Trouble enabling NDES logging

Hi,
I am trying to enable logging for Certificate Services Network Device Enrollment Service (NDES).  I am following the instructions in the book "Windows Server 2008 PKI and Certificate Security" on page 694.
As the instructions indicated, I logged in once as the service account we are using for NDES in order to create a local profile.  Next, I logged in as myself (I am in the local administrators group) and opened a command prompt as an administrator and
typed the following command:
certutil -setreg debug 0xffffffe3
The output of the command was:
CertUtil: -setreg command FAILED: 0x80070002 (WIN32: 2)
CertUtil: The system cannot find the file specified.
According to the book, this should have created a file named C:\Users\ServiceAccount\Mscep.log
Can anyone advise?

Hi Mike,
Can you try the following and report the results?
Set the SCEP Application Pool in IIS to "Load User Profile".
Here are the steps:
1.      
Call “iisreset” from an elevated prompt
2.      
Log in to the MSCEP server once as the Service Account and ensure a local profile is created under “%SystemDrive%\Users”
3.      
Log off of the Service Account and Log in as an admin
4.      
Open InetMgr.exe
5.      
Expand the Connection where the MSCEP Application is running
6.      
Select “Application Pools”
7.      
Right click the “SCEP” Application Pool and select “Advance Settings…”
8.      
Under the “Process Model” section, set the “Load User Profile” to “true”
9.      
Call “iisreset” from an elevated prompt
10.  
Try an MSCEP operation and check if the log has been created.
11.  
Verify “%SystemDrive%\Users\mscep.log” has been created.
Thanks,
John

Similar Messages

  • How to enable fnd log in self service page

    Hello,
    In professional forms, we can enable fnd log using the profile options "FND: Debug Log Enabled" to Yes and "FND: Debug Log Level" to different levels.
    Similarly, can we do the same with Self Service page? how and where can i see the log results? Also when i'm running the selfservice page from jDeveloper, is there any possibility to see the entire log?
    I need to track why i'm unable to run a page from jdeveloper and i need to track the log.
    Thank you all for the help in advance.
    kK

    Hi,
    To Enable to Log for a self service page click on 'Diagnostics' link avaible at the Upper Right corner of the page. Now from the Diagnostic poplist select the 'Show Log On Screen' then select the log level and save.
    Now you perform your fucntional steps all the log messages you will be able to see at the bottam of the page.
    Regards,
    Syed.

  • Where to check/enable for log keeping track of transport rule actions?

    I have implemented some transport rules to "journal" all emails from specific clients as per this
    thread. 
    So there are 4 transport rules to capture all those email:
    1. email from Clients (incoming / FROM)
    1.1 from users outside the organization.
    1.2 sent to member of AD Group
    1.3 sent to users inside the organization.
    1.4 where the from address contains "domain of our clients list"
    1.5 BBC to capture mailbox
    2. email to Clients (outgoing/ TO)
    2.1 from member of AD Group
    2.2 from users inside the org
    2.3 sent to users outside the organization.
    2.4 where the to address contains "domain of our clients list"
    2.5 BBC to capture mailbox
    3. email to Clients (outgoing/ CC)
    3.1 from member of AD Group
    3.2 from users inside the org
    3.3 sent to users outside the organization.
    3.4 where the cc address contains "domain of our clients list"
    3.5 BBC to capture mailbox
    4. email to Clients (outgoing/ BCC)
    4.1 from member of AD Group
    4.2 from users inside the org
    4.3 sent to users outside the organization.
    4.4 where the bcc address contains "domain of our clients list"
    4.5 BBC to capture mailbox
    The symptoms are that while I am seeing by selecting random emails that everything seem to run fine (rule filtering from transport does get incoming and outgoing messages to that “capture” mailbox) and I tested this fine with some test emails
    in different domains.
    Somehow I am no getting the results I want. With business sending some test sets I should be finding in that mailbox, I do not find everything. Some of the email that apparently would logically be captured are not. Is business lying about the test sets they
    send? I don’t think so and the fact is that I seem to be missing emails.
    Anyhow my questions to you are the following:
    1.    Do you know of any logging done by the transport server to check on matches of the filters?
    2.    I am using outside and inside condition in the rules. Are they what I think they are?
    I hope you can help. I think I am doing this right, but I cannot verify the process 100%. Some logs or additional information would help. Or perhaps I am not using the conditions properly.
    Thank you in advance.
    and BTW the environment is Exchange 2007

