Answered Policy Type Configuring error

  • יום שישי 18 דצמבר 2009 19:54
     
     
    Trying to change the Policy Type from local and I get a Unhandled exception "Index was outside the bounds of the array"
    I don't know what's causing it any ideas?

    System.IndexOutOfRangeException: Index was outside the bounds of the array.
       at Microsoft.EnterpriseManagement.SCE.Internal.UI.Console.Administration.EssentialsConfigCompletion.LaunchSCECertFile(ConfigurationWizardData data)
       at Microsoft.EnterpriseManagement.SCE.Internal.UI.Console.Administration.EssentialsConfigCompletion.ListViewResultsClick(Object sender, EventArgs e)
       at System.Windows.Forms.Control.OnClick(EventArgs e)
       at System.Windows.Forms.ListView.WmReflectNotify(Message& m)
       at System.Windows.Forms.ListView.WndProc(Message& m)
       at System.Windows.Forms.Control.ControlNativeWindow.WndProc(Message& m)
       at System.Windows.Forms.NativeWindow.Callback(IntPtr hWnd, Int32 msg, IntPtr wparam, IntPtr lparam)

כל התגובות

  • יום שישי 18 דצמבר 2009 21:26
    מנחה דיון
     
     



     Hi Fraser,

    You can uninstalling the Local Policy using the SCECertPolicyConfigUtil.exe tool and change to domain policy running the same tool.


    Command

    SCECertPolicyConfigUtil.exe /ManagementGroup <management group name> /uninstall

    To configure to Domain Policy

    SCECertPolicyConfigUtil.exe /ManagementGroup /PolicyType Domain /SCEServer <Essentials Server FQDN> /AEMFileShare /AEMPort 51906 /ConfigureAEM true

    For the above error, you need to send us the verbose ETL trace log.

    Thanks
    Ranjith A

     

     

  • יום שני 21 דצמבר 2009 20:20
     
     
    I was able to delete the local policy but now i can't get the domain policy to configure.
    This is the error log it gave me.

    [12-21-2009 14:17:43] SCECert Log -- Starting Log --
    [12-21-2009 14:17:43] CreateCertAndConfigureGroupPolicyDoWork: Params (ManagementGroup = access-manageme-mg) (SCEServer = access-management.cable.access) (LocalPolicy = 0) (RemoteControl = 0) (AEM = 1) (PolicyType = 0)(Firewall = 0)
     
    [12-21-2009 14:17:43] Creating WSUS Certificate..
    [12-21-2009 14:17:43] CreateWSUSCodeSigningCertificate: Params : C:\Program Files\System Center Essentials\\Certificates\WSUSCodeSigningCert.cer
    [12-21-2009 14:17:47] CreateWSUSCodeSigningCertificate: Got the code signing certificate from WSUS
    [12-21-2009 14:17:47] CreateWSUSCertificate: WSUS Codesigning Certificate created successfully.
    [12-21-2009 14:17:47] CreateSelfSignedCertificate:  Exporting Certs.
    [12-21-2009 14:17:47] CreateAndConfigureCertificates: SSL Certificate created successfully.
    [12-21-2009 14:17:47] CreateAndDeployCert:  Installing Cert.
    [12-21-2009 14:17:48] CreateGPOIfNotExist: Trying to find if GPO exist at (null) 
    [12-21-2009 14:17:48] GetADRoot: Initialized PDC with...
    [12-21-2009 14:17:48] LDAP://accessfiles.cable.access/DC=cable,DC=access
    [12-21-2009 14:17:48] FindObject: Trying to search SearchBase LDAP query LDAP://accessfiles.cable.access/CN=Policies,CN=System,DC=cable,DC=access 
    [12-21-2009 14:17:48] FindObject: Filter applied for search is (&(objectClass=groupPolicyContainer)(displayName=System Center Essentials All Computers Policy)) 
    [12-21-2009 14:17:48] Trying to open GPO located at LDAP://CN={B9EAC8C8-826A-46F4-AC02-0F5869BE4211},CN=Policies,CN=System,DC=cable,DC=access 
    [12-21-2009 14:17:48] DeployCertificates: OpenDSGPO succeeded.
    [12-21-2009 14:17:48] ConfigureSCERules: Params : IsLocalPolicy : False, SCEServer : access-management.cable.access, AEMFileShare : \\access-management\aemshare, RemoteControl : False, AEM : True, Firewall : False
    [12-21-2009 14:17:49] ConfigureSCERules: Starting enabling policy-configuration rule and overriding values...
    [12-21-2009 14:17:49] ConfigureSCERules: Overridden PolicyType
    [12-21-2009 14:17:49] ConfigureSCERules: Enabled the Rule...
    [12-21-2009 14:17:49] ConfigureSCERules: Overridden SCEServer
    [12-21-2009 14:17:49] ConfigureSCERules: Overridden AEM fileshare
    [12-21-2009 14:17:49] ConfigureSCERules: Overridden AEM port
    [12-21-2009 14:17:49] ConfigureSCERules: Overridden RemoteControl
    [12-21-2009 14:17:49] ConfigureSCERules: Overridden firewall
    [12-21-2009 14:17:52] ConfigureSCERules: ConfigureSceRules Success
    [12-21-2009 14:17:52] ConfigureDomainPolicyObjects: Creating GPO SCE Managed Computers Group Policy (access-manageme-mg) :
     
