I get an Authentication error saying unable to open.  Then, I am unable to return to books to try another download option as the item did not successfully open using the Adobe Reader Digital Rights Management.

    See http://windows.microsoft.com/en-us/windows/change-file-open-program#1TC=windows-7
    Also http://windows.microsoft.com/en-us/windows/change-default-programs#1TC=windows-7

  • MS SQL 2008 R2 Named instance: Login failed. Microsoft SQL server, Error: 18452) - Tryig to access using the FQDN assigned for the backup network card.

    Hi,
       I have a windows 2008 R2 Enterprise servers with standalone MS-SQL 2008 R2 named instance.  The server is having two networks, once production and the second for backup. The server FQDN is resolving to the production IP. The backup NIC
    DNS dynamic update is disabled and an "A" record is registered with the dns.  While trying to connect to the instance using the management studio:
    Successfuly able to connect using the instance name, the production hostname, production IP and backup IP. 
    but while trying to connect to the insance using the backup hostname getting the below error:
    "Login failed. The login is an untrusted domain and cannot be used with windows authentication. (Microsoft SQL server, Error: 18452) "
    This is required for the backup tool to get connected using the backup FQDN of the server.
    Should I need to create a host name alias,  request you to kindly assist me with the best recommedation to fix this.
    http://blogs.msdn.com/b/dbrowne/archive/2012/05/21/how-to-add-a-hostname-alias-for-a-sql-server-instance.aspx

    Hi,
    It might be a kerberos issue.  Check that there are valid SPN's registered using the setspn utility - http://technet.microsoft.com/en-us/library/cc731241.aspx
    Thanks, Andrew
    My blog...

  • Ios7.1.2 email server authentication error

    We have a problem sending email using iMail client on a) iPad (ios7.1.2(11D257) and b) iMac (Auto updating Mavericks OS10). However, we can send email from iPad (ios7.1.1 (11D201). All three devices can receive email.
    All machines use the same email account and servers. All are using the same email client. All have been working effectively for past 4 years - the problem started about 1 month ago.
    Have spent "hours" with email service provider to troubleshoot the problem. Here is a list of the steps we have taken:
    1) checked email servers, confirming that email accounts can both send and receive email. This included testing via a webmail client, and from a Microsoft Outlook client. In both cases the tests confirmed that email can be received AND sent via the email server.
    2) setup alternate email servers, on different ports, on iPad - can always receive email but cannot send. The error message that is received is "username or password for 'mail.iinet.net.au' is incorrect"
    3) deleted email accounts and rest device to wipe it clean, then started from scratch - can establish the email account, can receive email, but still get the same error message when trying to send email "username of password for 'mail.iinet.net.au' is incorrect"
    4) tried alternative email client (CloudMagic, Evomail, Canonball) - not possible to connect to the email account, typical error is "unable to verify your account information"
    5) tried to setup account on iPhone across mobile phone network to isolate whether problem was local WiFi - same result
    The only thing that has shone any light on this was when we identified the outgoing mail server as "mailout.comhem,se" with no authentication. With this setting email would send. This could suggest a problem with the WiFi network, but it has been working perfectly well up till now, and on other WiFi networks. It also does not explain the problem with iMac from home which is directly connected to an ADSL service provided by our email service provider (no intermediary in play at all).  This also means that for every new WiFi network that I use (I travel a lot) I will need to find the details of an intermediate outgoing mail server for the specific WiFi provider. It is not clear why routing through an intermediary email server overcomes the authentication error at the destination email server, unless there is some more fundamental problem at play.
    The authentication error has been isolated to somewhere between the device and the server - could there be some ios7.1.2 issue at play that is causing the authentication to fail, but not when directed through an intermediary mail server?
    This problem is deeply frustrating, and any help would be greatly appreciated

    I haven't ran across this, but I do see that there is no SQL Instance Name in your screenshot. Try putting SQLTMS in there and then click next and see what happens. Or if you know the name of your TMS database instance, put that in there.