    Based on my research, there is no specific log to match the filters. During the mail flow, only SMTP log and Message Tracking log can record the message information.
    You can check the two logs if needed. For more information, please refer to the following steps.
    Enable Message tracking log
    1. Open the Exchange Management Console. 
    2. In the console tree, expand Server Configuration, and select Hub Transport.
    3. In the action pane, click the Properties link that is directly under the server name.
    4. In the Properties page, click the Log Settings tab.
    5. In the Message tracking log section, Select Enable message tracking log to enable message tracking.
    6. Click Apply to save changes and remain in the Properties page, or click OK to save changes and exit the Properties page.
    Enable SMTP Log
    1. In the console tree, expand Organization Configuration, and select Hub Transport.
    2. In the action pane, click on Sender Connectors and right click on send connector and then click on properties.
    3. Select “Verbose” under “Protocol logging level” and then click ok.
    Then, you can find the logs from the following location.
    Collect Message Tracking Log
    On the Exchange server, go to directory “c:\program files\Microsoft\exchange server\TransportRoles\Logs\Message Tracking”
    Collect SMTP log
    Open the folder on the Hub Server,: C:\Program Files\Microsoft\Exchange Server\TransportRoles\Logs\ProtocolLog\SmtpSend.
    Thanks.
    Novak
    Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.

  • Enable Change logs in tcode

    Hi All,
    I need to enable Change logs in CJ20n as
    it is available in VA02
    CJ20n is an Project System module T-code.
    Please its urgent.
    Thanks & Regards,
    Amit.

    You can change the setting of the below transaction CJ20n by going to settings->options , where  we have the option to change or display.
    When  you change the setting to  'change' mode then you can open a new project where the option of scheduling can be done for a new project.
    Hope this is what you have asked for.

  • Am having all kinds of trouble enabling Home Sharing on Apple TV. Had been working previously, but now I am unable to share files between TV, Ipods and iMac. I have tried restarting all hardware, systems and connections. I recently upgraded modem?

    Am having all kinds of trouble enabling Home Sharing on Apple TV 3. Had been working previously, but now I am unable to share files between TV, Ipods and iMac. I have tried restarting all hardware, systems and connections. I recently upgraded modem, would this have an effect on connectivity?

    U may need to check the settings on ur PC or Mac.

  • How to enable log4j logging on Infoview and CMC on JBoss Appln Server?

    Hi
    I have enabled log4j logging on Web Intelligence (For Analytical Reporting Application). Can anybody help me in enabling logging for CMC and Infoview.
    Please refer to the below link for more details on Logging in JBoss AS.
    http://docs.jboss.org/process-guide/en/html/logging.html#d0e3341
    Regards
    Arun Sasi

    If you have the EM (Enterprise Manager) installed on your stand alone WLS (which you should) you can select the managed server your app is running on, select the 'Log Configuration' menu and you should see almost the same representation an in jdev.
    Timo

  • How to enable JCo logging

    I know I've seen this somewhere, but now that I need it, I can't find it.  I've spent two hours searching all the forums.  Can someone tell me how I enable JCo logging?  I have a JCO/Java program that works fine from the command line, but doesn't work when I try to use it in a Tomcat servlet.  None of the log files that I can find have any errors in them, but it appears that the call to JCO.createClient fails in the servlet.  I've read all of the posts about putting the JCo jar file in the servlet's lib directory and copying sapjcorfc.dll to Tomcat's bin directory, but no luck.  I'm hoping that there is some way that I can get JCo to give me a log that will indicate what is going wrong.  Thank you for your help.

    <b>SAP Note 723562</b>
    2. Runtime loading mechanism
    When an application references a JCo class for the first time it will be loaded by the associated class loader. During this process JCo's static initializer will be executed. This routine will search and load the JCo JNI library by using the following algorithm:
    1. Try to load the sapjcorfc library from the same directory where the sapjco.jar file or the JCo class files are located.
    2. Search the sapjcorfc library along the directory path defined in the java.library.path system property from left to right and if found load it from there.
                Note: If this property is not set manually, the JVM will usually set the OS specific library path environment variable as the default java.library.path system property at startup.
    1. Let the JVM handle the loading of the sapjcorfc library by delegating this task to its System.loadLibrary(String) method.
    JCo's JNI library is linked with the native RFC library. So when it is loaded the operating system will try to resolve its dependencies by loading the native RFC library, too. Usually, this will be done by searching for the first occurrence of the rfccm | librfc32 library along the directory path defined by the OS specific library path environment variable from left to right and load it.
    If the sapjcorfc library and/or the rfccm | librfc32 library cannot be loaded, you will get an ExceptionInInitializerError from the JCO. <clinit> method saying that it could not load the middleware layer com.sap.mw.jco.rfc.MiddlewareRFC. This error message may be caused for one of the following reasons:
    The sapjcorfc library cannot be found by using the above described algorithm, because you unintentionally installed it to the wrong directory or forgot to specify its directory in the OS specific library path environment variable or alternatively in the java.library.path system property.
    The rfccm | librfc32 library cannot be found because you unintentionally installed it to the wrong directory or forgot to specify its directory in the OS specific library path environment variable.
    The version of the sapjcorfc library found via the sapjco.jar directory or the java.library.path system property is not the required version (the version numbers and dates of the JCo middleware and the JCo library must be equal).
    The version of the rfccm | librfc32 library found via the OS specific library path environment variable is too old (for example you forgot to copy the librfc32.dll to the <WinDir>\system32 directory and an older version is loaded from there).
    The sapjcorfc library, the rfccm | librfc32 library or both lack the execute permission flag.
    The sapjcorfc library, the rfccm | librfc32 library or both do not have the same bit width as the JVM.
    The sapjcorfc library, the rfccm | librfc32 library or both were from a different JCo distribution and are not for use with your operating system and/or your hardware processor.
    The sapjcorfc library, the rfccm | librfc32 library or both require a higher operating system version.

