Jump to content

Recommended Posts

Posted

Bit more info, if it means anything to anyone:

 

Ive set my spn like this:

 

setspn -a PCNSCLNT/dc1.mydomain.com mydomain\ilm 

 

where dc1 is the server running ILM, mydomain.com is the domain, and ilm is the Service account Ive created.

 

That seemed to work OK.

 

But when I tried to run the pcnscfg.exe I got an error that the SPN was not found in the domain:

 

pcnscfg addtarget /n:PCNSCLNT /a:dc1.mydomain.com /s:PCNSCLNT /fi:"Students" /f:3

 

I get this warning:

 

Warning: The Service Principal Name you specified could not be found on any accounts in this domain. This target configuration will not be able to deliver passwords if the Service Principle Name is not configured properly.

 

Could someone please point out any mistakes in my commands please/

Posted

I'm guessing you've read through this already but just in case here's the step by step info on PCNS

 

Implementing the Automated Password Synchronization Solution - Step-by-Step

 

I've also read about gotchas with password complexity differences between AD and Live so watch out for those at some point as well.

 

I'm not best convinced by this setup at the moment, hoping Forefront 2010 has a simpler system for managing the passwords. As it stands we're lucky that we won't have to worry about it as we're assigning random number sequences for our students (so many part-time ones we really don't want to be managing password resets all day long!)

Posted
It might be worth posting on the outlook live administrators forum, I'm not using ILM myself so can't help out

 

Cheers, done that. Also logged an issue with the live@edu helpdesk so will hopefully hear somehting soon.

  • Thanks 1
Posted
I'm guessing you've read through this already but just in case here's the step by step info on PCNS

 

Implementing the Automated Password Synchronization Solution - Step-by-Step

 

I've also read about gotchas with password complexity differences between AD and Live so watch out for those at some point as well.

 

I'm not best convinced by this setup at the moment, hoping Forefront 2010 has a simpler system for managing the passwords. As it stands we're lucky that we won't have to worry about it as we're assigning random number sequences for our students (so many part-time ones we really don't want to be managing password resets all day long!)

 

Aye thats what Ive been following.. its the PCNSCLNT bit and the miis thing Im a bit confused about.

 

Weve already forced a password policy update domain wide in anticipation of live@edu, and Ive got ILM provisioning the accounts no worries with just it doing a random passowrd, its just the creating the accounts and sending up their existing passwords Im failing at.

 

PS. ILM for live@edu seems to be really reasonably priced for education

Posted

OK so I have resolved this issue myself...

 

The line should have been

 

pcnscfg addtarget /n:PCNSCLNT /a:dc1.mydomain.com /s:PCNSCLNT/dc1.mydomain.com /fi:"Students" /f:3

 

So now that bit works..

 

But the password sync is still failing badly..

Posted

Password sync is not working. When i do the StartSync -Firstrun, it creates the users, and I get no errors in the event log. However I cannot login the new users with their AD password. When I try to just change a users password that has just been created. I get the following errors:

 

Log Name:      Application
Source:        PCNSSVC
Date:          19/03/2010 2:50:37 PM
Event ID:      2100
Task Category: (1)
Level:         Information
Keywords:      Classic
User:          N/A
Computer:      DC5.mydomain.com
Description:
The password notification has been delivered to all targets.

Tracking ID: a00c2d15-68b8-463a-ae6c-a49fe96dac30
User GUID: 508df6ed-949a-4444-9559-157984865ee2
User: ADMINISTRATION\208222
Targets: PCNSCLNT
Event Xml:

 
   
   2100
   4
   1
   0x80000000000000
   
   4495
   Application
   DC5.mydomain.com
   
 
 
   a00c2d15-68b8-463a-ae6c-a49fe96dac30
   508df6ed-949a-4444-9559-157984865ee2
   ADMINISTRATION\208222
   PCNSCLNT
   
   
 


--------------------------
Log Name:      Application
Source:        OLMA
Date:          19/03/2010 2:50:41 PM
Event ID:      1010
Task Category: (1)
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      DC5.mydomain.com
Description:
Access is denied. Error Message: Connecting to remote server failed with the following error message : Access is denied. For more information, see the about_Remote_Troubleshooting Help topic.
Event Xml:

 
   
   1010
   2
   1
   0x80000000000000
   
   4496
   Application
   DC5.mydomain.com
   
 
 
   Connecting to remote server failed with the following error message : Access is denied. For more information, see the about_Remote_Troubleshooting Help topic.
 