  • RADIUS Authentication Error Across the Subnet

    Hi Guyz
    I have configured Microsoft Server 2012 R2 as a RADIUS for Cisco IOS Devices
    Server IP Address :  10.95.6.12
    Router IP Address Fa 0/0.192                    ---->>>    192.193.194.195
    Router IP Address Fa 0/0.6                          --->>>    10.95.6.1
    Switch IP Address VLAN 192                     ---->>>    192.193.194.2010.95.6.11
    Switch IP Address VLAN 6                          ---->>>    10.95.6.11
    When i access the Cisco Devices RADIUS CLIENT with 10.95.6.x Subnet, It works fine 
    When i access the Cisco Devices through RADIUS CLIENT 192.193.194.x Subnet, It does not pass through the RADIUS Authentication.
    Attached in the Picture i can not access the 192.193.194.20 Device but I can access 10.95.6.1 Device.  As soon as I change the IP Address 10.95.6.11 I can access the Device.
    Ping is successful across the  Routers / Switches and Server as well.  Below is unsuccessful debug details as well:
    ===
    Home_Switch#
    01:52:30: RADIUS/ENCODE(00000008): ask "Password: "
    Home_Switch#
    01:52:41: RADIUS/ENCODE(00000008):Orig. component type = EXEC
    01:52:41: RADIUS:  AAA Unsupported Attr: interface         [171] 4   
    01:52:41: RADIUS:   74 74                [ tt]
    01:52:41: RADIUS/ENCODE(00000008): dropping service type, "radius-server attribute 6 on-for-login-auth" is off
    01:52:41: RADIUS(00000008): Config NAS IP: 0.0.0.0
    01:52:41: RADIUS/ENCODE(00000008): acct_session_id: 8
    01:52:41: RADIUS(00000008): sending
    01:52:41: RADIUS/ENCODE: Best Local IP-Address 10.95.6.11 for Radius-Server 10.95.6.12
    01:52:41: RADIUS(00000008): Send Access-Request to 10.95.6.12:1812 id 1645/6, len 85
    Home_Switch#
    01:52:41: RADIUS:  authenticator 95 FB 3F FE 79 BB AA D6 - C9 26 F4 EC 95 32 80 06
    01:52:41: RADIUS:  User-Name           [1]   7   "cisco"
    01:52:41: RADIUS:  User-Password       [2]   18  *
    01:52:41: RADIUS:  NAS-Port            [5]   6   2                         
    01:52:41: RADIUS:  NAS-Port-Id         [87]  6   "tty2"
    01:52:41: RADIUS:  NAS-Port-Type       [61]  6   Virtual                   [5]
    01:52:41: RADIUS:  Calling-Station-Id  [31]  16  "192.193.194.50"
    01:52:41: RADIUS:  NAS-IP-Address      [4]   6   10.95.6.11                
    01:52:41: RADIUS(00000008): Started 5 sec timeout
    Home_Switch#
    01:52:46: RADIUS(00000008): Request timed out 
    01:52:46: RADIUS: Retransmit to (10.95.6.12:1812,1813) for id 1645/6
    01:52:46: RADIUS(00000008): Started 5 sec timeout
    Home_Switch#
    ===
    Any help will really appreciate. 

    Duplicate posts.  
    Go here:  http://supportforums.cisco.com/discussion/12154866/radius-authentication-error-across-subnet

  • Exchange 2010 Receive Connector gets 530 5.7.1 Not Authenticated Error

    Hi All, I am using Exchange2010 SP2 with HT,CAS and Mail roles ( this is my test machine). I created a receive connector for Mutual TLS in which i have added remote servers with which i want to do mutual (Domain Secure Emails Transfer) and enabled TLS &
    Mutual TLS in authentication tab only and partners in permission tab only. When I test these settings with my partners who are on exchange server or iron mail they are working fine. My problem occurs when i receive mails from MDaemon Pro 13.5 and the problem
    is i get 530 5.7.1 Not Authenticated  error. Can anyone help me why i am getting this.

