Меню

Rms ошибка авторизации через систему безопасности сервера

Ошибка авторизации через систему безопасности сервера

Цитировать выделенное

Добрый день Алексей. Есть такая ошибка при использовании своего сервера.

Ошибка авторизации через систему безопасности сервера
Пароль не правильный либо произошла ошибка.

Вот текст из лога
Ошибка: Error TMyOpenSSLSocket.ReadStream. (EMyOpenSSLException).
Переустановка клиента не помогает.  Помогает только перезагрузка пк

date/time          : 2022-09-21, 16:59:21, 807ms
computer name      : SPB-PC-KC-02
user name          : СИСТЕМА <admin>
registered owner   : comp02
operating system   : Windows 10 x64 build 19044
system language    : Russian
system up time     : 6 days 23 hours
program up time    : 6 days 23 hours
processors         : 2x Intel(R) Celeron(R) CPU G550 @ 2.60GHz
physical memory    : 1130/4033 MB (free/total)
free disk space    : (C 55,41 GB
display mode       : 1024×768, 32 bit
process id         : $1024
allocated memory   : 43,14 MB
largest free block : 836,15 MB
command line       : «C:Program Files (x86)Remote Manipulator System — Hostrutserv.exe» -service
executable         : rutserv.exe
exec. date/time    : 2022-05-16 01:57
version            : 7.1.3.0
callstack crc      : $2bfc1bb5, $8084c1e3, $8084c1e3
exception number   : 2
exception class    : EMyOpenSSLException
exception message  : Error TMyOpenSSLSocket.ReadStream.

thread $2510 (TMyOpenSSLMsgTransportThread):
007de591 +0ad rutserv.exe  uOpenSSLUtils   1397 +32 TMyOpenSSLSocket.ReadStream
007de597 +0b3 rutserv.exe  uOpenSSLUtils   1397 +32 TMyOpenSSLSocket.ReadStream
007de62f +037 rutserv.exe  uOpenSSLUtils   1410  +5 TMyOpenSSLSocket.ReadInt32
007df72d +295 rutserv.exe  uOpenSSLUtils   1930 +84 TMyOpenSSLMsgTransportThread.Execute
004b9ddf +02b rutserv.exe  madExcept                HookedTThreadExecute
004b9e4a +096 rutserv.exe  madExcept                HookedTThreadExecute
00541dd5 +049 rutserv.exe  System.Classes 15711 +18 ThreadProc
00541e38 +0ac rutserv.exe  System.Classes 15740 +47 ThreadProc
0040af7c +028 rutserv.exe  System         25395 +45 ThreadWrapper
004b9cc5 +00d rutserv.exe  madExcept                CallThreadProcSafe
004b9d2a +032 rutserv.exe  madExcept                ThreadExceptFrame
004b9da0 +0a8 rutserv.exe  madExcept                ThreadExceptFrame
760cfa27 +017 KERNEL32.DLL                          BaseThreadInitThunk
>> created by thread $2104 (TIdThreadWithTask) at:
00541e9c +018 rutserv.exe  System.Classes 15769  +1 TThread.Create

main thread ($1028):
00000000 +ffbc3fe0 rutserv.exe madStackTrace +0 StackAddrToStr
>> stack will be calculated soon

cpu registers:
eax = 02339920
ebx = 007d8408
ecx = 00000000
edx = 05d9c998
esi = 00000000
edi = 004b9cf8
eip = 007de596
esp = 06dffdd0
ebp = 06dffe24

stack dump:
ХХХХХХХХХХХХ

disassembling:
ХХХХХХХХХХХХ

Профиль |
Сообщений:
8 |
Дата создания:
06.10.2022 02:12:38

Re: Ошибка авторизации через систему безопасности сервера

alex

Модератор

Цитировать выделенное

anatol.gredyagin,
это условная ошибка (т.е. ошибкой она не является).
а причина в том, что нет доступа. возможно, поменялся сертификат Сервера или какие-то еще причины. Зачастую бывает, когда на Сервере указывают какие-то настройки, без понимания для чего они нужны, например, PIN код.
Профиль |
Сообщений:
3284 |
Дата создания:
06.10.2022 04:07:36

