myITforum.com Community Forum myITforum.com Community Forum

Home  Forums  Blogs  Live Support chat  Search Articles  Wiki  FAQ  Email Lists  Register  Login  My Profile  Inbox  Address Book  My Subscription  My Forums 

Photo Gallery  Member List  Search  Calendars  FAQ  Ticket List  Log Out

All Forums RSS Feed Subscription:


  


Client Push Installation: Cannot connect using machine account

 
View related threads: (in this forum | in all forums)

Logged in as: Guest
  Printable Version
All Forums >> [Management Products] >> Microsoft Systems Management Server >> SMS 2003 >> Client Push Installation: Cannot connect using machine account Page: [1]
Login
Message << Older Topic   Newer Topic >>
Client Push Installation: Cannot connect using machine ... - 8/8/2008 8:33:33 PM   
fault

 

Posts: 32
Score: 2
Joined: 7/21/2008
Status: offline
Hi guys,

Just playing around with SMS 2003 in my lab environment. I'm wanting to secure it with minimal accounts/privileges as required. I'm running in Advanced Security mode with Advanced Clients only. I have not specified any Client Push Installation Accounts. With this configuration, I get the following errors on the SMS site server in ccm.log:

quote:


======>Begin Processing request: "GZOVRXAR", machine name: "XP1"    SMS_CLIENT_CONFIG_MANAGER    9/08/2008 9:34:18 AM    3360 (0x0D20)
---> Trying each entry in the SMS Client Remote Installation account list    SMS_CLIENT_CONFIG_MANAGER    9/08/2008 9:34:18 AM    3360 (0x0D20)
---> Warning: no remote client installation or SMS service account found    SMS_CLIENT_CONFIG_MANAGER    9/08/2008 9:34:18 AM    3360 (0x0D20)
---> Attempting to connect to administrative share '\\XP1\admin$' using machine account.    SMS_CLIENT_CONFIG_MANAGER    9/08/2008 9:34:18 AM    3360 (0x0D20)
---> Failed to connect to \\XP1\admin$ using machine account (5)    SMS_CLIENT_CONFIG_MANAGER    9/08/2008 9:34:18 AM    3360 (0x0D20)
---> ERROR: Connected to XP1 registry, but couldn't connect to the \\XP1\admin$ share using account ''    SMS_CLIENT_CONFIG_MANAGER    9/08/2008 9:34:18 AM    3360 (0x0D20)
---> ERROR: Unable to access target machine for request: "GZOVRXAR", machine name: "XP1", error code: 5    SMS_CLIENT_CONFIG_MANAGER    9/08/2008 9:34:18 AM    3360 (0x0D20)
STATMSG: ID=3014 SEV=W LEV=M SOURCE="SMS Server" COMP="SMS_CLIENT_CONFIG_MANAGER" SYS=SMS1 SITE=SYD PID=1732 TID=3360 GMTDATE=Fri Aug 08 23:34:18.621 2008 ISTR0="XP1" ISTR1="" ISTR2="" ISTR3="" ISTR4="" ISTR5="" ISTR6="" ISTR7="" ISTR8="" ISTR9="" NUMATTRS=0    SMS_CLIENT_CONFIG_MANAGER    9/08/2008 9:34:18 AM    3360 (0x0D20)
Retry request id for "GZOVRXAR" set to "XP1"    SMS_CLIENT_CONFIG_MANAGER    9/08/2008 9:34:18 AM    3360 (0x0D20)
Stored request "XP1", machine name "XP1", in queue "Retry".    SMS_CLIENT_CONFIG_MANAGER    9/08/2008 9:34:18 AM    3360 (0x0D20)
<======End request: "XP1", machine name: "XP1".    SMS_CLIENT_CONFIG_MANAGER    9/08/2008 9:34:18 AM    3360 (0x0D20)


Documentation out there seems to say that you must specify at least one Client Push Installation Account (e.g., Automated Installation by Using the SMS Administrator Console). But I would have thought that you could use the machine account (e.g., XP1$) which has elevated privileges to install the client? The logs also seem to suggest that it attempts to even do this (i.e., first two lines above highlighted in red) but specifies that it failed to connect. Anyone know why the machine account cannot be used?

Specifying a domain level account with local administrative privileges on the client works fine, but I'm interested in the above situation.

Thanks.
Post #: 1
RE: Client Push Installation: Cannot connect using mach... - 8/9/2008 10:52:52 AM   
gjones


Posts: 824
Score: 50
Joined: 6/5/2001
From: Ottawa, Ontario, Canada
Status: offline
Did you add the SMS Machine account as a Domain Admin? If you didn't, this is required.

_____________________________

Garth@enhansoft.com

For a List of my Articles
http://www.myitforum.com/contrib/default.asp?cid=116
Blogs:
http://smsug.ca/blogs/garth_jones/default.aspx
http://myitforum.com/cs2/blogs/gjones/default.aspx


(in reply to fault)
Post #: 2
RE: Client Push Installation: Cannot connect using mach... - 8/12/2008 8:03:08 AM   
fault

 

Posts: 32
Score: 2
Joined: 7/21/2008
Status: offline
@gjones: Ah right, that would make sense! Thanks. Will give it a go. Any ideas why Microsoft doesn't (seem to?) advocate this and prefers you to use a service account (domain or local level) that has local administrative privileges?

(in reply to fault)
Post #: 3
RE: Client Push Installation: Cannot connect using mach... - 8/12/2008 10:11:17 AM   
gjones


Posts: 824
Score: 50
Joined: 6/5/2001
From: Ottawa, Ontario, Canada
Status: offline
Thing change over time... In ConfigMgr this is the way to go. :-)

_____________________________

Garth@enhansoft.com

For a List of my Articles
http://www.myitforum.com/contrib/default.asp?cid=116
Blogs:
http://smsug.ca/blogs/garth_jones/default.aspx
http://myitforum.com/cs2/blogs/gjones/default.aspx


(in reply to fault)
Post #: 4
Page:   [1]
All Forums >> [Management Products] >> Microsoft Systems Management Server >> SMS 2003 >> Client Push Installation: Cannot connect using machine account Page: [1]
Jump to:





New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts



  
Forum Software © ASPPlayground.NET Advanced Edition 2.4.5 ANSI

0.297