    I am attaching more details for the said problem. Below is send log from mdaemon side and receive log from exchange 2010 (my side).
    Sender Log: (MDaemon side)
    --- Session Transcript ---
     Mon 2014-02-03 17:31:18: Parsing message <xxxxxxxxxxxxxxxxxxxxxxxx\pd35000084484.msg>
     Mon 2014-02-03 17:31:18: *  From: [email protected]
     Mon 2014-02-03 17:31:18: *  To: [email protected]
     Mon 2014-02-03 17:31:18: *  Subject: Mutual TLS 03022014
     Mon 2014-02-03 17:31:18: *  Size (bytes): 1551
     Mon 2014-02-03 17:31:18: *  Message-ID: <[email protected]>
     Mon 2014-02-03 17:31:18: Attempting SMTP connection to [receive.com]
     Mon 2014-02-03 17:31:18: Resolving MX records for [receive.com] (DNS Server: 141.1.1.1)...
     Mon 2014-02-03 17:31:18: *  P=010 S=000 D=receive.com TTL=(240) MX=[win2k8.receive.com]
     Mon 2014-02-03 17:31:18: Attempting SMTP connection to [win2k8.receive.com:25]
     Mon 2014-02-03 17:31:18: Resolving A record for [win2k8.receive.com] (DNS Server: 141.1.1.1)...
     Mon 2014-02-03 17:31:28: *  DNS: 10 second wait for DNS response exceeded (DNS Server: 141.1.1.1)
     Mon 2014-02-03 17:31:28: Attempting SMTP connection to [win2k8.receive.com:25]
     Mon 2014-02-03 17:31:28: Resolving A record for [win2k8.receive.com] (DNS Server: 8.8.8.8)...
     Mon 2014-02-03 17:31:28: *  D=win2k8.receive.com TTL=(239) A=[receiver_ip]
     Mon 2014-02-03 17:31:28: Attempting SMTP connection to [receiver_ip:25]
     Mon 2014-02-03 17:31:28: Waiting for socket connection...
     Mon 2014-02-03 17:31:28: *  Connection established (sender_ip:60054 -> receiver_ip:25)
     Mon 2014-02-03 17:31:28: Waiting for protocol to start...
     Mon 2014-02-03 17:31:33: <-- 220 win2k8.receive.com Microsoft ESMTP MAIL Service ready at Mon, 3 Feb 2014 17:31:41 +0500
     Mon 2014-02-03 17:31:33: --> EHLO mail.sender.com
     Mon 2014-02-03 17:31:33: <-- 250-receive.com Hello [sender_ip]
     Mon 2014-02-03 17:31:33: <-- 250-SIZE
     Mon 2014-02-03 17:31:33: <-- 250-PIPELINING
     Mon 2014-02-03 17:31:33: <-- 250-DSN
     Mon 2014-02-03 17:31:33: <-- 250-ENHANCEDSTATUSCODES
     Mon 2014-02-03 17:31:33: <-- 250-STARTTLS
     Mon 2014-02-03 17:31:33: <-- 250-AUTH NTLM
     Mon 2014-02-03 17:31:33: <-- 250-8BITMIME
     Mon 2014-02-03 17:31:33: <-- 250-BINARYMIME
     Mon 2014-02-03 17:31:33: <-- 250 CHUNKING
     Mon 2014-02-03 17:31:33: --> STARTTLS
     Mon 2014-02-03 17:31:33: <-- 220 2.0.0 SMTP server ready
     Mon 2014-02-03 17:31:33: SSL negotiation successful (TLS 1.0, 2048 bit key exchange, 128 bit  encryption)
     Mon 2014-02-03 17:31:33: --> EHLO mail.sender.com
     Mon 2014-02-03 17:31:33: <-- 250-receive.com Hello [sender_ip]
     Mon 2014-02-03 17:31:33: <-- 250-SIZE
     Mon 2014-02-03 17:31:33: <-- 250-PIPELINING
     Mon 2014-02-03 17:31:33: <-- 250-DSN
     Mon 2014-02-03 17:31:33: <-- 250-ENHANCEDSTATUSCODES