Re: Ошибка авторизации через систему безопасности сервера

anatol.gredyagin

Цитировать выделенное

Да, на сервере установлн pin
Я так понимаю он для большей безопасности.
Профиль |
Сообщений:
8 |
Дата создания:
06.10.2022 21:39:37

Re: Ошибка авторизации через систему безопасности сервера

anatol.gredyagin

Цитировать выделенное

Алексей, Вы можете дать ссылку на описание, для чего нужен pin?
Профиль |
Сообщений:
8 |
Дата создания:
08.10.2022 20:29:16

Re: Ошибка авторизации через систему безопасности сервера

alex

Модератор

Цитировать выделенное

anatol.gredyagin,
PIN-код нужен для того, чтобы у сторонних пользователей не было доступа к ID транспорту. Но нужно понимать, что это скорее «защита от дурака», т.к. если у злоумышленника есть доступ хотя бы к одному настроенному PIN-кодом Хосту или Клиенту, он его, при определенных навыках, может извлечь. Ряд пользователей это устраивает и они, все равно, требуют защиту от дурака, вот мы пошли им на встречу и реализовали PIN.
если понимания, зачем нужен PIN все равно нет, я бы не рекомендовал им пользоваться.
Профиль |
Сообщений:
3284 |
Дата создания:
09.10.2022 17:43:58

Re: Ошибка авторизации через систему безопасности сервера

anatol.gredyagin

Цитировать выделенное

получается, что функционал, заложенный в программу, но он не всегда работает. В некоторых случаях мы получаем данную ошибку. При идентичной конфигурации ошибки нет. Как можно разобраться с данной ошибкой?

После перезагрузки клиента данная ошибка уходит. Но после, не перезагружая клиента не получается подключиться и в логе опять данная ошибка.

Профиль |
Сообщений:
8 |
Дата создания:
10.10.2022 23:27:51

Re: Ошибка авторизации через систему безопасности сервера

alex

Модератор

Цитировать выделенное

anatol.gredyagin,
если отключить PIN ошибка есть?
Профиль |
Сообщений:
3284 |
Дата создания:
10.10.2022 23:58:36

Re: Ошибка авторизации через систему безопасности сервера

anatol.gredyagin

Цитировать выделенное

Не помогает.Отключил на сервере, перезапустил сервер. Не могу подключиться к клиенту, та же ошибка.

А что получается, если свой сервер опубликован в интернет, и нет pin, то любой желающий может этот сервер использовать в качестве удаленного сервера для обслуживания клиентских подключений?

Профиль |
Сообщений:
8 |
Дата создания:
12.10.2022 23:08:06

Re: Ошибка авторизации через систему безопасности сервера

alex

Модератор

Цитировать выделенное

anatol.gredyagin,
нужно смотреть логи Сервера.

anatol.gredyagin писал(а):

А что получается, если свой сервер опубликован в интернет, и нет pin, то любой желающий может этот сервер использовать в качестве удаленного сервера для обслуживания клиентских подключений?

сможет, только будет ли? если злоумышленнику попадется в руки дистрибутив, где прописан данный Север, он и PIN код сможет достать. если нужна настоящая защита, то там можно использовать ту же систему безопасности Сервера.

Профиль |
Сообщений:
3284 |
Дата создания:
12.10.2022 23:11:30

Re: Ошибка авторизации через систему безопасности сервера

anatol.gredyagin

Цитировать выделенное

Сложно спрогнозировать что злоумышленник будет делать, что будет использовать.
Что касается системы безопасности сервера, скажите вы что имеете ввиду?
Профиль |
Сообщений:
8 |
Дата создания:
12.10.2022 23:45:54

Re: Ошибка авторизации через систему безопасности сервера

anatol.gredyagin

Цитировать выделенное

И можете уточнить, в какой папке смотреть логи сервера, спасибо!
Я не могу найти логи подключения. На сервере включено журналирование ошибок, событий и соединений.
Профиль |
Сообщений:
8 |
Дата создания:
12.10.2022 23:54:18

