SceCli errors after installing OCSP Responder


i have domain controller on windows server 2008 r2 enterprise edition. dc hosts aactive directory certificates services , ocsp responder. since several time ago receive message in application event log each time when gp applied computer or user:

security policies propagated warning. 0x534 : no mapping between account names , security ids done.
<here lot of text provided here: http://support.microsoft.com/kb/324383 >

i found problem accounts:
cannot find ocspisapiapppool.
cannot find defaultapppool.
cannot find wdiservicehost.

to these accounts are assigned rights , priveleges in default domain controllers policy. can safely remove these accounts gpo?

thanks!


[http://www.sysadmins.lv] enjoy automation of tools within windows-based, .net aware, wpf accessible, multi-processes on same ip / port usage, admin's automation tool, powershell.exe! © flowering weeds

hi,

 

thanks information.

 

i did lot of tests , noticed accounts created locally , added polices after installed related roles on server. however, according report of default domain controller policy uploaded, found name of accounts displayed incorrectly in policies. should be:

 

iis apppool\ocspisapiapppool.

iis apppool\defaultapppool.

nt service\wdiservicehost

 

that’s why system cannot resolve account name when policy applies.

 

please refer following table , correct policy settings accordingly:

 

policy

setting

   
   

adjust memory quotas process

iis apppool\ocspisapiapppool, nt authority\local service, nt authority\network service, builtin\administrators, iis apppool\defaultapppool

   
   
   
   
   
   
   
   
   

generate security audits

nt authority\local service, nt authority\network service, iis apppool\defaultapppool, iis apppool\ocspisapiapppool

   
   
   
   
   
   
   
   

replace process level token

iis apppool\ocspisapiapppool, nt authority\local service, nt authority\network service, iis apppool\defaultapppool

   
   
   

profile system performance

builtin\administrators, nt service\wdiservicehost

  

 

note: when add accounts policies, need input name directly (iis apppool\ocspisapiapppool, example) in “add user or group” dialog box instead of click browse button , check names.

 

if there unclear, please feel free let me know.

 

joson zhou

technet subscriber support in forum

if have feedback on our support, please contact tngfb@microsoft.com
posting provided "as is" no warranties, , confers no rights.


Windows Server  >  Security



Comments

Popular posts from this blog

2008 Windows Deployment Server Properties Error

Can no longer user MS Update - Files required to use Microsoft Update are no longer registered

How do a find data in one file, search for it in another file and if not found, write a custom message to another file