  • How to enable JMS logging to capture message body for Uniform Distributed Q

    Hi All,
    we need to log JMS message body for our PROD env. but we do not see any "All Body" option in JMSQueue-> logging for our Uniform Distributed Queue.
    Please let me know how can we achieve our requirement.
    Thanks in Advance.

    got the solution.
    This is a know bug - [ID 1377584.1]
    adding below parameters in config/jms file should do the requirement.:
    <message-logging-params>
    <message-logging-enabled>true</message-logging-enabled>
    <message-logging-format>%header%,JMSCorrelationID,JMSDeliveryMode,JMSDestination,JMSExpiration,JMSMessageID,JMSPriority,JMSRedelivered,JMSReplyTo,JMSTimestamp,JMSType,%properties%,JMSXDeliveryCount,JMSXUserID,JMS_BEA_DeliveryTime,JMS_BEA_RedeliveryLimit,JMS_BEA_UnitOfOrder,*%body%*</message-logging-format>
    </message-logging-params>
    Edited by: Bob on May 10, 2013 11:53 AM

  • Enable Change log in tcod

    Hi All,
    I need to enable Change logs in CJ20n as it is available in VA02
       CJ20n is an Project System module T-code.
    Please its urgent.
    Thanks & Regards,
    Amit.

    Actually, my problem is we changed USER0 field in AUFK table with our own data element, for USER0 we used Z_AUFUSER0 by replacing the existing AUFUSER0 data element, however, we forgot to check the checkbox "Change document" in the "Further Characteristics" tab of our custom data element.
    Hope this helps.

  • Enabling Change log in OUD 11gR2PS2

    Hi Team,
    We are trying to configure reverse LDAP sync between OIM and OUD. OIM has the reconciliation scheduler for user reverse sync. But this depends on change log parameter in OUD. We are trying to enable change log in OUD. But We see that change logs is enabled on enabling the replication topology in OUD. We have a stand alone server and we do not require replication topology. Can we still enable change log in OUD? We need it for updating user locked information from OUD to OIM.
    Note: We are not performing OAM-OIM integration
    Please provide us any helpful solutions.
    Thanks,
    Sunderson SJG

    Hi,
    Change log will only be enabled when you create a replication server. I understand that is an overhead, but that is how OUD is build. This is very well document within the oracle docs.
    HTH.

  • Steps to Enable Archive log - RAC 10gR2(10.2.04)

    Hi
    Can anyone help on steps to enable archive log in RAC + ASM environment.
    db version- 10.2.0.4 , filesystem - ASM, Two nodes(db1,db2)
    Regards & Thanks

    you can follow below steps to configure your RAC database archive/noarchive log mode
    Putting the database into archive/noarchivelog mode in RAC environment:
    ========================================================================
    1. Set cluster_database=false for the instance.
    alter system set cluster_database=false scope=spfile sid='PROD1';
    2. Shutdown all the instances accessing the database.
    srvctl stop database -d prod
    3. Mount the database using the local instance.
    startup mount
    4. Enabling archiving / noarchiving
    alter database archivelog;
    OR
    alter database noarchivelog;
    5. Change the parameter cluster_database=true for the instance prod1.
    alter system set cluster_database=true scope=spfile sid='PROD1';
    6. Shutdown the local database.
    shutdown
    7. Bring up all the instances.
    srvctl start database -d prod

  • Having trouble displaying the Logged in Customer details.  The customer is able to register himself

    Having trouble displaying the Logged in Customer details.  The customer is able to register himself to my site but when he enters his username and password I don't know how to display the welcome username message and switch the login link to logout. Even afte the customer is logged in it still shows login. Please look at the image for more details.

