Showing posts with label FIM 2010. Show all posts
Showing posts with label FIM 2010. Show all posts

Thursday, June 17, 2010

FIM 2010 – Password Reset failing

 

ISSUE:

Ok… So you have brought up your Forefront Identity Management 2010 environment, configured policies, got password reset working and life is good.  Then down the road you of course make performance, configuration changes or tweaks to the environment, MAs, etc…  One day you initiate (or user) a password reset via a workstation “reset password” link, pass through the gate questions without any problems, enter the new password and submit.  Then to your surprise are presented with a not so intuitive error.  Wait… this worked before WTH is going on.

You do some digging, check for events on the server running the password reset and discover a slue of the following events under “Forefront Identity Manager” event node.

EventID: 3
Source: Microsoft.ResourceManagement
Details:   "PWReset activity could not connect to the directory"

image

After banging my head on the concrete, I recalled changes made to the environment and when, then matched them up to the last time Password Reset worked.  I recalled a change made to the AD MA in order to work around the Excessive CPU Utilization on the Synchronization Server, which was to set the ADMA to “Run in a separate process..”.   If you set the AD MA to run in a separate process, password reset fails.

SOLUTION: 

Make sure the AD MA is NOT enabled to “Run in a separate process”, and then restart the Forefront Identity Manager Synchronization Server Service (miisserver.exe).  Try another password reset and BAM, it works.

So what fixed one issue apparently damaged/disrupted another.  Until the fix for FIM 2010 is available, determine what is more important to you… a pegged processor on the Synchronization Server or Password Reset working.  I’ll leave that up to you.

Tuesday, June 15, 2010

FIM 2010: Approval email “This request cannot be approved or rejected…”

 

Issue:

Within a Distribution Group an approval workflow and email is generated, when you open Outlook as the approver you receive the error message below and the approve/reject buttons are dimmed 

"This request cannot be approved or rejected for the following reason(s): The sender (FIM Service Component User) is not an authorized sender of approval requests. Contact your system administrator for assistance."

Cause:

The FIM service account email address entered during the FIM Extensions and Add-ins install/configure process was not correct.  In my case when this was encountered, I entered the email address correctly for the FIMService account; however Exchange created a different PrimarySMTP address for the account, and set other as a secondary.  This caused the error.

Solution:

On the machine with the FIM Extensions and Add-ins installed, perform a “Change” on the installation.

Program and Features > Forefront Identity Manager Add-ins and Extensions > Change

During the change, enter the correct email address assigned to the FIM Service account.

Hopefully you discover this before deploying company wide.  If not, you can always make the change via Group Policy, or other Desktop management solution.

Wednesday, June 2, 2010

FIM 2010 – Error during Password Reset Registration

 

After performing the Password Reset deployment tasks per http://technet.microsoft.com/en-us/library/ee534892(WS.10).aspx#reset_pswd_us_pswd_reset_portal  you log into a machine and initiate the password registration sequence.  Following the completion of the Gate questions, you receive and error stating:

“An error was encountered. Please call helpdesk or your system administrator”

Cause:

The reason for the error is that the FIM Service account does not have “READ” permissions on the “Forefront Identity Manager” certificate installed on the FIMService Server. 

Resolution:

To resolve the issue, grant the FIMService account READ permissions to the certificate designated for Forefront Identity Manager.  Assigning the permission via the certificate manager console > Manager Private Key.. process may fail with an “Access "Denied” error when initiated.  In order modify the permissions, you will have to initiate the security permissions change by running the remote process in the system account.  This can be performed by downloading PSEXEC on to the FIMService server and executing the command sequence in the order shown below:

On the server hosting FIMService, download and install psexec and execute the following procedure. In that order

psexec.exe -s -d -i cmd.exe
mmc.exe
add Cert snap-in -> local machine -> computer account
Personal store --> right click the cert --> all tasks -->manage private key
grant FIMService service account read permission.

clip_image001

Following the permissions change, the Password Reset Registration process should work (No reboot required).

There you go!!