     Mon 2014-02-03 17:31:33: <-- 250-AUTH NTLM
     Mon 2014-02-03 17:31:33: <-- 250-8BITMIME
     Mon 2014-02-03 17:31:33: <-- 250-BINARYMIME
     Mon 2014-02-03 17:31:33: <-- 250 CHUNKING
     Mon 2014-02-03 17:31:33: --> MAIL From:<[email protected]> SIZE=1551
     Mon 2014-02-03 17:32:03: <-- 530 5.7.1 Not authenticated
     Mon 2014-02-03 17:32:03: --> QUIT
    --- End Transcript ---
    Receive Log: (Exchange 2010 side)
    2014-02-03T13:31:12.609Z,WIN2K8\Default WIN2K8,08D0EEF2D8DBF9DD,0,receiver_ip:25,sender_ip:60294,+,,
    2014-02-03T13:31:12.609Z,WIN2K8\Default WIN2K8,08D0EEF2D8DBF9DD,1,receiver_ip:25,sender_ip:60294,*,SMTPSubmit SMTPAcceptAnySender SMTPAcceptAuthoritativeDomainSender AcceptRoutingHeaders,Set Session Permissions
    2014-02-03T13:31:12.609Z,WIN2K8\Default WIN2K8,08D0EEF2D8DBF9DD,2,receiver_ip:25,sender_ip:60294,>,"220 win2k8.receive.com Microsoft ESMTP MAIL Service ready at Mon, 3 Feb 2014 18:31:11 +0500",
    2014-02-03T13:31:12.625Z,WIN2K8\Default WIN2K8,08D0EEF2D8DBF9DD,3,receiver_ip:25,sender_ip:60294,<,EHLO mail.sender.com,
    2014-02-03T13:31:12.625Z,WIN2K8\Default WIN2K8,08D0EEF2D8DBF9DD,4,receiver_ip:25,sender_ip:60294,>,250-win2k8.receive.com Hello [sender_ip],
    2014-02-03T13:31:12.625Z,WIN2K8\Default WIN2K8,08D0EEF2D8DBF9DD,5,receiver_ip:25,sender_ip:60294,>,250-SIZE,
    2014-02-03T13:31:12.625Z,WIN2K8\Default WIN2K8,08D0EEF2D8DBF9DD,6,receiver_ip:25,sender_ip:60294,>,250-PIPELINING,
    2014-02-03T13:31:12.625Z,WIN2K8\Default WIN2K8,08D0EEF2D8DBF9DD,7,receiver_ip:25,sender_ip:60294,>,250-DSN,
    2014-02-03T13:31:12.625Z,WIN2K8\Default WIN2K8,08D0EEF2D8DBF9DD,8,receiver_ip:25,sender_ip:60294,>,250-ENHANCEDSTATUSCODES,
    2014-02-03T13:31:12.625Z,WIN2K8\Default WIN2K8,08D0EEF2D8DBF9DD,9,receiver_ip:25,sender_ip:60294,>,250-STARTTLS,
    2014-02-03T13:31:12.625Z,WIN2K8\Default WIN2K8,08D0EEF2D8DBF9DD,10,receiver_ip:25,sender_ip:60294,>,250-AUTH NTLM,
    2014-02-03T13:31:12.625Z,WIN2K8\Default WIN2K8,08D0EEF2D8DBF9DD,11,receiver_ip:25,sender_ip:60294,>,250-8BITMIME,
    2014-02-03T13:31:12.625Z,WIN2K8\Default WIN2K8,08D0EEF2D8DBF9DD,12,receiver_ip:25,sender_ip:60294,>,250-BINARYMIME,
    2014-02-03T13:31:12.625Z,WIN2K8\Default WIN2K8,08D0EEF2D8DBF9DD,13,receiver_ip:25,sender_ip:60294,>,250 CHUNKING,
    2014-02-03T13:31:12.625Z,WIN2K8\Default WIN2K8,08D0EEF2D8DBF9DD,14,receiver_ip:25,sender_ip:60294,<,STARTTLS,
    2014-02-03T13:31:12.625Z,WIN2K8\Default WIN2K8,08D0EEF2D8DBF9DD,15,receiver_ip:25,sender_ip:60294,>,220 2.0.0 SMTP server ready,
    2014-02-03T13:31:12.625Z,WIN2K8\Default WIN2K8,08D0EEF2D8DBF9DD,16,receiver_ip:25,sender_ip:60294,*,,Sending certificate
    2014-02-03T13:31:12.625Z,WIN2K8\Default WIN2K8,08D0EEF2D8DBF9DD,17,receiver_ip:25,sender_ip:60294,*,"CN=win2k8.receive.com, OU=Domain Control Validated - QuickSSL(R) Premium, Certificate subject
    2014-02-03T13:31:12.625Z,WIN2K8\Default WIN2K8,08D0EEF2D8DBF9DD,18,receiver_ip:25,sender_ip:60294,*,"CN=SSL CA, OU=SSL, O=3rd Party, C=LL",Certificate issuer name
