Changing service account for HSI services loses cryptographic key (192412)
The information in this article applies to:
- Microsoft SNA Server 4.0 SP4
This article was previously published under Q192412 SYMPTOMS
Changing the service account for which the HSI (Host Security Integration) services
run under, causes Host Security to function incorrectly.
CAUSE
When Host Security is initially installed, the service user account is given a
cryptographic key based on the user ID that was chosen during the
installation setup process. This information is then taken and put into the registry
and is referenced when the HSI services start.
If the user account has changed, it will not match the original
cryptographic key information, causing the Host Account Cache (HAC) to become
corrupted and HAC lookups to fail. Reviewing the application log in the Event
Viewer will show the following errors coming from source SNA Host Security:
Event ID 1244
Unable to import cryptographic key into container Supplied code
0x8009000d
Event ID 594
Host Process - was unable to create connection handle to connect to PMP
Event ID 629
Host Process - was unable to create connection handle to connect to UDB
WORKAROUND
Use the original Service Account and password that the Host Security Services
were initially installed under.
STATUS
Microsoft has confirmed that this is a problem in SNA Server Service Pack 4.
Modification Type: | Major | Last Reviewed: | 6/24/2004 |
---|
Keywords: | kbsnaonly kbbug kbpending KB192412 |
---|
|