Re: Ошибка авторизации через систему безопасности сервера

alex

Модератор

Цитировать выделенное

anatol.gredyagin,
напишите в поддержку support@tektonit.com (рекомендуется указать, какой лицензией вы пользуетесь)
Профиль |
Сообщений:
3284 |
Дата создания:
13.10.2022 12:47:15

Данный метод авторизации не включен в настройках удаленного хоста

Цитировать выделенное

Ошибка авторизации через систему безопасности сервера

Периодически невозможно подключиться. Пишет: Данный метод авторизации не включен в настройках удаленного хоста.
Проблема возникает на разных подключениях. То они работают, то данное сообщение. Иногда помогает закрытие Viewer 6.10.3 (Лицензия HELPDESK), а потом запуск.
При этом на RMS HOST 6.8 вход нормальный.

Mini Internet-ID сервер 2.7.5.0, Windows Server 2012 — 300 подключений. сеть 100Мбит (Оптика), порты проброшены

RMS 6.9.10.3, RMS 6.9.4 — Win7 и 10
Методы авторизации Пароль и Пользователь RMS c паролем.
Viewer 294 соединений, интерфейс подтормаживает. Inte 7, SSD, 8 Gb ОЗУ
Антивирус dr.WEb в исключения добавлены exe  программ.

Подскажите возможные причины?

Профиль |
Сообщений:
14 |
Дата создания:
15.01.2019 13:48:15

Re: Данный метод авторизации не включен в настройках удаленного хоста

alex

Модератор

Цитировать выделенное

sergeyfs,
в первую очередь, нужно смотреть лог Хоста.
в свойствах пользователя на Сервере установлен ли флажок «Принудительно использовать систему безопасности сервера»? Профиль |
Сообщений:
3284 |
Дата создания:
15.01.2019 14:05:45

Re: Данный метод авторизации не включен в настройках удаленного хоста

sergeyfs

Цитировать выделенное

Да установлен. Профиль |
Сообщений:
14 |
Дата создания:
15.01.2019 14:08:48

Re: Данный метод авторизации не включен в настройках удаленного хоста

sergeyfs

Цитировать выделенное

Убрал, Спасибо — помогло. Профиль |
Сообщений:
14 |
Дата создания:
15.01.2019 14:14:41

Re: Данный метод авторизации не включен в настройках удаленного хоста

alex

Модератор

Цитировать выделенное

sergeyfs,
sergeyfs писал(а):

Убрал, Спасибо — помогло.

но это тоже не всегда выход. ответил в тикете. Профиль |
Сообщений:
3284 |
Дата создания:
15.01.2019 14:17:32

Re: Данный метод авторизации не включен в настройках удаленного хоста

eve511

Цитировать выделенное

Добрый день, такая же проблема, какое есть решение? галочку убирал не помогло, версия последняя Профиль |
Сообщений:
2 |
Дата создания:
30.11.2020 10:12:13

Re: Данный метод авторизации не включен в настройках удаленного хоста

alex

Модератор

Цитировать выделенное

eve511,
что-то не правильно настроено. начните с того, чтобы удалить все настройки Сервера HKEY_LOCAL_MACHINESOFTWARETektonITRemote Manipulator SystemMiniInternetId
затем поэтапно меняйте настройки, каждый раз проверяя работоспособность. Профиль |
Сообщений:
3284 |
Дата создания:
30.11.2020 14:46:49
  • Remove From My Forums
  • Вопрос

  • Доброго дня.

    В организации есть лес AD contoso.com и субдомен sub.contoso.com. Все пользователи (и их рабочие станции) находятся в домене sub.contoso.com.

    В домене contoso.com установили RMS (Windows Server 2008R2). В DNS добавили запись соответствующую имени RMS кластера. На одной из клиентских станций установили MS Office 2010 pro +.

    Если в MS Office перейти по пути файл — сведения — разрешения — защитить документ — ограничить разрешения для пользователей — ограниченный доступ, 

    буквально через пару секунд появляется запрос на авторизацию.

