【问题标题】:SailPoint - Windows Local - Direct connectorSailPoint - Windows 本地 - 直接连接器
【发布时间】:2019-12-20 18:47:51
【问题描述】:

大家早上好!在 Windows 本地 - 直接连接器上遇到以下问题(仅在组聚合上)IQService 失败且没有错误,它正在遍历组,它只是停止并崩溃(没有错误 - 请参阅下面的日志)。

我能够验证以下内容:

管理员是本地管理员组的一部分。

远程注册服务已开启。

防火墙已关闭。

Sailpoint 是 8.0 版和 IQService 匹配:

ServiceName: IQService-Instance1
Display Name: SailPoint IQService-Instance1
Configured Port: 5050
Build version: 8.0 r53edbe8-20190524-075742
Build timestamp: 05/24/2019 11:03 AM -0500
Build location: RC_8.0
Build builder: jenkins
Executable: C:\SailPoint\IQService\IQService.exe
File Size: 36352
File Date: 5/24/2019 5:03:40 PM

Windows 服务器 2012 R2

只是为了验证管理员部分:

C:\SailPoint\IQService>whoami

seri\administrator

C:\SailPoint\IQService>网络用户管理员

Local Group Memberships *Administrators *fam-Windows File Serv
*Performance Log Users
Global Group memberships *Domain Users *Enterprise Admins
*Group Policy Creator *Schema Admins
*Domain Admins
The command completed successfully.

Tomcat 日志:

2019-12-20T18:12:43,939 ERROR http-nio-8080-exec-4 sailpoint.rest.ApplicationResource:311 - java.lang.RuntimeException: sailpoint.tools.GeneralException: Connection reset

IQService 日志:

12/20/2019 18:12:43 : RpcHandler [ Thread-4 ] DEBUG : "Initiating the serviceState for c87fbe66-fdc8-4e7d-bcfa-22d5d177c74c"
12/20/2019 18:12:43 : RpcHandler [ Thread-4 ] INFO : "Calling Service [NTConnector] and method[iterateObjects] "
12/20/2019 18:12:43 : Impersonator [ Thread-4 ] DEBUG : "Authenticating as User [Administrator] domain [SERI]"
12/20/2019 18:12:43 : AbstractConnector [ Thread-4 ] DEBUG : "ENTER AbstractConnector"
12/20/2019 18:12:43 : AbstractConnector [ Thread-4 ] DEBUG : "EXIT AbstractConnector"
12/20/2019 18:12:43 : NTConnectorServices [ Thread-4 ] DEBUG : "ENTER prepare"
12/20/2019 18:12:43 : NTConnectorServices [ Thread-4 ] DEBUG : "ENTER resolveServerName"
12/20/2019 18:12:43 : NTConnectorServices [ Thread-4 ] DEBUG : "EXIT resolveServerName"
12/20/2019 18:12:43 : NTConnectorServices [ Thread-4 ] DEBUG : "Connection URL [WinNT://ad-resource]"
12/20/2019 18:12:43 : NTConnectorServices [ Thread-4 ] DEBUG : "EXIT prepare"
12/20/2019 18:12:43 : AbstractConnector [ Thread-4 ] DEBUG : "ENTER IterateObjects"
12/20/2019 18:12:43 : NTConnectorServices [ Thread-4 ] DEBUG : "ENTER doIterateObjects"
12/20/2019 18:12:43 : NTConnectorServices [ Thread-4 ] DEBUG : "ENTER getNext"
12/20/2019 18:12:43 : NTConnectorServices [ Thread-4 ] DEBUG : "ENTER getObjectEnumerator"
12/20/2019 18:12:43 : NTConnectorServices [ Thread-4 ] DEBUG : "Connecting to Container [WinNT://ad-resource]"
12/20/2019 18:12:43 : NTConnectorServices [ Thread-4 ] DEBUG : "ENTER bind"
12/20/2019 18:12:43 : NTConnectorServices [ Thread-4 ] DEBUG : "new DirectoryEntry(WinNT://ad-resource)"

