Password Sync was unstable in FIM 2010.
Dear all.
We have installed and configured the password Synchronization function in FIM 2010 between AD and Oracle using a dll created in Visual Studio 2008 (Framework 3.5), when
we make a password reset the behavior is unstable because sometimes changes the password in Oracle and others do not, this has occurred in tests with different users
We have followed exactly the installation guide and the error is still there, the strangest thing is that Domain Controller logs the following window appears indicating that was successful:
Log Name: Application
Source: PCNSSVC
Date: 19/04/2011 09:48:00 a.m.
Event ID: 2100
Task Category: (1)
Level: Information
Keywords: Classic
User: N/A
Computer: manpowerAD.manpower.ax
Description:
The password notification has been delivered to all targets.
Tracking ID: c3b755f5-a223-460f-b162-13c89baabedb
User GUID: 82717a2a-c15a-4dfe-ab79-68d2ebc7c00c
User: MANPOWER\LSánchez
Targets: FIMServer
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="PCNSSVC" />
<EventID Qualifiers="16384">2100</EventID>
<Level>4</Level>
<Task>1</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2011-04-19T14:48:00.000Z" />
<EventRecordID>22532</EventRecordID>
<Channel>Application</Channel>
<Computer>manpowerAD.manpower.ax</Computer>
<Security />
</System>
<EventData>
<Data>c3b755f5-a223-460f-b162-13c89baabedb</Data>
<Data>82717a2a-c15a-4dfe-ab79-68d2ebc7c00c</Data>
<Data>MANPOWER\LSánchez</Data>
<Data>FIMServer</Data>
Log Name: Application
Source: PCNSSVC
Date: 19/04/2011 09:48:00 a.m.
Event ID: 2201
Task Category: (1)
Level: Information
Keywords: Classic
User: N/A
Computer: manpowerAD.manpower.ax
Description:
The password notification was received from the filter.
Tracking ID: c3b755f5-a223-460f-b162-13c89baabedb
User GUID: 82717a2a-c15a-4dfe-ab79-68d2ebc7c00c
User: MANPOWER\LSánchez
Targets: FIMServer
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="PCNSSVC" />
<EventID Qualifiers="16384">2201</EventID>
<Level>4</Level>
<Task>1</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2011-04-19T14:48:00.000Z" />
<EventRecordID>22531</EventRecordID>
<Channel>Application</Channel>
<Computer>manpowerAD.manpower.ax</Computer>
<Security />
</System>
<EventData>
<Data>c3b755f5-a223-460f-b162-13c89baabedb</Data>
<Data>82717a2a-c15a-4dfe-ab79-68d2ebc7c00c</Data>
<Data>MANPOWER\LSánchez</Data>
<Data>FIMServer</Data>
Here the result for the configuration.
C:\Users\Administrator>setspn -l fimsyncservice
Registered ServicePrincipalNames for CN=FimSyncService,OU=Service Accounts FIM,DC=manpower,DC=ax:
PCNSCLNT/FIMSYNC.manpower.ax
C:\Software\FIM\Password Change Notification Service\x64\Program Files\Microsoft Password Change Notification>pcnscfg LIST
The service configuration is not set. Defaults will be used by the service.
Default Service Configuration
MaxQueueLength........: 0
MaxQueueAge...........: 259200 seconds
MaxNotificationRetries: 0
RetryInterval.........: 60 seconds
Targets
Target Name...........: FIMServer
Target GUID...........: DB292ACF-DA59-4B3D-A4FB-22ED086C3AFD
Server FQDN or Address: fimsync.manpower.ax
Service Principal Name: PCNSCLNT/fimsync.manpower.ax
Authentication Service: Kerberos
Inclusion Group Name..: MANPOWER\Domain Users
Exclusion Group Name..: MANPOWER\Domain Admins
Keep Alive Interval...: 0 seconds
User Name Format......: 3
Queue Warning Level...: 0
Queue Warning Interval: 30 minutes
Disabled..............: False
Total targets: 1
We made some tests but was not successfull,
Can someone tell us if we are omitting any step in the configuration?
Thanks a lot.
April 19th, 2011 11:37am
Hi-
Are there errors logged in the application log of the FIM sync server? Do you have any tracing/instrumentation in your custom password extension to help determine when things are succeeding/failing?My Book - Active Directory, 4th Edition
My Blog - www.briandesmond.com
Free Windows Admin Tool Kit Click here and download it now
April 21st, 2011 12:46am