SAP Knowledge Base Article - Preview

1886178 - Intermittent or consistent failures with AD group mapping from remote forest in BI 4.x

Symptom

  • Receiving invalid SID error when scheduling AD updates or updating manually
  • CMS trace has errors like (the bold parts below are important to identify the issue, the rest is just informational and may vary)
  • Could not locate a DC for domain (domain name) or domain does not exist.
  • Error getting a DC for the sid
  • The secWinAD plugin failed to look up the account for the group "Group SID". Please enter non-local groups as DomainName\GroupName and local groups as \\ServerName\GroupName.) while trying to retrieve info for group: "group SID"
  •  assert failure: (.\ad_acct_entity.cpp:152). (false : WINAD: CAccountEntity::InitFromSid() -- BindIADsToLDAPFromSid hr=-2147467259).
  • More recently seen error "The Active Directory Authentication plugin failed to verify the domain:(domain name)"
  • To note the error in BOLD is the most relevant if you should run across this KBA, it seems that some of the other parts of the error are misdirecting other issues to this KBA, this KBA is about a DOMAIN problem ONLY! if that part of the error is missing you have a different issue.


Read more...

Environment

SAP BusinessObjects Business Intelligence Platform 4.0 4.1 4.x all SP's

Product

SAP BusinessObjects Business Intelligence platform 4.0

Keywords

zie SSO single sign on sign-on automatic logon multiple forests , KBA , multi , could not find dc , emkba , emkb , biauth , active , directory , ikba , BI-BIP-AUT , Authentication, ActiveDirectory, LDAP, SSO, Vintela , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.