    [12-21-2009 14:17:52] CreateGPOIfNotExist: Trying to find if GPO exist at (null) 
    [12-21-2009 14:17:52] FindObject: Trying to search SearchBase LDAP query LDAP://accessfiles.cable.access/CN=Policies,CN=System,DC=cable,DC=access 
    [12-21-2009 14:17:52] FindObject: Filter applied for search is (&(objectClass=groupPolicyContainer)(displayName=SCE Managed Computers Group Policy (access-manageme-mg))) 
    [12-21-2009 14:17:52] CreateGPOIfNotExist: GPO does not exist at LDAP://accessfiles.cable.access/DC=cable,DC=access. Hence creating new one.
    [12-21-2009 14:17:52] FindObject: Trying to search SearchBase LDAP query LDAP://accessfiles.cable.access/CN=Policies,CN=System,DC=cable,DC=access 
    [12-21-2009 14:17:52] FindObject: Filter applied for search is (&(objectClass=groupPolicyContainer)(displayName=SCE Managed Computers Group Policy (access-manageme-mg))) 
    [12-21-2009 14:17:53] CreateGPOIfNotExist: GPO created successfully at LDAP://CN={D547415B-5166-4CE7-8435-EDF75AC1F824},CN=Policies,CN=System,DC=cable,DC=access 
    [12-21-2009 14:17:53] CreateSecurityGroupAndSetGroupPolicyACLs: Params : SGName : SCE Managed Computers (access-manageme-mg), SGACL: CABLE\ACCESS-MANAGEME$, gpoName: SCE Managed Computers Group Policy (access-manageme-mg)
    [12-21-2009 14:17:53] CreateSecurityGroupAndSetGroupPolicyACLs: SearchDirectory: not found (&(objectClass=group)(cn=SCE Managed Computers (access-manageme-mg))(groupType=-2147483640))
    [12-21-2009 14:17:53] CreateSecurityGroupAndSetGroupPolicyACLs: securityGroup with UNIVERSAL_SG not found: now searching with GLOBAL_SG
    [12-21-2009 14:17:53] CreateSecurityGroupAndSetGroupPolicyACLs: SearchDirectory: not found (&(objectClass=group)(cn=SCE Managed Computers (access-manageme-mg))(groupType=-2147483646))
    [12-21-2009 14:17:53] CreateSecurityGroupAndSetGroupPolicyACLs: SearchDirectory: not found (&(objectCategory=computer)(cn=Access-Management))
    [12-21-2009 14:17:53] CreateSecurityGroupAndSetGroupPolicyACLs: Error : Could not find SCE Server in active directory Access-Management
    [12-21-2009 14:17:53] CreateSecurityGroupAndSetGroupPolicyACLs: StackTrace:    at Microsoft.SystemCenter.Essentials.Policy.EssentialsPolicyConfiguration.CreateSecurityGroupAndSetGroupPolicyAcls(String logFile, String securityGroupName, String securityGroupAccess, String gpoName, String gpoPath, Boolean installed)
    [12-21-2009 14:17:53] CreateSecurityGroupAndSetGroupPolicyACLs: CreateSecurityGroupAndSetGroupPolicyACLs failed with error code of: 0x80131577
     
    [12-21-2009 14:17:53] ConfigureDomainPolicyObjects: CreateSecurityGroupAndSetGroupPolicyACLs failed with error code of: 0x80131577
     
    [12-21-2009 14:17:53] ConfigureSCEServer: ConfigureDomainPolicyObjects failed with error code of: 0x80131577
     
    [12-21-2009 14:17:53] CreateCertAndConfigureGroupPolicy: Returned from thread
    [12-21-2009 14:17:53] CreateCertAndConfigureGroupPolicy: Worker thread failed with error code of: 0x80131577
     
    [12-21-2009 14:17:53] CreateCertAndConfigureGroupPolicy: WaitForSingleObject returned: 0x80131577
     
  • יום שלישי 05 ינואר 2010 17:37
     
     תשובה
    Hello,

    It looks like it is not able to find the Computer with name "Access-Management", and hence security group is not getting created. Could you please try two things?

    [Note: It would be easy to do these operations on a DC. Also make sure you use the same user credentials that you used to run the Essentials]

    1. Open the "Active Directory Users and Computers" mmc snap-in (dsa.msc from commandline), and goto "Computers" containers to see if 'Access-Management' is present?

    2. Try to create a test security group by following steps:
        a. Right-click on users
        b. Click on New -> Group
        c. Use some TestSecirtyGroup as the name
        d. Keep the group scope to "Universal" and Group Type to "Security"
        e. Click on OK

    Please let us know if you are able to create the group. You can delete the group afterwords.
    This posting is provided "AS IS" with no warranties, and confers no rights.
    • סומן כתשובה על-ידי LFraser יום שישי 29 ינואר 2010 15:41
    •