on 06-04-2015 2:43 PM
We installed a new dialog instance on our QAS system. The system
previously had two instances that were clustered. We then uninstalled
the new dialog instance. When we uninstalled, we answered "yes" to the
question to remove OS accounts. The system uses SNC. Now we can't log
in using SNC. We get a message that says:
GSS-API(maj):Miscellaneous Failure
GSS-API(min):SPPI u2u-problem: please add Service principle to targe
targer="p:SAPServiceQAS@ABCD.ORG"
Error in SNC
I think the qasadm and SAPAServiceQAS domain accounts got deleted when
the new dialog instance was uninstalled. To try to resolve this issue, we tried to
reinstall the dialog instance. I think this recreated the qasadm and SAPServiceQAS domain accounts.
We got an error when sapinst tried to start the new instance. Errors in the dev_w* files say:
C ERROR: -1 in function SQLConnectWithRetry (SQLConnectWithRetry)
[line 2307]
C (18456) [28000] [Microsoft][SQL Server Native Client 10.0][SQL
Server]Login failed for user 'ABDC\SAPServiceQAS'.
I had our system administrator add gasadm and SAPServiceQAS into the
Administrators group on the two clustered servers, but we still get the
same error when we try to log in. The system is still up and we can
log in without using SNC (by entering the username and password).
I don't want to try to restart the system because it may not start.
What do we need to do?
Thanks,
Jerry
Hello,
Even if you manually create the accounts, several other manual steps would have to be performed.
That is because Windows has an internal ID (called "SID") to identify the account, and when you set permissions at the filesystem (for example), the SID that is stored at the permission table, not the username itself.
Thus, you would have to at least:
- replace the permissions of all SAP folders; and
- replace the permissions of all shares related to SAP (e.g., "sapmnt").
You might also need to edit the SAP services ("SAP<SID>_xx" services) at the Windows Services, retyping the user Id/password there.
However, the only "supported solution" would be to completely uninstall and then reinstall this system.
You could check for "system copy" procedures. Depending on your SAP version, you can create a database backup (using DB tools) and use the system copy "target system" option to reinstall the system without losing the data.
You can find the system copy guides at:
http://www.service.sap.com/sltoolset ->
Software Logistic Toolset 1.0 ->
[Scroll down the page] System Provisioning ->
Installation: Systems Based on SAP NetWeaver 7.0 / 7.0 EHPs
Installation: Systems Based on SAP NetWeaver 7.1 and Higher
System Copy: Systems Based on SAP NetWeaver 7.0/7.0 EHPs
System Copy: Systems Based on SAP NetWeaver 7.1 or Higher
Regards,
Isaías
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Isaias,
Thanks for the information. The uninstall/reinstall sounds like what we will have to do. I was hoping the solution wouldn't be that hard. It might be a couple of weeks before we can try this. The system is still up and usable. We have some important projects going on now, so we don't want to take the system down to fix it. I'll let you know what happens.
Thanks again,
Jerry
Hi Isaias,
We were able to get the system working again without uninstalling/reinstalling. We did the following:
setspn -S SAPServiceQAS/name OUR_DOMAIN\SAPServiceQAS
This seems to have fixed the system. Everything seems to be working fine. I don't know if this was any better or faster that uninstalling and reinstalling the system. I'm sure that would have worked too. I appreciate your advice.
Thank you,
Jerry
User | Count |
---|---|
86 | |
10 | |
10 | |
10 | |
7 | |
6 | |
6 | |
5 | |
5 | |
4 |
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.