Sunday 28 September 2014

Services are in starting state in Exchange 2013 Mailbox and CAS role ECP and OWA are not accessible

Today i start to make ready a DR of exchange 2013, the installation of exchange Mailbox and CAS role was already done and after that the server was power off for couple of weeks.
after starting the server i found that the /ECP and OWA were not accessible and  services were in starting state and the exchange management shell was also not connecting to itself and was trying to connect the PR Mailbox CAS servers and giving this error.

"VERBOSE: Connecting to MBXCAS.domain.com
 New-PSSession : [MBXCAS.domain.com] Processing data from remote server MBXCAS.domain.com failed
 with the following error message: The WinRM Shell client cannot process the request. The shell handle passed to the WSMan Shell function is not valid. The shell handle is valid only when WSManCreateShell function completes successfully. Change the request including a valid shell handle and try again. For more information, see the about_Remote_Troubleshooting Help topic.
 At line:1 char:1
 + New-PSSession -ConnectionURI “$connectionUri” -ConfigurationName Microsoft.Excha" 


In event viewer Application logs the following events were there.
Event ID 4027"
Process MSExchangeHMWorker.exe (ExHMWorker) (PID=8440). WCF request (Get Servers for Domain.com) to the Microsoft Exchange Active Directory Topology service on server (TopologyClientTcpEndpoint (localhost)) failed. Make sure that the service is running. In addition, make sure that the network ports that are used by Microsoft Exchange Active Directory Topology service are not blocked by a firewall. The WCF call was retried 3 time(s). Error Details

No Suitable Directory Servers Found in Forest Domain.com Site SiteName and connected Sites"

Event ID 2112

"
Process Microsoft.Exchange.Directory.TopologyService.exe (PID=4400). The Exchange computer DC1.Domain.com does not have Audit Security Privilege on the domain controller DC1.Domain.com. This domain controller will not be used by Exchange Active Directory Provider.
Event ID 2142

"
Process Microsoft.Exchange.Directory.TopologyService.exe (PID=4400) Forest domain.com Topology discovery failed, error details

No Suitable Directory Servers Found in Forest Domain.com Site SiteName and connected Sites..
 
"


after digging into it i came to know that this server computer object was not added in EXCHANGE SERVER group in active directory after adding into this group i restart the server and after restart everything was working fine. Exchange management shell start normally, all services was running normally.

But /ECP and OWA was not accessible.
i open IIS and go to SITE and right click Exchange Back End select Binding and select https and click on edit button and in SSL certificate Select "Microsoft Exchange" certificate but when click on View to check its property then on Certification path Tab this certificate status was inactive.
for this i went to local certificate store in Certificate MMC and went to this server local certificate store and check property "Servername.domain.com" on general tab its name was "Microsoft Exchange" in certificate Purposes i select option "Enable all porpose of this certificate" and click ok.
after this restart IIS and then  /ECP and OWA were also accessible.

 

The target principal name is incorrect DC not replicating in AD 2008

Today i Start two DCs in a site which were down from couple of weeks and after checking their health found that both DCs have replication issues with DCs in other sites.

Now my steps to resolve this issue were as bellow.

(1) First i check network configuration and also check the required ports to be opened and Found OK
(2) Then i compare time of faulty DCs with PDC and found OK
(3) Then i went to AD sites and services and tried from there replication but got the following error.
"The following error occurred during the attempt to synchronize naming context CN=Configuration, DC=abc, DC=com from domain controller dc1 to domain controller dc2:
the target principal name is incorrect
"

(4) Then i went to commandprompt and tried "Repadmin/showrepl and Repadmin/syncall etc"
but got the following error
"AD Replication error -2146893022: The target principal name is incorrect"

(5) I use the procedure in (http://nawazblogger.blogspot.com/2013/09/the-trust-relationship-between-this.html) and now came to know that I have to reset the password of both faulty DCs as in ADSI
edit of faulty DC and functional DCs it was different in pwdlastset in faulty and functional DCs .
To resolve this issue i went AD users and computer and then DCs OU and try right click on both DCs and select reset but got the following error.

"Server "DC1" is a domain controller you cannot reset the password of this object"

(6) Then i try the following command to reset but before this went to Services on this DC and stop the KDC service and set the startup type to manual and restart the server and after completion of this command restart this service as was before.
netdom resetpwd /s:DomainControler /ud:domain\user1 /pd:*
it asked for password and after typing the password and hitting enter key i got the bellow error while using DomainController of other site.
"The machine account password for the local machine could not be reset.
The network path was not found.
The command failed to complete successfully."
Then i went
Then i try to use "DomainController" as its own name as this server is domain controller and command was successful got this message.
The machine account password for the local machine has been successfully reset.
 The command completed successfully
(7) Then i check from ADSIEDIT of faulty and functional DCs and found that pwdlastset date was same.
(8) Now went to AD site and Services and also from command prompt with "Repadmin /showrepl and Repadmin /syncall etc"

and every thing was OK. all errors gone

Wednesday 10 September 2014

Can not Print or Save Microsoft Baseline Security Analyzer report


"print this report" not working in Baseline Security Analyzer explorer

today i ran MBSA to scan a system and after completion of scan i want to print the report.
But "print this report" was not work.

solution:

go to control panel and then open Devices and printers and select the "Microsoft XPS document writers" as no hardware printer was not installed on this system.
after this i was able to print the report/Save the report in *.xps format.

 

Changes to the public group membership cannot be saved. you do not have sufficient permission to perform this operation on this object (Resolved)

After migrating from Microsoft exchange 2007 to Microsoft exchange 2013 outlook users were unable to Modify members of distribution groups in outlook.

Getting error while updating groups in outlook:

Changes to the public group membership cannot be saved. you do not have sufficient permission to perform this operation on this object
Open your exchange control panel (https://url/ecp) and then go to permissions--> user roles-->double click on Default role assignment policy and then go to "MyDistributionGroups" and check and save