    Пробуем авторизоваться под contosouser или под subuser никакой разницы нет, авторизация не успешна.

    Как это поправить?

Ответы

  • В итоге проблему нашел в IIS — default web site — _wmcs — authentication — windows authentication — providers

    Удалил всех, применил. Зашел снова и добавил только NTLM. iisreset и все заработало успешно.

    • Помечено в качестве ответа

      4 июня 2013 г. 13:43

  • Remove From My Forums
  • Question

  • Installed RMS role in production exactly as installed in (working) test environment, yet not working in production. Symptoms are: Client is directed to RMS cluster, then recieves message that the service is not available. At that moment an entry is created
    in the event log of the server with the RMS role, stating that authentication failed while communicating the the SQL server. Setup is: RMS role created on «server1.domain.com» Database on «sqlServer.domain.com» DNS entries set up for each, «RMS.domain.com
    > server1.domain.com, and RMS-SQL.domain.com > sqlServer.domain.com. SCP is registered in AD as RMS.domain.com, and clients are being directed to the RMS server. In the errors below, I’ve replaced the actual server and domain names as noted above. I
    will appreciate any help, being really pushed for an implemtation date.

    Process information:
        Process ID: 4728
        Process name: w3wp.exe
        Account name: domainADRMSSRVC < this is the service account, which has rights to the SQL databases >

    Exception information:
        Exception type: SqlException
        Exception message: Cannot open database «DRMS_Config_rms_domain_com_443» requested by the login. The login failed.
    Login failed for user ‘NT AUTHORITYANONYMOUS LOGON’.

    This Active Directory Rights Management Services (AD RMS) cluster cannot perform an operation on one of the AD RMS databases. Ensure that all AD RMS databases are operating correctly on the network and that the AD RMS service account has read and write permissions
    to the databases.
    Parameter Reference
    Context: STATIC
    RequestId: N/A
    HelpLink.ProdName: Microsoft SQL Server
    HelpLink.EvtSrc: MSSQLServer
    HelpLink.EvtID: 4060
    HelpLink.BaseHelpUrl: http://go.microsoft.com/fwlink
    HelpLink.LinkId: 20476
    SqlError-1.Server: <SQLserver.domain.com>

    SqlError-0.Class: 11
    SqlError-0.Number: 4060
    SqlError-1.State: 1
    SqlError-1.Message: Login failed for user ‘NT AUTHORITYANONYMOUS LOGON’.
    SqlError-0.Message: Cannot open database «DRMS_Config_rms_domain_com_443» requested by the login. The login failed.
    SqlError-1.Number: 18456
    SqlError-0.State: 1
    SqlError-1.Class: 14
    SqlError-0.Server: fl2000-sqlServer.domain.com

    • Edited by

      Wednesday, November 2, 2011 9:45 PM

Answers

  • The Rights Management Servies is running under the service account (ADRMSSRVC).

    • Marked as answer by
      JackInIT
      Wednesday, November 23, 2011 2:24 PM

  • The solution was in IIS Authentication: turned off ASP.NET authentication, now working properly.

    • Marked as answer by
      JackInIT
      Wednesday, November 23, 2011 2:27 PM

  • Remove From My Forums
  • Question

  • Installed RMS role in production exactly as installed in (working) test environment, yet not working in production. Symptoms are: Client is directed to RMS cluster, then recieves message that the service is not available. At that moment an entry is created
    in the event log of the server with the RMS role, stating that authentication failed while communicating the the SQL server. Setup is: RMS role created on «server1.domain.com» Database on «sqlServer.domain.com» DNS entries set up for each, «RMS.domain.com
    > server1.domain.com, and RMS-SQL.domain.com > sqlServer.domain.com. SCP is registered in AD as RMS.domain.com, and clients are being directed to the RMS server. In the errors below, I’ve replaced the actual server and domain names as noted above. I
    will appreciate any help, being really pushed for an implemtation date.

