Hi,
We have 2 forests, ForestA and ForestB.
FIM is deployed in ForestA.
FIM is synchronising users from ForestB (via ForestB MA) to ForestA (via ForestA MA).
ForestA and ForestB are connected via a 2 way Kerberos Trust.
All firewalls have been disabled between the virtual machines.
In ForestB we have deployed PCNS and ran the following command: pcnscfg ADDTARGET /N:FIMServer /A:FIM01.forestA.com /S:PCNSCLNT:FIM01.forestA.com /FI:"Domain Users" /f:3
In ForestA we have registered the SPN as: setspn -A PCNSCLNT/FIM01.forestA.com ForestA\FIMSyncService
FIM is importing users from ForestB and successfully provisioning them in ForestA.
FIM is configured as follows:
- FIM/Tools/Options/ Enable Password Synchronization is selected
- ForestB MA is configured as the Password Synchronization source / with ForestA selected as the Target MA
- ForestA MA / Configure Extensions / Enable Password Management is enabled
However, when a user changes their password in ForestB, event viewer on ForestB domain controller errors with:
Password Change Notification Service received an RPC exception attempting to deliver a notification.
The password change notification target could not be authenticated.
Additional Details:
Thread ID: 4300
Tracking ID: xxx...
User GUID: xxx...
User: FORESTB\test1
Target: FIMServer
Delivery Attempts: 60
Queued Notifications: 1
0x00000721 - A security package specific error occurred.
ProcessID is 2100
System Time is: 4/7/2014
Generating component is 2
Status is 1825 - A security package specific error occurred.
Detection location is 1710
Flags is 0
NumberOfParameters is 1
Long val: 0
ProcessID is 2100
System Time is: 4/7/2014
Generating component is 2
Status is 1825 - A security package specific error occurred.
Detection location is 1461
Flags is 0
NumberOfParameters is 0
ProcessID is 2100
System Time is: 4/7/2014
Generating component is 2
Status is 1825 - A security package specific error occurred.
Detection location is 141
Flags is 0
NumberOfParameters is 1
Long val: -1073
ProcessID is 2100
System Time is: 4/7/2014
Generating component is 3
Status is -1073
Detection location is 140
Flags is 0
NumberOfParameters is 4
Long val: 16
Long val: 6
Unicode string: PCNSCLNT/FIM01.FORESTA.COM
Long val: 681
Any ideas?
- Edited by Shim Kwan Wednesday, April 09, 2014 8:40 AM