KDS Root Key Issues


hi guys,

so issue started during test deployment of adfs. wast use gmsa used option "create group managed service account" failed during install.

troubleshooting:
- patch & reboot dc
- enable windows firewall
- check root key showing ok in adss/services
- tried different dc
- add new kds root key
- wait 10hrs
- checked event log

after going create gmsa manually. here process:

ps c:\users\super51b> get-kdsrootkey


attributeofwrongformat :
keyvalue               : {99, 116, 39, 17...}
effectivetime          : 1/04/2014 7:48:43 p.m.
creationtime           : 1/04/2014 7:48:43 p.m.
isformatvalid          : true
domaincontroller       : cn=************=****,ou=domain controllers,dc=***,dc=local
serverconfiguration    : microsoft.keydistributionservice.cmdlets.kdsserverconfiguration
keyid                  : **************-******-******-******-**************
versionnumber          : 1



ps c:\users\super51b> test-kdsrootkey -keyid "**************-******-******-******-**************"
test-kdsrootkey : there no more endpoints available endpoint mapper. (exception hresult: 0x800706d9)
@ line:1 char:1
+ test-kdsrootkey -keyid "**************-******-******-******-**************"
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    + categoryinfo          : notspecified: (:) [test-kdsrootkey], comexception
    + fullyqualifiederrorid : there no more endpoints available endpoint mapper. (exception hresult:
    0x800706d9),microsoft.keydistributionservice.cmdlets.testkdsrootkeycommand

then thought try create account anyway ran:

new-adserviceaccount -name <serviceaccountname> -dnshostname <fqdn> -principalsallowedtoretrievemanagedpassword <group> -serviceprincipalnames <spn1,spn2,…>

but recived same error.

i tried adding new kds root key got same error.

a bit of research brings exchange install issues relate the windows firewall being disabled enabled ran again got same result.

i don't wan't delete kds root key in-case in us.

anyone seen before???

you need have dc running 2012+ in default dc container not in sub ous/containers massive waste of time such retarded issue.


Windows Server  >  Windows Server 2012 General



Comments

Popular posts from this blog

CRL Revocation always failed

Failed to query the results of bpa xpath

0x300000d errors in Microsoft Remote Desktop client