Wednesday, May 19, 2010

FIM 2010 – Documentation Roadmap

 

FIM 2010 Documentation Summary

Documentation Roadmap

Guidance for how to use the Microsoft® Forefront™ Identity Manager 2010 2010 and Microsoft® Forefront Identity Manager Certificate Management (FIM CM) documentation.

FIM 2010 Technical Overview

This document is an overview of FIM and how it provides solutions in the identity technology problem space.

Release Notes

This document provides information about the latest changes to FIM and FIM CM.

Planning and Architecture

  • Capacity Planning Guide 
    • This guide describes how different hardware configuration options affect the performance of a server hosting FIM. The configuration options discussed are processors (quantity and speed), database location, memory, disks and network.
  • Preinstallation and Topology Configuration
    • This document provides recommendations for deploying the FIM components in various physical topologies, and setting up for high availability.

Technical Concepts

  • Designing Business Policy Rules
    • This document explains how management policy rules (MPRs), resources and sets, workflows, and requests work together to define business policies that control entitlements of people, applications, or other services to critical resources.
  • Understanding Configuring and Customizing the FIM Portal
    • This document describes the elements and components of the FIM Portal, and how it can be configured and customized for your environment.
  • Understanding Custom Resource and Attributes
    • This document discusses the components and structure of the FIM schema: resource types, attributes, and bindings.
  • Understanding Data Synchronization with External Systems
    • The ability to manage distributed identity information from a central point is key component of the FIM architecture. This process is governed by a well-defined and customizable set of synchronization rules.
    • The objective of this document is to explain how you can use the FIM Synchronization Service to synchronize data with external systems.
  • Understanding Expected State Detection
    • With expected state detection (ESD), you can detect the custom states of objects in your managed external systems in FIM and configure a response to them.
    • The objective of this document is to give you an overview of ESD, to explain how ESD works, and to discuss advanced ESD solutions.

Getting Started

Deployment

  • Migrating from ILM 2007 to FIM 2010
    • This document outlines the steps and processes involved in migrating your ILM 2007 environment to FIM 2010.
  • FIM 2010 Installation Guide
    • This document describes the prerequisites and steps necessary to install the FIM Service, the FIM Synchronization Service, the FIM Portal, and the FIM Add-in for Outlook.
  • FIM 2010 Post Installation Configuration Guide
    • This document provides configurations and procedures to be performed after a successful installation. Depending on your environment, some of these tasks may be optional.
  • Configuration Migration Deployment Guide
    • This document describes the steps for migrating configuration data from a test environment to the FIM Service and the FIM Synchronization Service.
  • Custom Resource and Attribute Management Deployment Guide
    • This document provides end-to-end steps for synchronizing custom resources and attributes to Active Directory.
  • Password Reset Deployment Guide
    • This document provides instructions to help you to configure the password reset and registration feature by using the FIM Portal.
  • How Do I Synchronize Users from Active Directory Domain Services to FIM
    • This guide walks you through the main building blocks that are involved in the process of populating FIM with user data from Active Directory® Domain Services (AD DS), describes how you can verify whether your scenario works as expected, provides suggestions for managing Active Directory users by using FIM, and lists additional sources for information.
  • How Do I Synchronize Groups from Active Directory Domain Services to FIM
    • This guide walks you through the main building blocks that are involved in the process of populating FIM with group data from AD DS, describes how you can verify whether your scenario works as expected, provides suggestions for managing Active Directory groups by using FIM, and lists additional sources for information.
  • How do I Provision Users to Active Directory Domain Services
    • This guide walks you through the main building blocks that are involved in the process of provisioning users from FIM to AD DS, describes how you can verify whether your scenario works as expected, provides suggestions for managing Active Directory users by using FIM, and lists additional sources for information.
  • How do I Provision Groups to Active Directory Domain Services
    • This guide walks you through the main building blocks that are involved in the process of provisioning groups from FIM to AD DS, describes how you can verify whether your scenario works as expected, provides suggestions for managing Active Directory groups by using FIM, and lists additional sources for information.