    2014-02-03T13:31:12.625Z,WIN2K8\Default WIN2K8,08D0EEF2D8DBF9DD,19,receiver_ip:25,sender_ip:60294,*,0763ED,Certificate serial number
    2014-02-03T13:31:12.625Z,WIN2K8\Default WIN2K8,08D0EEF2D8DBF9DD,20,receiver_ip:25,sender_ip:60294,*,1234567890,Certificate thumbprint
    2014-02-03T13:31:12.625Z,WIN2K8\Default WIN2K8,08D0EEF2D8DBF9DD,21,receiver_ip:25,sender_ip:60294,*,win2k8.receive.com;win2k8.receive.com;autodiscover.receive.com,Certificate alternate names
    2014-02-03T13:31:13.234Z,WIN2K8\Default WIN2K8,08D0EEF2D8DBF9DD,22,receiver_ip:25,sender_ip:60294,<,EHLO mail.sender.com,
    2014-02-03T13:31:13.234Z,WIN2K8\Default WIN2K8,08D0EEF2D8DBF9DD,23,receiver_ip:25,sender_ip:60294,*,,TlsDomainCapabilities='None'; Status='NoRemoteCertificate'
    2014-02-03T13:31:13.234Z,WIN2K8\Default WIN2K8,08D0EEF2D8DBF9DD,24,receiver_ip:25,sender_ip:60294,>,250-win2k8.receive.com Hello [sender_ip],
    2014-02-03T13:31:13.234Z,WIN2K8\Default WIN2K8,08D0EEF2D8DBF9DD,25,receiver_ip:25,sender_ip:60294,>,250-SIZE,
    2014-02-03T13:31:13.234Z,WIN2K8\Default WIN2K8,08D0EEF2D8DBF9DD,26,receiver_ip:25,sender_ip:60294,>,250-PIPELINING,
    2014-02-03T13:31:13.234Z,WIN2K8\Default WIN2K8,08D0EEF2D8DBF9DD,27,receiver_ip:25,sender_ip:60294,>,250-DSN,
    2014-02-03T13:31:13.234Z,WIN2K8\Default WIN2K8,08D0EEF2D8DBF9DD,28,receiver_ip:25,sender_ip:60294,>,250-ENHANCEDSTATUSCODES,
    2014-02-03T13:31:13.234Z,WIN2K8\Default WIN2K8,08D0EEF2D8DBF9DD,29,receiver_ip:25,sender_ip:60294,>,250-AUTH NTLM,
    2014-02-03T13:31:13.234Z,WIN2K8\Default WIN2K8,08D0EEF2D8DBF9DD,30,receiver_ip:25,sender_ip:60294,>,250-8BITMIME,
    2014-02-03T13:31:13.234Z,WIN2K8\Default WIN2K8,08D0EEF2D8DBF9DD,31,receiver_ip:25,sender_ip:60294,>,250-BINARYMIME,
    2014-02-03T13:31:13.234Z,WIN2K8\Default WIN2K8,08D0EEF2D8DBF9DD,32,receiver_ip:25,sender_ip:60294,>,250 CHUNKING,
    2014-02-03T13:31:13.234Z,WIN2K8\Default WIN2K8,08D0EEF2D8DBF9DD,33,receiver_ip:25,sender_ip:60294,<,MAIL From:<[email protected]> SIZE=17914,
    2014-02-03T13:31:13.234Z,WIN2K8\Default WIN2K8,08D0EEF2D8DBF9DD,34,receiver_ip:25,sender_ip:60294,*,Tarpit for '0.00:00:30',
    2014-02-03T13:31:43.250Z,WIN2K8\Default WIN2K8,08D0EEF2D8DBF9DD,35,receiver_ip:25,sender_ip:60294,>,530 5.7.1 Not authenticated,
    2014-02-03T13:31:43.250Z,WIN2K8\Default WIN2K8,08D0EEF2D8DBF9DD,36,receiver_ip:25,sender_ip:60294,<,QUIT,
    2014-02-03T13:31:43.250Z,WIN2K8\Default WIN2K8,08D0EEF2D8DBF9DD,37,receiver_ip:25,sender_ip:60294,>,221 2.0.0 Service closing transmission channel,
    2014-02-03T13:31:43.250Z,WIN2K8\Default WIN2K8,08D0EEF2D8DBF9DD,38,receiver_ip:25,sender_ip:60294,-,,Local
    I hope this shall help you understand some thing. Do remember that i am using mutual (force) TLS with this client
    whose domain is already in my send/receive secure list of TransportConfig.

