none
Exchange 2010 Mgt Console

    Întrebare

  • I am having issues when starting up EMS or EMC as certain users from a Windows 2008 R2 server that has the Exchange 2010 Management Tools installed.  This server is the eqv of a TS Srver in 2003 terms.

    Under my account they run without any issues.  I see no errors.

    For the EMS under cetain user accounts I see the following error:

    VERBOSE: Connecting to serverfqdn

    Connecting to remote server failed with the following error message : The WinRM client cannot process the request. It cannot determine the content type of the HTTP response from the destination computer. The content type is absent or invalid. For more information, see the about_Remote_Troubleshooting Help topic.
        + CategoryInfo          : OpenError: (System.Manageme....RemoteRunspace:RemoteRunspace) [], PSRemotingTransportExc
       eption
        + FullyQualifiedErrorId : PSSessionOpenFailed

    It then looks for all servers within the domain, and fails:

    Failed to connect to an Exchange server in the current site.
    Enter the server FQDN where you want to connect.:

    I have tried many fixes:

    I have given the user the same permission I have, which is a member of the Exchange Organization Administrators group.

    I have tried adding them to Domain Admins.

    The account has RemotePowerShellEnabled

    Looked at the entry:

    http://blogs.technet.com/b/exchange/archive/2010/02/04/3409289.aspx

    The module I think is registered properly, there is an entry for the WSMan  entry in the ApplicationHost.config file.

    The powershell entry in IIS has SSL turned off, and all authentication settings set to disabled.

    I have added IIS WinRM, I have also ran the WinRM quick config.

    I am not sure what else to try with this now any suggestions would be welcomed.

    Julie

    14 februarie 2012 12:14

Răspunsuri

  • Under my account they run without any issues.  I see no errors.

    For the EMS under cetain user accounts I see the following error:

    Hi Julie,

    Did they start the EMS in their own Windows profile? Or Run as different user?

    If possible, please let them Run as different user in your profile to narrow down the issue.

    You can also try to install the Management tool on one client to test.

    Install the Exchange 2010 Management Tools

    http://technet.microsoft.com/en-us/library/bb232090.aspx


    Frank Wang

    TechNet Community Support


    • Editat de Frank.Wang 16 februarie 2012 03:46
    • Marcat ca răspuns de Frank.Wang 21 februarie 2012 02:03
    16 februarie 2012 03:43
  • Sorry for taking so long to post a reply.

    I have managed to resolve the issue.  It turns out that the user was a member of a group, that was a member of many other groups.

    This bloated their AD token and caused the errors we were seeing.

    I managed to find a log in event viewer:

    Log Name:      System

    Source:        Microsoft-Windows-Security-Kerberos

    Date:          13/02/2012 15:24:17

    Event ID:      6

    Task Category: None

    Level:         Warning

    Keywords:      Classic

    User:          N/A

    Computer:      

    Description:

    The kerberos SSPI package generated an output token of size 13829 bytes, which was too large to fit in the token buffer of size 12000 bytes, provided by process id 1852.

     The output SSPI token being too large is probably the result of the user username being a member of a large number of groups.

    Hope this helps anyone else seeing the same problem.

    Julie

    • Marcat ca răspuns de julesw76 2 martie 2012 09:56
    2 martie 2012 09:56

Toate mesajele

  • Did you check this?
    http://blogs.technet.com/b/exchange/archive/2010/12/07/3411644.aspx

    Gulab Prasad,
    MCITP: Exchange Server 2010 | MCITP: Exchange Server 2007
    MCITP: Lync Server 2010 | MCITP: Windows Server 2008
    My Blog | Z-Hire Employee Provisioning App

    14 februarie 2012 13:02
  • I did, had the exact error but the fixes have not helped.  Thanks for your reply.

    Julie

    14 februarie 2012 13:16
  • Under my account they run without any issues.  I see no errors.

    For the EMS under cetain user accounts I see the following error:

    Hi Julie,

    Did they start the EMS in their own Windows profile? Or Run as different user?

    If possible, please let them Run as different user in your profile to narrow down the issue.

    You can also try to install the Management tool on one client to test.

    Install the Exchange 2010 Management Tools

    http://technet.microsoft.com/en-us/library/bb232090.aspx


    Frank Wang

    TechNet Community Support


    • Editat de Frank.Wang 16 februarie 2012 03:46
    • Marcat ca răspuns de Frank.Wang 21 februarie 2012 02:03
    16 februarie 2012 03:43
  • Hi Julie,

    Any updates?


    Frank Wang

    TechNet Community Support


    20 februarie 2012 02:04
  • Sorry for taking so long to post a reply.

    I have managed to resolve the issue.  It turns out that the user was a member of a group, that was a member of many other groups.

    This bloated their AD token and caused the errors we were seeing.

    I managed to find a log in event viewer:

    Log Name:      System

    Source:        Microsoft-Windows-Security-Kerberos

    Date:          13/02/2012 15:24:17

    Event ID:      6

    Task Category: None

    Level:         Warning

    Keywords:      Classic

    User:          N/A

    Computer:      

    Description:

    The kerberos SSPI package generated an output token of size 13829 bytes, which was too large to fit in the token buffer of size 12000 bytes, provided by process id 1852.

     The output SSPI token being too large is probably the result of the user username being a member of a large number of groups.

    Hope this helps anyone else seeing the same problem.

    Julie

    • Marcat ca răspuns de julesw76 2 martie 2012 09:56
    2 martie 2012 09:56