SceCli errors after installing OCSP Responder
security policies propagated warning. 0x534 : no mapping between account names , security ids done.
<here lot of text provided here: http://support.microsoft.com/kb/324383 >
i found problem accounts:
cannot find ocspisapiapppool.
cannot find defaultapppool.
cannot find wdiservicehost.
to these accounts are assigned rights , priveleges in default domain controllers policy. can safely remove these accounts gpo?
thanks!
[http://www.sysadmins.lv] enjoy automation of tools within windows-based, .net aware, wpf accessible, multi-processes on same ip / port usage, admin's automation tool, powershell.exe! © flowering weeds
hi,
thanks information.
i did lot of tests , noticed accounts created locally , added polices after installed related roles on server. however, according report of default domain controller policy uploaded, found name of accounts displayed incorrectly in policies. should be:
iis apppool\ocspisapiapppool.
iis apppool\defaultapppool.
nt service\wdiservicehost
that’s why system cannot resolve account name when policy applies.
please refer following table , correct policy settings accordingly:
| policy | setting |
| adjust memory quotas process | iis apppool\ocspisapiapppool, nt authority\local service, nt authority\network service, builtin\administrators, iis apppool\defaultapppool |
| generate security audits | nt authority\local service, nt authority\network service, iis apppool\defaultapppool, iis apppool\ocspisapiapppool |
| replace process level token | iis apppool\ocspisapiapppool, nt authority\local service, nt authority\network service, iis apppool\defaultapppool |
| profile system performance | builtin\administrators, nt service\wdiservicehost |
note: when add accounts policies, need input name directly (iis apppool\ocspisapiapppool, example) in “add user or group” dialog box instead of click browse button , check names.
if there unclear, please feel free let me know.
joson zhou
technet subscriber support in forum
if have feedback on our support, please contact tngfb@microsoft.composting provided "as is" no warranties, , confers no rights.
Windows Server > Security
Comments
Post a Comment