  • CRVS2010 Beta - Microsoft JScript runtime error: 'bobj' is undefined

    1. When I try to generate a crystal report with the "CR4VS2010" from the web client, I am getting the following error:
    Microsoft JScript runtime error: 'bobj' is undefined.
    I am using the OS -> Windows Vista.
    2. Where as if i try to generate the report using the service job, i am getting the following error:
    System.IO.FileNotFoundException was unhandled
      Message=Could not load file or assembly 'file:///C:\Program Files\SAP BusinessObjects\SAP BusinessObjects Enterprise XI 4.0\win32_x86\dotnet1\crdb_adoplus.dll' or one of its dependencies. The system cannot find the file specified.
      Source=mscorlib
      FileName=file:///C:\Program Files\SAP BusinessObjects\SAP BusinessObjects Enterprise XI 4.0\win32_x86\dotnet1\crdb_adoplus.dll
      FusionLog==== Pre-bind state information ===
    LOG: User = SAGITEC\karthikeyan.s
    LOG: Where-ref bind. Location = C:\Program Files\SAP BusinessObjects\SAP BusinessObjects Enterprise XI 4.0\win32_x86\dotnet1\crdb_adoplus.dll
    LOG: Appbase = file:///E:/Source/Eclipse/Bin/
    LOG: Initial PrivatePath = NULL
    Calling assembly : (Unknown).
    ===
    LOG: This bind starts in LoadFrom load context.
    WRN: Native image will not be probed in LoadFrom context. Native image will only be probed in default load context, like with Assembly.Load().
    LOG: Using application configuration file: E:\Source\Eclipse\Bin\NeoSpinBatch.vshost.exe.Config
    LOG: Using host configuration file:
    LOG: Using machine configuration file from C:\Windows\Microsoft.NET\Framework\v4.0.21006\config\machine.config.
    LOG: Attempting download of new URL file:///C:/Program Files/SAP BusinessObjects/SAP BusinessObjects Enterprise XI 4.0/win32_x86/dotnet1/crdb_adoplus.dll.
    Edited by: Don Williams on Apr 26, 2010 6:22 AM
    Edited by: Jason Everly on Apr 26, 2010 9:30 AM
    Changed subject line to correct format

    3. For fixing the error#2, i copied the DLL to the respective directory mentioned in the above error. But it gives me new error :
    System.IO.FileLoadException was unhandled
      Message=Mixed mode assembly is built against version 'v2.0.50727' of the runtime and cannot be loaded in the 4.0 runtime without additional configuration information.
      Source=mscorlib
      StackTrace:
           at System.Reflection.RuntimeAssembly._nLoad(AssemblyName fileName, String codeBase, Evidence assemblySecurity, RuntimeAssembly locationHint, StackCrawlMark& stackMark, Boolean throwOnFileNotFound, Boolean forIntrospection, Boolean suppressSecurityChecks)
           at System.Reflection.RuntimeAssembly.nLoad(AssemblyName fileName, String codeBase, Evidence assemblySecurity, RuntimeAssembly locationHint, StackCrawlMark& stackMark, Boolean throwOnFileNotFound, Boolean forIntrospection, Boolean suppressSecurityChecks)
           at System.Reflection.RuntimeAssembly.InternalLoadAssemblyName(AssemblyName assemblyRef, Evidence assemblySecurity, StackCrawlMark& stackMark, Boolean forIntrospection, Boolean suppressSecurityChecks)
           at System.Reflection.RuntimeAssembly.InternalLoadFrom(String assemblyFile, Evidence securityEvidence, Byte[] hashValue, AssemblyHashAlgorithm hashAlgorithm, Boolean forIntrospection, Boolean suppressSecurityChecks, StackCrawlMark& stackMark)
           at System.Reflection.Assembly.LoadFrom(String assemblyFile)
           at CrystalDecisions.ReportAppServer.DataSetConversion.DataSetConverter.DataSetProcessingDelegate(IntPtr arg)
      InnerException:
    Please help me in resolving the above issues ASAP.
    Thanks in advance,
    Karthikeyan Sridharan

  • TES API Authentication error

    I'm using Microsoft Visual Studio and able to import the teswebservice?wsdl and schema. However, when I try to connect using the user ClientCredential.   I receive an authentication error below. Any idea?? See attachment..     
    Web Service :        http://10.3.0.70:8080/api/tes-6.0/webservice/teswebservice?wsdl  
    We tried connecting to this API by creating an object and respective properties – but it is failed to authorize the services. Here the following Error
    The HTTP request is unauthorized with client authentication scheme 'Anonymous'. The authentication header received from the server was 'Basic realm="Tidal Application Realm"'.