---------------
Log Name:      Application
Source:        MSExchange Common
Date:          19/03/2010 2:50:41 PM
Event ID:      4999
Task Category: (1)
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      DC5.mydomain.com
Description:
The description for Event ID 4999 from source MSExchange Common cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event:

652
E12
c-buddy-DBG-x86
14.00.0650.021
miiserver
M.E.GALSync.ManagementAgent
M.E.X.PSDataProvider.InvokeCmdlet
M.MetadirectoryServices.AccessDeniedException
3422
14.00.0650.021
False

the message resource is present but the message is not found in the string/message table

Event Xml:

 
   
   4999
   2
   1
   0x80000000000000
   
   4497
   Application
   DC5.mydomain.com
   
 
 
   652
   E12
   c-buddy-DBG-x86
   14.00.0650.021
   miiserver
   M.E.GALSync.ManagementAgent
   M.E.X.PSDataProvider.InvokeCmdlet
   M.MetadirectoryServices.AccessDeniedException
   3422
   14.00.0650.021
   False
   
   
 

---------------
Log Name:      Application
Source:        MIIServer
Date:          19/03/2010 2:50:41 PM
Event ID:      6800
Task Category: (7)
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      DC5.mydomain.com
Description:
The password management extension encountered an error.
The stack trace is:

"Microsoft.MetadirectoryServices.PasswordExtensionException: Error in the application.
  at Microsoft.Exchange.XmaConnector.PSDataProvider.ReportError(Exception e, ScorecardCounter scorecard)
  at Microsoft.Exchange.XmaConnector.PSDataProvider.InvokeCmdlet(PSCommand cmd)
  at Microsoft.Exchange.XmaConnector.PSDataProvider.SetDataObject(String task, Dictionary`2 csentry, String[] supportedParameters, Dictionary`2 defaultValues)
  at Microsoft.Exchange.XmaConnector.PSDataProvider.SetSyncMailbox(Dictionary`2 csentry)
  at Microsoft.Exchange.XmaConnector.XmaExportExLabs.SetPassword(Dictionary`2 Entry)
  at Microsoft.Exchange.XmaConnector.PWExtension.IlmPWExtension.SetPassword(CSEntry csentry, String NewPassword)
  at Microsoft.Exchange.XmaConnector.PWExtension.IlmPWExtension.SetPassword(CSEntry csentry, String NewPassword)
Microsoft Identity Integration Server 3.3.1139.2"
Event Xml:

 
   
   6800
   2
   7
   0x80000000000000
   
   4498
   Application
   DC5.mydomain.com
   
 
 
   Microsoft.MetadirectoryServices.PasswordExtensionException: Error in the application.
  at Microsoft.Exchange.XmaConnector.PSDataProvider.ReportError(Exception e, ScorecardCounter scorecard)
  at Microsoft.Exchange.XmaConnector.PSDataProvider.InvokeCmdlet(PSCommand cmd)
  at Microsoft.Exchange.XmaConnector.PSDataProvider.SetDataObject(String task, Dictionary`2 csentry, String[] supportedParameters, Dictionary`2 defaultValues)
  at Microsoft.Exchange.XmaConnector.PSDataProvider.SetSyncMailbox(Dictionary`2 csentry)
  at Microsoft.Exchange.XmaConnector.XmaExportExLabs.SetPassword(Dictionary`2 Entry)
  at Microsoft.Exchange.XmaConnector.PWExtension.IlmPWExtension.SetPassword(CSEntry csentry, String NewPassword)
  at Microsoft.Exchange.XmaConnector.PWExtension.IlmPWExtension.SetPassword(CSEntry csentry, String NewPassword)
Microsoft Identity Integration Server 3.3.1139.2
 

 

Could someone please have a look through the errors above, and see if they can spot anything obvious please?

Posted

I deleted the whole ILM server (joys of virtualisation) and started fresh.

 

Took me the whole day (started at 11am and its now 11pm) But I now have ILM syncing passwords with Live@edu :)

  • 2 weeks later...
Posted

Hello can't figure out the syntax to configure the Pcnscfg.exe I get this error:

 

'Pcnscfg.exe' is not recognized as an internal or external command,

operable program or batch file.

 

I followed these instructions: Implementing the Automated Password Synchronization Solution - Step-by-Step

and tried also not putting the extension .exe, but I still get the same issue.

 

When I finish step 2 I checked if the installation went thru fine and this is the out put to the setspn -L OLSync command: "Registered ServicePrincipalNames for CN=OLSync,CN=Users,DC=adtest,DC=byuh,DC: "

Seems to be configured correctly but now I'm stuck because when I go to the next step I that message that PCNSCFG is not recognized.

 

Can some one help please?

 

Thanks

 

Manu

 

P.S.

I wrote the same question on the Outlook live answers website but I keep getting ignored...very frustrating.