Operations

  • Best Practices for FIM 2010
    • The document provides guidance and tips for deploying, maintaining, and troubleshooting FIM.
  • FIM 2010 Backup and Restore Guide
    • This guide describes the steps for locating data in FIM server-side components, finding resources to perform the actual backup, and then restoring the data in a test environment.
  • Troubleshooting FIM 2010
    • This document provides guidance for diagnosing common issues with FIM.

Technical Reference

Common Tasks

This section contains suggested approaches to the FIM documentation.

If you are new to FIM 2010
If you are migrating from ILM 2007 to FIM 2010
For pre-installation design and planning
For user and group management
For data synchronization with external systems
For customizing your FIM 2010 environment
For operational maintenance on your FIM 2010 environment
Additional references

For additional references and guidance, see:

Tuesday, May 18, 2010

Service Principal Name (SPN) checklist for Kerberos authentication with IIS 7.0/7.5

 

This post is more about the confusion that may arise around SPNs for setting up Kerberos authentication in IIS 7.0. IIS 7.0 has a new Kernel-mode authentication feature using which the ticket for the requested service is decrypted using Machine account (Local system) of the IIS server. It no longer depends upon the application pool Identity for this purpose by default and in turn improves the performance.

Here is how it looks like.

image

image

So what does this mean?

You no longer need to worry about the correlation between HTTP SPNs and the Application pool Identity that was required in the earlier version i.e. IIS 6.0. But that's not blindly true. There has been some confusion whether we don't have to care at all about SPNs or may have to depending upon the settings. Here is a checklist to give more clarity for different scenarios that you may fall under:

SCENARIO 1a

  • IIS 7.0 Web Site/Application
  • Authentication
    Integrated Windows authentication
  • Application Pool Identity
    NETWORK SERVICE
  • Kernel-Mode authentication
    Enabled (<attribute name="useKernelMode" type="bool" defaultValue="true" /> in the ApplicationHost.config file)
  • Site URL
    Accessed with the NetBIOS name, like http://<myIISserver-NetBIOS-name>/Default.aspx

SPNs will be required ONLY for the IIS machine account:

HOST/<myIISserver-NetBIOS-name>

HOST/<myIISserver-NetBIOS-name.fully-qualified-domainname> for e.g. HOST/myIISserver.mydomain.com

***Note: By default HOST/<myIISserver-NetBIOS-name> and HOST/<myIISserver-NetBIOS-name.fully-qualified-name> is already added for the machine account when a machine is added to a domain and HTTP forms a part of HOST. So you may not have to do anything special here for SPNs. Everything should be set by default.

You can check the set of existing SPNs for the machine account by running the following command:

> Setspn.exe -L <myIISserver-NetBIOS-name> or directly using a Snap-in like Adsiedit.msc.

SCENARIO 1b

  • IIS 7.0 Web Site/Application
  • Authentication
    Integrated Windows authentication
  • Application Pool Identity
    Custom account for e.g. Domain1\Username1
  • Kernel-Mode authentication
    Enabled (<attribute name="useKernelMode" type="bool" defaultValue="true" /> in the ApplicationHost.config file)
  • Site URL
    Accessed with the NetBIOS name, like http://<myIISserver-NetBIOS-name>/Default.aspx

The SPN requirements remain the same as above. You don't have to add SPNs like http/<myIISserver-NetBIOS-name> for the Domain1\Username1 unlike in IIS 6.0 (where we had to add an SPN of the form http/<myIISserver-NetBIOS-name> for the Application Pool identity).

SPNs will be required ONLY for the IIS machine account:

HOST/<myIISserver-NetBIOS-name>

HOST/<myIISserver-NetBIOS-name.fully-qualified-domainname> for e.g. HOST/myIISserver.mydomain.com

***Note: By default HOST/<myIISserver-NetBIOS-name> and HOST/<myIISserver-NetBIOS-name.fully-qualified-name> is already added for the machine account when a machine is added to a domain and HTTP forms a part of HOST. So you may not have to do anything special here for SPNs. Everything should be set by default.