    Can you try setting the domain name separately, similar to how you have set Password ? I think setting domain\username is the culprit. For example:
    _client.ClientCredentials.Windows.ClientCredential.Domain = "warzone42";
    _client.ClientCredentials.Windows.ClientCredential.UserName = "user1428798";
    _client.ClientCredentials.Windows.ClientCredential.Password = "p@ssw0rd";
    Can you also try accessing the same webservice from a tool like SOAPUI ? Once done, you can see the request and response messages to troubleshoot. Such tools(SOAPUI) are Java based and will behave correctly as compared to when called from Visual Studio/.Net

  • Exchange 2010 RPC over HTTPs failing with authentication error

    Hi.  I have my remote.xxx.co.uk domain and autodiscover.xxx.co.uk domain pointing to my SBS2011 server, have ports 25, 80, 443 open.  The Microsoft Connectivity Analyzer fails with the below error.
    Outlook will autodiscover happily on the local network, and works fine.  Phones etc do too.
    Outlook at a remote VPN connected site won't connect through autodiscover, but will if you do it manually (ignoring the RPC Proxy settings).  Everything works for a while, but then I guess outlook decides to use autodiscover to complete all the connection
    details, and then these machines can no longer connect to exchange as I guess they decide the speed is too slow and try to connect using RPC instead.
    Users can access OWA happily, and activesync is working on phones etc.
    SSL cert is a wildcard type on my domain, and certs are installed - all green and happy when visiting OWA on both remote.xxxxx.co.uk and autodiscover.xxxxx.co.uk domains.
    I cannot work out why I have an authentication error for RPC?
    Any advice would be great!
    Testing HTTP Authentication Methods for URL https://remote.xxxxx.co.uk/rpc/rpcproxy.dll?xxxxxx.xxxxxx.local:6002.
    The HTTP authentication test failed.
    Additional Details
    Exception details:
    Message: The operation has timed out
    Type: System.Net.WebException
    Stack trace:
    at System.Net.HttpWebRequest.GetResponse()
    at Microsoft.Exchange.Tools.ExRca.Extensions.RcaHttpRequest.GetResponse()
    Elapsed Time: 100065 ms

    Hi.
    To update.
    I tried to recreate the virtual directories in the Exchange Management Console, using the recreate links and via the shell, but while they were recreated, they did not function as they should due to issues in the meta database.
    I then found the following which worked.
    Looking at the ActiveSync virtual directories, when running the below command, the result showed the directory was there, so I then knew to delete it.
    In EMS I ran,
    => Ran "$site = [ADSI]"IIS://localhost/W3SVC/1/Root/Microsoft-Server-ActiveSync""
    Result: Carriage return.
    => Ran "$site"
    Result:
    distinguishedName:
    Path: {C:\Program Files\Microsoft\ExchangeServer\V14\Client Access\Sync}
    In EMS I then ran,
    => Ran "$Site = [ADSI]"IIS://localhost/W3SVC/1/Root""
    Result: Carriage return.
    => Ran "$site.Delete("IIsWebVirtualDir","Microsoft-Server-ActiveSync")"
    Result: Carriage return.
    => Ran "$site.SetInfo()"
    Result: Carriage return.
    => Ran "$site"
    Result: Carriage return.
    => Ran "iisreset"
    I then recreated the virtual directories. 
    In EMS I ran,
    => Ran "New-ActiveSyncVirtualDirectory -WebSiteName "Default Web Site""
    Results: Successfully recreated.
    => Ran "iisreset"
    I am not sure exactly, but I did this for multiple virtual directories, and everything came to life just as it should.

  • HT5016 microsoft premium 2000 error

    itunes not loading microsoft office 2000 error

    I double checked the name and it's correct. I also typed in the IP address instead of the hostname like:
    jdbc:microsoft:sqlserver://172.16.105.54:1433;databaseName=testdb
    I set the SQL server to use SQL Authentication and created a user and the password. I tried following:
    //the suggested way in the microsoft documentation
    url = "jdbc:microsoft:sqlserver://172.16.105.54:1433;databaseName=testdb;user=user;password=password";
    Connection con = DriverManager.getConnection(url);
    I also tried:
    url = "jdbc:microsoft:sqlserver://172.16.105.54:1433;databaseName=testdb";
    user = user;
    password = password;
    Connection con = DriverManager.getConnection(url, user, password);
    Both gave the same error.