Posted
Hello can't figure out the syntax to configure the Pcnscfg.exe I get this error:

 

'Pcnscfg.exe' is not recognized as an internal or external command,

operable program or batch file.

 

I followed these instructions: Implementing the Automated Password Synchronization Solution - Step-by-Step

and tried also not putting the extension .exe, but I still get the same issue.

 

When I finish step 2 I checked if the installation went thru fine and this is the out put to the setspn -L OLSync command: "Registered ServicePrincipalNames for CN=OLSync,CN=Users,DC=adtest,DC=byuh,DC: "

Seems to be configured correctly but now I'm stuck because when I go to the next step I that message that PCNSCFG is not recognized.

 

Can some one help please?

 

Thanks

 

Manu

 

P.S.

I wrote the same question on the Outlook live answers website but I keep getting ignored...very frustrating.

 

The output to your setspn -L OLSync is incorrect. It should actually give you an extra line after that

 

C:\>setspn -L ILMServiceAccount
Registered ServicePrincipalNames for CN=ILMServiceAccount,CN=Users,DC=admin,DC=myschool,DC=nsw,DC=edu,DC=au:
       PCNSCLNT/ilm.admin.myschool.nsw.edu.au

 

What command did you run for the setspn?

Posted

This is the command that I ran:setspn.exe -A PCNSCLNT/DCTEST.ADTEST.xxx.EDU\OLSync

DCtest is the test domain controller adtest.xxx.edu is the domain and OLSync is the account that I created to run OLsync.

 

What am I doing wrong?

Is this why the 'Pcnscfg.exe' is not working?

 

Thanks

Manu

Posted

 setspn.exe -A PCNSCLNT/DCTEST.ADTEST.xxx.EDU nameofyourdomain\OLSync

 

then the PCNS line would be

 

pcnscfg.exe addtarget /n:PCNSCLNT /a:DCTEST.ADTEST.xxx.EDU /s:PCSNCLNT/DCTEST.ADTEST.xxx.EDU /fi:"Domain Users" /f:3

 

Where it says Domain Users, you can change that to a more specified group. Eg, I used a group called Students.

 

Make sure you clear any wrong entries by using

setspn.exe -D 

 

and

pcsncfg.exe DELETETARGET /n:

 

You can check what they look like with

setspn.exe -L OLsync

and

pcnscfg.exe -LIST

 

hope this helps

Posted

Thanks Rabbieburns now I get the correct code for setspn, but no matter what I write I get the same error for the PCNSCFG, I tried to change folder from where I executed it but still the same. I tried to do a search for the actual file on the computer but I could not find it. I believe not to be installed, where do I get it and install it?

Thanks

 

Manu

Posted

Its on the ILM cd in a folder \MIIS\Password Synchronization\ there is a x86 and x64 version.

 

You need to install it on every single one of your Domain Controllers.

 

and then you need to change to the C:\Program Files\Microsoft Password Change Notification\ folder and run the command from there

Posted

Thanks!

I had it installed but I was looking in the wrong folder. This is the message that I got:

 

C:\Program Files\Microsoft Password Change Notification>pcnscfg.exe addtarget /n

:PCNSCLNT /a: DCTEST.ADTEST.byuh.EDU /s:PCSNCLNT/DCTEST.ADTEST.xxx.EDU /fi:"Doma

in Users" /f:3

Warning: The Service Principal Name you specified could not be found on any

accounts in this domain. This target configuration will not be able to deliver

passwords if the Service Principal Name is not configured properly.

 

Target Name...........: PCNSCLNT

Target GUID...........: CF420837-BDB5-4D69-98D4-D8197C0CAA33

Server FQDN or Address: DCTEST.ADTEST.xxx.EDU

Service Principal Name: PCSNCLNT/DCTEST.ADTEST.xxx.EDU

Authentication Service: Kerberos

Inclusion Group Name..: ADTEST\Domain Users

Exclusion Group Name..:

Keep Alive Interval...: 0 seconds

User Name Format......: 3

Queue Warning Level...: 0

Queue Warning Interval: 30 minutes

Disabled..............: False

 

Is this how should it look like at this point? There is another step to be completed, will that fix the message that says that is not configured right?

Thanks very much for your help.

 

Cheers

 

Manu

Posted

Thanks very much Rabbie.

I get this message when I ran the command though:

"C:\Program Files\Microsoft Password Change Notification>pcnscfg.exe addtarget /n

:PCNSCLNT /a:DCTEST.ADTEST.byuh.EDU /s:PCSNCLNT/DCTEST.ADTEST.byuh.EDU /fi:"Doma

in Users" /f:3

Warning: The Service Principal Name you specified could not be found on any

accounts in this domain. This target configuration will not be able to deliver

passwords if the Service Principal Name is not configured properly.