    Process information:
        Process ID: 4728
        Process name: w3wp.exe
        Account name: domainADRMSSRVC < this is the service account, which has rights to the SQL databases >

    Exception information:
        Exception type: SqlException
        Exception message: Cannot open database «DRMS_Config_rms_domain_com_443» requested by the login. The login failed.
    Login failed for user ‘NT AUTHORITYANONYMOUS LOGON’.

    This Active Directory Rights Management Services (AD RMS) cluster cannot perform an operation on one of the AD RMS databases. Ensure that all AD RMS databases are operating correctly on the network and that the AD RMS service account has read and write permissions
    to the databases.
    Parameter Reference
    Context: STATIC
    RequestId: N/A
    HelpLink.ProdName: Microsoft SQL Server
    HelpLink.EvtSrc: MSSQLServer
    HelpLink.EvtID: 4060
    HelpLink.BaseHelpUrl: http://go.microsoft.com/fwlink
    HelpLink.LinkId: 20476
    SqlError-1.Server: <SQLserver.domain.com>

    SqlError-0.Class: 11
    SqlError-0.Number: 4060
    SqlError-1.State: 1
    SqlError-1.Message: Login failed for user ‘NT AUTHORITYANONYMOUS LOGON’.
    SqlError-0.Message: Cannot open database «DRMS_Config_rms_domain_com_443» requested by the login. The login failed.
    SqlError-1.Number: 18456
    SqlError-0.State: 1
    SqlError-1.Class: 14
    SqlError-0.Server: fl2000-sqlServer.domain.com

    • Edited by

      Wednesday, November 2, 2011 9:45 PM

Answers

  • The Rights Management Servies is running under the service account (ADRMSSRVC).

    • Marked as answer by
      JackInIT
      Wednesday, November 23, 2011 2:24 PM

  • The solution was in IIS Authentication: turned off ASP.NET authentication, now working properly.

    • Marked as answer by
      JackInIT
      Wednesday, November 23, 2011 2:27 PM

  • Remove From My Forums
  • Question

  • Hi all,

    All my client can’t connect to AD RMS Server (Win 2008 R2 SP1), error like this : 

    This
    service is temporarily unavailable. Ensure that you have connectivity to this server. this error could be because you are working offline, your proxy settings are preventing your connection, or you are experiencing intermittent network issues.

    From the client I have configure URL to local trust site, can ping the server, can access the url RMS, IE online.

    what could probably wrong ?


    Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.

Answers

  • Oh … just noticed it’s a Win XP SP2 box need to update it via the Internet direct from Microsoft update. Faced the same on XP desktops, need to fully update with IE, .net framework and office patches.

    Have you checked with Windows 7 if you are having the same issue?

     Just FYI — XP SP2 out of support


    Blog Link: http://blogs.cyquent.ae | Follow us on Twitter:
    @cyquent | ADRMS Wiki Portal:

    Technet Wiki

    • Edited by

      Wednesday, July 27, 2011 10:52 AM
      added a response line

    • Marked as answer by
      Brad Mahugh — (Microsoft)
      Thursday, April 4, 2013 3:35 AM

  • Hi Alokemc,

    I think you should open a new thread for yourself m8.

    Hi All,

    I uninstall existing ADRMS server (SVR01) and install at SVR02, the problem still the same. Then I try a fresh installation Windows XP and try to disable IE GPO, then it works. I think the major problem is the IE GPO (User Configuration).

    So how can I revert back all the settings from my client, either the IE settings or the old credential from RMS, the registry settings also, so I have a clean client ?


    Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.

    • Marked as answer by
      Brad Mahugh — (Microsoft)
      Thursday, April 4, 2013 3:36 AM

  • Hi

    Looks pretty much standard configuration, I believe you need to make a few changes in the following sections and life would be good,

    Local intranet (Security Level: Medium-low) > Sites in this zone >
    Add the Intranet URL for the AD RMS server

    Local intranet (Security Level: Medium-low) > Sites >
    Include all sites that bypass the proxy server > Set to Enable

    Let me know how it goes ..


