Agramont.net

Sr. Product Manager, Enterprise Tech for Accelrys
Welcome to Agramont.net Sign in | Join | Help
in Search

Conrad Agramont's Blog

Resolving the "No trusted group name..." issue

During a "rebuild" of my lab today, I came across the following error:

<response><errorContext description="No trusted group name was specified in the site properties. The method can be invoked only by trusted group members of the provisioning site." code="0xc2201518" executeSeqNo="0"/></response>

This error would always show now matter what MPF request I submitted to Provtest.exe via the command line.

The key thing to not here is that this was part of a "rebuild".  Thus, there was a "working environment of MPS (the HMC 3.0 flavor) and I "blew it away" to start over [sort of] fresh.  I did all of the things you should clean up (more info on this below), but forgot a very important step.  I didn't delete the SQL Logins for the MPF Accounts on the SQL Server where the MPF Databases once resided.  When you redeploy the MPF databases via the "Provisioning Deployment Tool" the databases will be created, but the SQL Logins will not be updated.  So this issue is that the SQL logins point to the Active Directory names (e.g. MPFServiceAccts), but the underlying reference is the old account SID and not the newly created (by the deployment tool) ones.

Here is what I did to fix this:

  1. Delete all of the MPF related SQL Logins
  2. Add SQL Logins for the below Active Directory accounts and assign to the below database roles
Login Database/Role
MPFAdmins
  • MPFAudit/MPFAdminsRole
  • MPFConfig/MPFAdminRole
  • MPFTranLogData/MPFAdminRole
  • ResourceManager/MPFAdminRole
MPFAuditors
  • MPFAudit/MPFAuditorsRole
MPFClientAccts
  • MPFConfig/MPFClientRole
MPFServiceAccts
  • MPFAudit/MPFServiceRole
  • MPFConfig/MPFServiceRole
  • MPFTranLogData/MPFServiceRole
  • ResourceManager/MPFServiceRole

Once I did this, I had to "shutdown" the "Provisioning Engine" COM+ application.  Rebooting the MPS server also works.

Now there might be other issues why this error will appear, but on this day the above solution worked out.

So what should you do when you "rebuild" and MPS Deployment? 

They key thing to note here is that I wasn't trying to keep the old data or structure.  So this was a full rebuild, but without uninstalling Active Directory, Exchange, SQL, etc.  This is by no means the definitive list (I guess that will be another task/posting), but it should give you a good idea of what to address:

  1. Use the "Provisioning Deployment Tool" to remove all services
  2. Delete the MPSDeploymentAccount from Active Directory
  3. Delete the MPF Databases
  4. Delete the Plans Database
  5. Delete the MPF SQL Logins (note the table above, but also the MPSPlansAcct SQL Login)
  6. Reboot all servers.

Comments

 

Conrad Agramont's WebLog said:

June 27, 2006 1:26 AM
 

Marcel Messing said:

whats up conrad!! update: got this same error for hmc 4.0 and wanted to add the: MPSPlansAccts group as well to the list, with PlanManager/PlanManagerRole
August 10, 2007 10:44 AM
 

agramont said:

Hey Marcel!!  Thanks for posting the update.  I have yet to give HMC 4.0 a spin, but I'm sure I'll get to it soon enough.

August 10, 2007 11:09 AM
 

Mohamed Magdy said:

Hey guys i dont have Experiance in SQL Server and i dont know how to add or delet SQL Logins and i have the same problem

could any one please tell me how to Add SQL Server Logins?

Thanx in Advanced

May 7, 2009 8:42 AM

Leave a Comment

(required) 
(optional)
(required) 
Submit

About agramont

Conrad Agramont is focused on .NET Development, Virtualization, Windows 7, Windows Server 2008, Virtual Desktop, and Microsoft Business Productivity (Exchange, Office, Live Communications)
For more information on Conrad and Agramont Services, please visit: http://agramontservices.com
Follow Me On Twitter (@agramont)

This Blog

Syndication

News

Add to Technorati Favorites

Community Tools