 

Target Name...........: PCNSCLNT

Target GUID...........: CF420837-BDB5-4D69-98D4-D8197C0CAA33

Server FQDN or Address: DCTEST.ADTEST.byuh.EDU

Service Principal Name: PCSNCLNT/DCTEST.ADTEST.byuh.EDU

Authentication Service: Kerberos

Inclusion Group Name..: ADTEST\Domain Users

Exclusion Group Name..:

Keep Alive Interval...: 0 seconds

User Name Format......: 3

Queue Warning Level...: 0

Queue Warning Interval: 30 minutes

Disabled..............: False"

So I typed the command "setspn -L OLSync" and I get this message: "Usage: setspn [modifiers switches data] computername

Where 'computername' can be the name or domain\name

 

Modifiers:

-F = perform the duplicate checking on forestwide level

-P = do not show progress (useful for redirecting output to file)

 

Switches:

-R = reset HOST ServicePrincipalName

Usage: setspn -R computername

-A = add arbitrary SPN

Usage: setspn -A SPN computername

-S = add arbitrary SPN after verifying no duplicates exist

Usage: setspn -S SPN computername

-D = delete arbitrary SPN

Usage: setspn -D SPN computername

-L = list registered SPNs

Usage: setspn [-L] computername

-Q = query for existence of SPN

Usage: setspn -Q SPN

-X = search for duplicate SPNs

Usage: setspn -X

 

Examples:

setspn -R daserver1

It will register SPN 'HOST/daserver1' and 'HOST/{DNS of daserver1}'

setspn -A http/daserver daserver1

It will register SPN 'http/daserver' for computer 'daserver1'

setspn -D http/daserver daserver1

It will delete SPN 'http/daserver' for computer 'daserver1'

setspn -F -S http/daserver daserver1

It will register SPN 'http/daserver' for computer 'daserver1' if no such SPN exi

sts in the forest"

How is that possible it was working the other day? I ran the command to delete it and recreate it and this is what I get: "C:\>setspn.exe -A PCNSCLNT/DCTEST.ADTEST.BYUH.EDU ADTEST.BYUH.EDU\OLSync

Registering ServicePrincipalNames for CN=OLSync,CN=Users,DC=adtest,DC=byuh,DC=ed

u

PCNSCLNT/DCTEST.ADTEST.BYUH.EDU

Updated object"

I thought I was done and instead I'm back to square 1! I want to cry!

What am I doing wrong? nothing has changed the environment is the same.

 

Manu

Posted

you have made a mistake in your command.

 

"C:\Program Files\Microsoft Password Change Notification>pcnscfg.exe addtarget /n
:PCNSCLNT /aCTEST.ADTEST.byuh.EDU /s:[b]PCSNCLNT[/b]/DCTEST.ADTEST.byuh.EDU /fi:"Doma
in Users" /f:3

 

you have put PCSNCLNT instead of PCNSCLNT

 

(apologies if that was a typo I made previously if you have copied)

Posted

I fixed all the misspellings and now everything looks like it should be, but still can't synchronize the passwords.

Any other clues?

I get this message from the event viewer:

 

" The management agent "Hosted" completed run profile "Delta Import (Stage Only)" with a delta import or delta synchronization step type. The rules configuration has changed since the last full import or full synchronization.

 

User Action

To ensure the updated rules are applied to all objects, a run with step type of full import and full synchronization should be completed."

I appreciate your help.

 

Manu

Posted

thats not an error just a log.

 

When you run .\StartSync.ps -FirstRun

 

Does it create the accounts OK? Do you get a load of green Success text showing?

 

When you change a password on a DC, does it say it was delivered to all targets, or does it give you an error?

Posted

When I run the command .\startSync I get this results:

 

PS C:\Program Files\Microsoft Identity Integration Server\SourceCode\Scripts> .\StartSync

Hosted [Delta Import (Stage Only)] success

OnPremise [Delta Import (Stage Only)] success

OnPremise [Delta Sync] success

Hosted [Delta Sync] success

Hosted [Export] success

Hosted [Delta Import (Stage Only)] success

 

It creates new accounts in WLive for users that I create in the AD, when I reset the password on AD it shows a message that says that the password for that user has been changed, nothing more. So I'm assuming that the password sync is still not working properly.

Manu

Posted

That is looking promising. You wont get any other message in AD after changing the password. The only other thing you will see is an event log from the PCNS Service saying the password was delivered to all targets.

 

Can you login to live@edu with the new password you changed it to?

Posted

ITs just another entry in eventviewer on the domain controller you used to change the password.

 

Have you enabled password sync within ILM and entered the correct live@edu admin account into the relevent places?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...