You can check the set of existing SPNs for the machine account by running the following command:

> Setspn.exe -L <myIISserver-NetBIOS-name> or directly using Snap-in like Adsiedit.msc.

SCENARIO 2a

  • IIS 7.0 Web Site/Application
  • Authentication
    Integrated Windows authentication
  • Application Pool Identity
    NETWORK SERVICE
  • Kernel-Mode authentication
    Enabled (<attribute name="useKernelMode" type="bool" defaultValue="true" /> in the ApplicationHost.config file)
  • Site URL
    Accessed with a Custom Host name, like http://www.mysite.com


SPNs will be required ONLY for the IIS machine account in the following format:

HTTP/<site-custom-name> for e.g. HTTP/www.mysite.com

You can add an SPN using Setspn.exe like

> Setspn -a http/<site-custom-name> <myIISserver-NetBIOS-name>

where <myIISserver-NetBIOS-name> is the IIS machine account and <site-custom-name> is the custom host/host header name for the Web Site URL.

e.g. > Setspn -a http/www.mysite.com <myIISserver-NetBIOS-name>
*The command is NOT case sensitive

You can check the existing set of SPNs for the machine account by running the following command:

> Setspn.exe -L <myIISserver-NetBIOS-name>

SCENARIO 2b

  • IIS 7.0 Web Site/Application
  • Authentication
    Integrated Windows authentication
  • Application Pool Identity
    Custom account for e.g. Domain1\Username1
  • Kernel-Mode authentication
    Enabled (<attribute name="useKernelMode" type="bool" defaultValue="true" /> in the ApplicationHost.config file)
  • Site URL
    Accessed with a Custom host/Host header name, like http://www.mysite.com

SPNs will be required ONLY for the IIS machine account and NOT for Domain1\Username1 account unlike in IIS 6.0.

HTTP/<site-custom-name> for e.g. HTTP/www.mysite.com

You can add an SPN using Setspn.exe like

> Setspn -a http/<site-custom-name> <myIISserver-NetBIOS-name> where <myIISserver-NetBIOS-name> is the IIS machine account and <site-custom-name> is the custom host/host header name for the Web Site URL.

e.g. > Setspn -a http/www.mysite.com <myIISserver-NetBIOS-name>
*The command is NOT case sensitive

You can check the existing set of SPNs for the machine account by running the following command:

> Setspn.exe -L <myIISserver-NetBIOS-name>

Special case of running IIS 7.0 in a WEB FARM
If you are running IIS 7.0 server in a Web farm the KDC will not know in advance which individual server the request may go to and hence ticket decryption may fail. Hence in such a scenario instead of registering SPNs under a specific machine account use a domain account. I am not a SharePoint guy but based on what I have read on the Web this scenario is also applicable to a single SharePoint server configuration.

There are two ways to go:

Either

Disable Kernel mode authentication and follow the general steps for Kerberos as in the previous IIS 6.0 version. Refer this

Or,

[Recommended for Performance reasons]

Let Kernel mode authentication be enabled and the Application pool's identity be used for Kerberos ticket decryption. The only thing you need to do here is:

1. Run the Application pool under a common custom domain account.

2. Add this attribute "useAppPoolCredentials" in the ApplicationHost.config file.

<system.webServer>
   <security>
      <authentication>
         <windowsAuthentication enabled="true" useKernelMode="true" useAppPoolCredentials="true" />
      </authentication>
   </security>
</system.webServer>

Remember there is no GUI setting for this. You need to modify the ApplicationHost.config file from

<%SystemDrive%>/Windows/System32/inetsrv/config folder on the IIS 7.0 machine.

3. Add the SPNs in the form:

http/<virtualhost-name> and

http/<virtualhost-name.fully-qualified-name>  for the Application Pool Identity.

Ensure that we don't have such an entry for SPNs for any other account including IIS server machine account.

*If we have the same SPN mapped to multiple accounts (be it a machine or an user account) it leads to Duplicate SPNs and will break Kerberos.

Hope this helps!

Getting Started with FIM 2010

The following resources are available for Getting Started with FIM 2010