    Blog Link: http://blogs.cyquent.ae | Follow us on Twitter:
    @cyquent | ADRMS Wiki Portal:
    Technet Wiki

    • Marked as answer by
      Brad Mahugh — (Microsoft)
      Thursday, April 4, 2013 3:36 AM

  • Hi Team,

    I found the same issue with my one of the client. Here (In development) it’s working fine. with and without domain (using citrix). But there at client end it’s not working.

    They have Windows 7 + Office 2010.

    Same From IRMS Check Configuration

    Check 1: Microsoft Office Server is not installed.

    Need helps from you.


    Thanks & Regards, Brijesh Shah

    • Marked as answer by
      Brad Mahugh — (Microsoft)
      Thursday, April 4, 2013 3:36 AM

  • Remove From My Forums
  • Question

  • Hi all,

    All my client can’t connect to AD RMS Server (Win 2008 R2 SP1), error like this : 

    This
    service is temporarily unavailable. Ensure that you have connectivity to this server. this error could be because you are working offline, your proxy settings are preventing your connection, or you are experiencing intermittent network issues.

    From the client I have configure URL to local trust site, can ping the server, can access the url RMS, IE online.

    what could probably wrong ?


    Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.

Answers

  • Oh … just noticed it’s a Win XP SP2 box need to update it via the Internet direct from Microsoft update. Faced the same on XP desktops, need to fully update with IE, .net framework and office patches.

    Have you checked with Windows 7 if you are having the same issue?

     Just FYI — XP SP2 out of support


    Blog Link: http://blogs.cyquent.ae | Follow us on Twitter:
    @cyquent | ADRMS Wiki Portal:

    Technet Wiki

    • Edited by

      Wednesday, July 27, 2011 10:52 AM
      added a response line

    • Marked as answer by
      Brad Mahugh — (Microsoft)
      Thursday, April 4, 2013 3:35 AM

  • Hi Alokemc,

    I think you should open a new thread for yourself m8.

    Hi All,

    I uninstall existing ADRMS server (SVR01) and install at SVR02, the problem still the same. Then I try a fresh installation Windows XP and try to disable IE GPO, then it works. I think the major problem is the IE GPO (User Configuration).

    So how can I revert back all the settings from my client, either the IE settings or the old credential from RMS, the registry settings also, so I have a clean client ?


    Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.

    • Marked as answer by
      Brad Mahugh — (Microsoft)
      Thursday, April 4, 2013 3:36 AM

  • Hi

    Looks pretty much standard configuration, I believe you need to make a few changes in the following sections and life would be good,

    Local intranet (Security Level: Medium-low) > Sites in this zone >
    Add the Intranet URL for the AD RMS server

    Local intranet (Security Level: Medium-low) > Sites >
    Include all sites that bypass the proxy server > Set to Enable

    Let me know how it goes ..


    Blog Link: http://blogs.cyquent.ae | Follow us on Twitter:
    @cyquent | ADRMS Wiki Portal:
    Technet Wiki

    • Marked as answer by
      Brad Mahugh — (Microsoft)
      Thursday, April 4, 2013 3:36 AM

  • Hi Team,

    I found the same issue with my one of the client. Here (In development) it’s working fine. with and without domain (using citrix). But there at client end it’s not working.

    They have Windows 7 + Office 2010.

    Same From IRMS Check Configuration

    Check 1: Microsoft Office Server is not installed.

    Need helps from you.


    Thanks & Regards, Brijesh Shah

    • Marked as answer by
      Brad Mahugh — (Microsoft)
      Thursday, April 4, 2013 3:36 AM

0 0 голоса
Рейтинг статьи
Подписаться
Уведомить о
guest

0 комментариев
Старые
Новые Популярные
Межтекстовые Отзывы
Посмотреть все комментарии

А вот еще интересные материалы:

  • Яшка сломя голову остановился исправьте ошибки
  • Ясность цели позволяет целеустремленно добиваться намеченного исправьте ошибки
  • Ясность цели позволяет целеустремленно добиваться намеченного где ошибка
  • Rms ошибка авторизации через систему безопасности windows
  • Rms ошибка 53 невозможно подключить сетевой диск