************************ 东西****************************** *****************

12/20/2019 18:12:43 : NTConnectorServices [ Thread-4 ] DEBUG : "EXIT buildMapFromEntry"
12/20/2019 18:12:43 : NTConnectorServices [ Thread-4 ] DEBUG : "EXIT getNext"
12/20/2019 18:12:43 : NTConnectorServices [ Thread-4 ] DEBUG : "ENTER getNext"
12/20/2019 18:12:43 : NTConnectorServices [ Thread-4 ] DEBUG : "Processing object[WinNT://SERI/ad-resource/Remote Desktop Users]"
12/20/2019 18:12:43 : NTConnectorServices [ Thread-4 ] DEBUG : "ENTER buildMapFromEntry"
12/20/2019 18:12:43 : NTConnectorServices [ Thread-4 ] DEBUG : "Processing Attribute [Description]"
12/20/2019 18:12:43 : NTConnectorServices [ Thread-4 ] DEBUG : "Attribute [Description] as a value[Members in this group are granted the right to logon remotely] type[System.String]."
12/20/2019 18:12:43 : NTConnectorServices [ Thread-4 ] DEBUG : "Description=Members in this group are granted the right to logon remotely"
12/20/2019 18:12:43 : NTConnectorServices [ Thread-4 ] DEBUG : "Processing Attribute [DirectoryPath]"
12/20/2019 18:12:43 : NTConnectorServices [ Thread-4 ] DEBUG : "Attribute [DirectoryPath] as a null value. skipping..."
12/20/2019 18:12:43 : NTConnectorServices [ Thread-4 ] DEBUG : "Processing Attribute [MemberGroups]"
12/20/2019 18:12:43 : NTConnectorServices [ Thread-4 ] DEBUG : "Attribute [MemberGroups] as a null value. skipping..."
12/20/2019 18:12:43 : NTConnectorServices [ Thread-4 ] DEBUG : "Processing Attribute [GroupType]"
12/20/2019 18:12:43 : NTConnectorServices [ Thread-4 ] DEBUG : "Attribute [GroupType] as a value[4] type[System.Int32]."
12/20/2019 18:12:43 : NTConnectorServices [ Thread-4 ] DEBUG : "ENTER mapGroupType"
12/20/2019 18:12:43 : NTConnectorServices [ Thread-4 ] DEBUG : "EXIT mapGroupType"
12/20/2019 18:12:43 : NTConnectorServices [ Thread-4 ] DEBUG : "Processing Attribute [Members]"
12/20/2019 18:12:43 : NTConnectorServices [ Thread-4 ] DEBUG : "Attribute [Members] as a null value. skipping..."
12/20/2019 18:12:43 : NTConnectorServices [ Thread-4 ] DEBUG : "Processing Attribute [objectSid]"
12/20/2019 18:12:43 : NTConnectorServices [ Thread-4 ] DEBUG : "Attribute [objectSid] as a value[System.Byte[]] type[System.Byte[]]."
12/20/2019 18:12:43 : NTConnectorServices [ Thread-4 ] DEBUG : "Processing Attribute [sAMAccountName]"
12/20/2019 18:12:43 : NTConnectorServices [ Thread-4 ] DEBUG : "Attribute [sAMAccountName] as a null value. skipping..."
12/20/2019 18:12:43 : NTConnectorServices [ Thread-4 ] DEBUG : "ENTER getGroupMembers"
12/20/2019 18:12:43 : NTConnectorServices [ Thread-4 ] DEBUG : "looking up members for Group [Remote Desktop Users]"
12/20/2019 18:12:43 : NTConnectorServices [ Thread-4 ] DEBUG : "GroupEnum was non null for [WinNT://SERI/ad-resource/Remote Desktop Users]"

服务崩溃并且每次都发生在同一组远程桌面用户上?上面显示的最后一行 - 关于上面的崩溃日志可能会在哪里结束的任何想法?

【问题讨论】:

    标签: windows sailpoint


    【解决方案1】:

    在与@kevin_james 会面后,他能够找出问题所在。如果您在 ADUC 中打开安全组 Remote Desktop Users,“Everyone”组会附加一个红色向上箭头 - 这个红色箭头表示 F.S.P. “外国安全主体 (FSP) 是安全主体,在将对象(用户、计算机或组)添加到某个域组时创建,但源自外部受信任域。FSP 由红色箭头标记识别。”我没有办法解决接受 FSP 的问题,但是,如果您删除它并重新添加“每个人”组将不再有红色箭头,它会正常工作。向凯文致敬!!

    【讨论】:

      猜你喜欢
      • 2019-01-29
      • 2020-11-17
      • 2019-03-07
      • 2020-03-31
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      相关资源
      最近更新 更多