SMS 2003: MP authentication problems on domain controllers

dmcheng1_at_yahoo.com
Date: 02/16/05

  • Next message: Kim Oppalfens: "Re: SMS Administrator Console fail to connect"
    Date: 16 Feb 2005 13:42:00 -0800
    
    

    Can anyone explain to me the setup and permissions required for running
    SMS and IIS on domain controllers? While most of my SMS environment
    seems to working, I have had a few site servers that have rebooted and
    since then, their Management Points fail the authentication (the
    http://....?mpcert and ?mplist pages) and I can't get them running
    again even after reinstalling the Management Point.

    Here's my setup: SMS 2003 (no SP) running on Windows 2003 Server (no
    SP) in an Active Directory tree, all in the same domain. A central
    primary site server at the data center and about 170 child primary site
    servers at remote locations. All servers are domain controllers and
    running SMS, IIS 6, and SQL 2000.

    I see the IUSR and IWAM accounts for all the affected site servers in
    the Active Directory. The accounts have not been disabled. I have
    placed the IWAM accounts into a group called IWAM_ALL_DCs. I have
    placed IWAM_ALL_DCs into the IIS_WPG group so that when a new IIS
    server comes up, the list isn't wiped out.

    Question: Should IIS_WPG be a member of any domain groups? Right now
    it is not.

    I run IIS Admin on the affected site servers,verify that SMS Management
    Point Pool and CCM Server Framework application pools are using IWAM
    and are started. Then I restart the IIS server process.

    When I go to the mpcert and mplist pages, I get Service Unavailable
    errors and then I see that the application pools have stopped.

    Any advice would be appreciated!

    Thanks
    David


  • Next message: Kim Oppalfens: "Re: SMS Administrator Console fail to connect"

    Relevant Pages

    • Re: Management Points not working after domain controler demontion on
      ... I have a procedure that works for me; some steps might not be required on all servers but generally I find it better to just follow it and be sure that it comes up again without any issues :-) ... This causes IIS accounts to be recreated in local SAM. ... Use dcomcnfg and check if there are any DCOM objects related to SMS IIS ... This causes SMS accounts to be recreated in local SAM. ...
      (microsoft.public.sms.admin)
    • Re: Management Points not working after domain controler demontion on
      ... Windows Server System MVP - SMS ... trying to access the site and after adding some permissions for the local IIS ... accounts managed to get some progress, still issues though so I'll be trying ... secondary SMS servers running IIS 5.0. ...
      (microsoft.public.sms.admin)
    • RE: Secondary Site MP to SQL problem
      ... I guess my problem really started when I had to rename the 4 servers I ... currently have running SMS. ... But I didn't understand that I should also have reinstalled both IIS and SQL ... Before that all my clients got HTTP errors, ...
      (microsoft.public.sms.setup)
    • Re: Management Points not working after domain controler demontion on
      ... Demoting will kill all the sms groups and their memberships. ... client machines filling the IIS logs with "401 ccmhttp" errors. ... secondary SMS servers running IIS 5.0. ...
      (microsoft.public.sms.admin)
    • RE: HELP-Domain Controller reboot causes session loss
      ... My web servers that are running IIS6.0 are in located in an AD site with 2 ... therory is because the connection is comming through IIS and its IIS that ... moving the session info to the SQL database and maybe ... All servers (including domain controllers) are windows 2003. ...
      (microsoft.public.inetserver.iis.security)