    Thanks Sidney, that worked........I tried to change the css style of make the log out link to stay in same horizontal line as the Logged in but I can't.(Please see the image) Is it the module that is designed to work this way???
    And one more .....is there a way where I can change the message "No one logged in" to say LogIn.
    Thank you

  • Enabling supplemental logging for many tables

    Hi All,
    Oracle9i Enterprise Edition Release 9.2.0.8.0 - 64bit Production
    PL/SQL Release 9.2.0.8.0 - Production
    CORE     9.2.0.8.0     Production
    TNS for Solaris: Version 9.2.0.8.0 - Production
    NLSRTL Version 9.2.0.8.0 - Production
    I have 200 tables where i need to enable supplement logging.
    ALTER TABLE table_name ADD SUPPLEMENTAL LOG DATA (ALL) COLUMNS ==>not working==>ORA-00905: missing keyword
    so iam manually enabling the supplement logging
    alter table EMP_PER ADD SUPPLEMENTAL LOG GROUP EMP_PE_SLOG3(END_ADDR_ORG_ID,LOA_END_DT,LAST_PROMO_DT,LAST_ANNUAL_RVW_DT,HIRE_DT,CURR_SALARY_AMT,CURR_BONUS_TGT_PCT,CURR_AVAIL_UNTIL,COST_PER_HR)always;
    But as few of the tables are having more then 400 columns its taking lot of time to break the query into many group.
    Can any one help we with a PLSQL block to generate the script for all the tables

    Thanks Cj for your reply.
    I have checked the whole presensentaion but the issue is when we have more then 33 columns then we need to create a new log group to fit in else we are getting max column exceed.
    So now iam writting the queries manaually..for all the 200 tables...which is taking ,more time
    so could u hel;p me out with a proc or script or dynamic sql which can fetch me the supplement enabling query for many tables

  • Enable Verbose Logging while running the propagation script

    I have created two weblogic portal domains one in DEV, and other in TEST. Each domain is a cluster of two managed servers. Portal content propagation script is failing and I have opened a support case with Oracle. Support engineer has asked me to run the propagation script after enabling verbose logging. He also provided a link as reference. [Propagation Topic - Enabling Verbose Logging|http://download.oracle.com/docs/cd/E13218_01/wlp/docs102/prodOps/propToolAdvanced.html#wp1071933]
    I am a weblogic administrator, not a developer, I don't have access any of my development team until Monday. When I spoke with Support engineer earlier he said it can be accomplished using deployment plan.
    Does anybody have any detail instructions or sample I can use?

    Thanks Deepak for a very quick response. Online commit fails. There are hundreds of errors in the file, I am copying first few errors.
    ============================
    WARNING (Dec 16, 2009 7:35:14 PM PST): Resource [Application:portalservices:myenergyweb.WebApp:myenergyweb.Library:waystoSave.Portlet], Manual Explanation [This portlet definition is based on a .portlet file. If changes have been made to the .portlet file make sure to move the updated .portlet file to the destination application. If changes to the definition have been made using the Portal Administration Tools then propagation will make the necessary updates.].
    INFO (Dec 16, 2009 7:35:14 PM PST): The commit operation will attempt to process [777] elections.
    ERROR (Dec 16, 2009 8:36:58 PM PST): The commit operation failed to process [442] elections.
    ERROR (Dec 16, 2009 8:36:58 PM PST): [Application:portalservices:myenergyweb.WebApp:myenergyweb.Library:Account.Portlet] failed to [update]
    ERROR (Dec 16, 2009 8:36:58 PM PST): [Application:portalservices:myenergyweb.WebApp:myenergyweb.Library:Account.Portlet:Account.PortletInst] failed to [update]
    ERROR (Dec 16, 2009 8:36:58 PM PST): [Application:portalservices:myenergyweb.WebApp:myenergyweb.Library:Account.Producer] failed to [update]
    ERROR (Dec 16, 2009 8:36:58 PM PST): [Application:portalservices:myenergyweb.WebApp:myenergyweb.Library:EditPhoneEmail.Portlet] failed to [update]
    ERROR (Dec 16, 2009 8:36:58 PM PST): [Application:portalservices:myenergyweb.WebApp:myenergyweb.Library:EditPhoneEmail.Portlet:EditPhoneEmail.PortletInst] failed to [update]
    ERROR (Dec 16, 2009 8:36:58 PM PST): [Application:portalservices:myenergyweb.WebApp:myenergyweb.Library:EditPrimaryBilling.Portlet] failed to [update]
    ============================
    Edited by: user8009444 on Dec 17, 2009 9:19 PM

  • Nexus - enable remote logging of entered commands

    Hi all!
    Is there same way to enable remote logging of entered commands on Nexus platform? I found only how to do it with aaa and tacacs+, but we do not have such? In classic IOS it was quite easy to do.
    Thanks.

    Hi Igor
    Nexus has internal accounting log: sh accouting log
    But it can be sent only to the accounting server, not to a syslog server.
    If you want - you man manually export it to some log.
    HTH,
    Alex

Maybe you are looking for