In addition to Weibo, there is also WeChat
Please pay attention
WeChat public account
Shulou
2025-04-11 Update From: SLTechnology News&Howtos shulou NAV: SLTechnology News&Howtos > Servers >
Share
Shulou(Shulou.com)06/02 Report--
Error phenomena:
In System.Security.AccessControl.RawAcl.InsertAce (Int32 index, GenericAce ace) in System.Security.AccessControl.CommonAcl.AddQualifiedAce (SecurityIdentifier sid, AceQualifier qualifier, Int32 accessMask, AceFlags flags, ObjectAceFlags objectFlags, Guid objectType, Guid inheritedObjectType) in System.Security.AccessControl.DiscretionaryAcl.AddAccess (AccessControlType accessType, SecurityIdentifier sid, Int32 accessMask, InheritanceFlags inheritanceFlags, PropagationFlags propagationFlags, ObjectAceFlags objectFlags, Guid objectType, Guid inheritedObjectType) in System.Security.AccessControl.DirectoryObjectSecurity.ModifyAccess (AccessControl Modification, ObjectAcce*** rule, Boolean& modified) in System.Security.AccessControl.DirectoryObjectSecurity.AddAcce*** rule (ObjectAcce*** rule) in Microsoft.Rtc.Management.Deployment.Core.DirectoryCommon.ApplyAcesOnAcl (ActiveDirectorySecurity acl, Boolean remove, ActiveDirectoryAcce***ule[] aces) in Microsoft.Rtc.Management.Deployment.Core.DirectoryCommon.ProcessAcesOnDirectoryObject (ADSession session, ADObjectId id, ActiveDirectoryAcce***ule[] aces, EnterprisePrepAceOption aceOption) in Microsoft.Rtc.Management.Deployment.Core.DirectoryCommon. ProcessPermission (DeploymentContext context, String domainFqdn, ADObjectId groupDomainId, String groupDomainController, LcAceTable aceTable, String trusteeGroupName, String groupName, String taskId, String permissionLocation, ADObjectId dirObject) in Microsoft.Rtc.Management.Deployment.LcForest. ProcessLcsForestPermission (LcAction eAction, ADObjectId globalContainerId) in Microsoft.Rtc.Management.Deployment.LcForest.PrepareForest()
Solution:
This is caused by the built-in DACL size limit of AD. The solution is to delete the built-in ACEs entries in AD. For details, refer to the following steps:
Click Run, enter ldp, then click ok in ldp console click Connection menu, click Connect Enter FQDN of DC then click ok In Connection menu click Bind, enter credentials information of domain administrator, click ok In View menu, click Tree Select correct domain context in Base DN for example "DC=Contoso,DC=com," in Tree menu under CN=Configuration,DC=,DC=com Navigate to "CN=Services,CN=Configuration,DC=,DC=com". Right-click object in step 6, click Advanced, Select Security Descriptor, where you want to make sure SACL and Text dump are cancelled, and click OK.
At this time, a new window will pop up with the details of the security descriptor: in the security descriptor window, select the DACL check box, select and delete all ACEs containing "\0ADEL:" in the middle of the Security descriptor window, select multiple ACE entries and select Delete ACE. Close the security descriptor after deleting all ACEs. Close the LDP console.
12 Force DC replication to extend the architecture again and see if the problem persists.
In the process of extending the schema again, an error may be reported, and the AD object cannot be found.
Delete all logs from folders where previously extended schema generated logs, restart Lync front-end server, and then extend schema.
(In the Tree menu, under CN=Configuration,DC=,DC=com, locate the ACEs entry containing "\0ADEL:" in "CN=RTC Service,CN=Services,CN=Configuration,DC=,DC=com". It may still exist. If there are still problems, please delete the records under the above directory again)
Welcome to subscribe "Shulou Technology Information " to get latest news, interesting things and hot topics in the IT industry, and controls the hottest and latest Internet news, technology news and IT industry trends.
Views: 0
*The comments in the above article only represent the author's personal views and do not represent the views and positions of this website. If you have more insights, please feel free to contribute and share.
Continue with the installation of the previous hadoop.First, install zookooper1. Decompress zookoope
"Every 5-10 years, there's a rare product, a really special, very unusual product that's the most un
© 2024 shulou.com SLNews company. All rights reserved.