cancel
Showing results for 
Search instead for 
Did you mean: 

Dialog instance on Windows 2008 R2

0 Kudos

Hi,

We're trying to install a dialog isntance for our solution manager

Central Instance is on iSeries

Dialog Instance will be on Windows 2008 R2 Standard Edition because we want to install ADS

But when we are on Install instance basics of D00 we get an error when the system trys to start service SAP<SID>_00

We think it s.th. related with the user/pwd and i5/OS NetServer

We have granted to the user rights for

Policy Setting

Log on as a batch job <DOMAIN>\Admins. del dominio, <DOMAIN>\SAPSe<SID>, <DOMAIN>\<SID>adm

Log on as a service <HOST>\sapadm, <DOMAIN>\<SID>adm, <DOMAIN>\SAPSe<SID>, <DOMAIN>\Admins. del dominio, admins. del dominio

Local Policies/Security Optionshide

Network Securityhide

Policy Setting

Network security: LAN Manager authentication level Send LM & NTLM - use NTLMv2 session security if negotiated

But we get errors on windows

Log Name:      Security

Source:        Microsoft-Windows-Security-Auditing

Date:          14/03/2013 17:14:39

Event ID:      4648

Task Category: Logon

Level:         Information

Keywords:      Audit Success

User:          N/A

Computer:      <HOST>.<DOMAIN>.com

Description:

A logon was attempted using explicit credentials.

Subject:

          Security ID:                    <DOMAIN>\SAPSe<SID>

          Account Name:                    SAPSe<SID>

          Account Domain:                    <DOMAIN>

Account Whose Credentials Were Used:

          Account Name:                    <SID>adm

          Account Domain:                    <DOMAIN>

Target Server:

          Target Server Name:          ?????M

          Additional Information:          ?????M

Process Information:

          Process ID:                    0xef0

          Process Name:                    E:\usr\sap\<SID>\D00\exe\sapstartsrv.exe

Network Information:

          Network Address:          -

          Port:                              -

This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials.  This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.

But we have made symbolic link on windows 2008

mklink /d E:\usr\sap\<SID>\SYS \\<CI>.<DOMAIN>.com\sapmnt\<SID>\SYS

and if we change on regedit the service properties from network connection to local connection i.e.

"E:\usr\sap\<SID>\D00\exe\sapstartsrv.exe" pf="\\<CI>\sapmnt\<SID>\SYS\profile\START_D00_<HOST>"

"E:\usr\sap\<SID>\D00\exe\sapstartsrv.exe" pf="E:\usr\sap\<SID>\SYS\profile\START_D00_<HOST>"

The service starts without problems

And also if we set the service as is that with networ share and restart the computer the service starts without problems.

I do not know what is doing SapInst with the creation of the service and the startup that locks the user.

Did any body experience this problems? Any idea?

And does any body knwos how to set the creation of this step as done on the sapinst in order to continue as if we set the service manually it works without problems

Rgds,

Jaume

Accepted Solutions (0)

Answers (2)

Answers (2)

0 Kudos

Hi,

It seems that we've found a solution

We've modified files keydb.xml and inifile.xml changing all references to profile files from

"\\<cihost>\sapmnt\<sid>\SYS\profile\" to "E:\usr\sap\<sid>\SYS\profile\"

Restarted sapinst and the process followed on.

Now we have another problem we're getting a timeout for the instance come up yet this dialog instance is on a remote centre, we have

FCO-00011  The step start with step key |NW_DI|ind|ind|ind|ind|0|0|NW_DI_Instance|ind|ind|ind|ind|di|0|start was executed with status ERROR ( Last error reported by the step: ABAP processes of instance SSM/D00 [ABAP: UNKNOWN, Java: UNKNOWN] did not start after 10:00 minutes. Giving up.).

Now we have to find if there is any place where to change the timeout in order to increase it

Rgds,

Jaume.

Former Member
0 Kudos

Hi Jaume,

It seems like you have tried must of the possible solutions to this issue. I thing I would also check is to make sure the user SIDadm has not been disabled for NetShare access... I found out this recently myself. Open your System i Navigator, and add/go to your hostname, under File System, right-click File Shares and select "Open i5/OS NetServer". In the new window, go to File - Disabled User IDs and make sure your SIDadm is not there. If this still doesn't work, I would not recommend to skip the step.

Regards,

Luis