  • Authentication errors in Magic Triangle set up

    Hi All,
    I have recently integrated a SL server into AD to provide MCXs to Mac workstations as well as network homes, time machine server etc.
    Everything is working fine and there aren't any major problems - clients can log into AFP homes and the majority of MCXs are working well.  One thing I have noticed though is that exactly every 2 hours I get an error in Windows event viewer complaining of a Kerberos authentication error (Event ID 4768).  The account name specified in the event log is the computer record for the OD master.
    I did a bit of digging through the logs and can see the successful logging in of the Mac server computer account to the Password server.  In the password server service log, I get this:
    RSAVALIDATE: success.
    Apr  8 2012 14:10:12    USER: {0x4f7e1ea56b8b4567000000040000000, server.domain.com$} is the current user.
    Apr  8 2012 14:10:12    AUTH2: {0x4f7e1ea56b8b4567000000040000000, server.domain.com$} CRAM-MD5 authentication succeeded.
    The computer account 'server.domain.com$' is listed when you go into WGM and go to 'show system records' and is the computer account for the mac server that is the OD master.
    I believe that the server is trying to authenticate to the Windows DC, receiving an error (and generating the 4768 error code) and then successfully authenticating to OD. 
    I have changed the search policy on the server to authenticate against OD first and then AD, but I am still getting this error.  I don't know whether Directory Utility is buggy and incorrectly shows LDAP before AD as I cannot find the dscl command to list search policies anywhere, only to add, delete and amend search policies.
    Questions:
    1) Why is the server authenticating to itself every 2 hours?
    2) Does anyone know how to list the search policy order in dscl, so I can verify that the server is actually authing against OD first?
    3) If the search policy is OK, and I suspect it is, why is the server trying to auth against AD?
    4) Has anyone else seen this error and, if so, how did you resolve?
    Coincidently, I also get this error when I log into WGM using the directory admin username/password.
    TIA

    Hi James,
    Received wisdom for Magic Triangle is to bind the Mac server to AD and ensure that Kerberos is disabled on the Mac server. It sounds like you may not have done it that way?
    This reference may help:
    http://www.afp548.com/netboot/mactips/activedir.html
    Just a guess - but perhaps the re-authentication every 2 hours is due to Kerberos ticket expiration?
    Best

  • Any one else have Microsoft C++ runtime error in Adobe Photoshop Elements 11 (non cloud version)

    I have been using Adobe Photoshop Elements 11 for 9 months successfully with no issues.  Last night, for no reason, it stopped working , giving me a Microsoft C++ runtime error.  I have tried every trouble shooting suggestion, including resetting the computer, deleting recent updates, disk cleanup, etc.  I finally un installed the program, and when I attempted to re-install, it got almost to the end of the install, and then I get a message " The installation process encountered an error using Shared Technologies".   Can anyone help me?  Technical support for store bought copies of this program is non existant.  It took me 2 hours to find a  phone number that works and that was only for cloud users, and the only support they offer is a chat room , which disappeard from my screen this morning, and is no being offered at least today.   I must have this program for my photography classes I take 2 x a week.  Please help!

    Moving this discussion to the Photoshop Elements forum.

  • Microsoft C++runtime error in Adobe Photoshop_10, editor,Windows 7

    Would like to fix this.
    Program opens, when I click on editor, Visual Runtime error occurs, and program will shut down when I closed window or click to cancel.
    I have been coming up with some solutions on the forum but some people have not been successful for other versions & I hve not found the specific one question like mine. Can some one send me the correct link for this fix for my particular stats
    Thank you

    Follow the steps in article:
    http://helpx.adobe.com/photoshop-elements/kb/microsoft-c-runtime-error-launcing.html

Maybe you are looking for

  • New browser window without Border

    Hi , How I can achieve of on clicking commandlink need to open a new browser window without a border as a child and having the parent window in background as frozen mode..I need to have it looking similar to popup..Im using Jdeveloper 11.1.1.6 Thanks

  • How to stop the call summary display on home screen?

    How to stop the call summary display on home screen?

  • Helvetica Neue PostScript fonts not appearing in font list

    Just curious if anyone else out there on a Mac (I'm on 10.5.8) is having trouble with Helvetica Neue (or any other System fonts) being accessable from the Fireworks CS5 font list? I expect that I should see a whole slew of Helvetica Neue typefaces (P

  • PLease Help! WMV issues

    Hello, When I Get Media and bring in a WMV file to any preset, the top half of the video file is black and the bottom half is fine. Working in PE7. Any ideas why this is suddenly happening? Thanks, Stan

  • Suddenly can't open PDFs

    I have a Dell about a year old that came with Windows 8. I open PDFs on a regular basis and suddenly it just stopped. Reader comes up and the screen goes dark and the blue circle circles but nothing ever opens.