Advertisement

05.01.2008 at 01:40PM PDT, ID: 23370018 | Points: 250
[x]
Attachment Details
Need help resolving why changing minPwdLength leads to 1202 and 1085 events/errors
Tags: Microsoft, Server 2003, 2003, 1202 1085
Hey all,

We are running a native 2003 domain. (Test lab and production) I have a GPO to change the minimum password length from the default of 7 to 15 characters.

As you may know, that to accomplish this I needed to change the minPwdLength setting using ADSIEDIT. As soon as I changed that to 15 (Default is 14) we get 1202 and 1058 errors on the workstations in both the lab and production environments.

1202 - SceClie - Security policies were propagated with warning. 0x57 : The parameter is incorrect.
1085 - Userenv - The Group Policy client-side extension Security failed to execute. Please look for any errors reported earlier by that extension.

All workstations or XPXSP2 and the servers are 2003 SP2. (Latest updates and patches as well.) Test lab is 100% clean, (Brand new domain.)

 If I change it back to 14, the errors go away. This is easily reproducible in the test lab. Any thoughts on what I need to do to the workstations to eliminate the errors?

Thanks
Start your free trial to view this solution
Question Stats
Zone: OS
Question Asked By: Rikketyrik
Question Asked On: 05.01.2008
Participating Experts: 2
Points: 250
Views: 0
Translate:
Loading Advertisement...
05.04.2008 at 12:04PM PDT, ID: 21496622

Rank: Genius

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.04.2008 at 01:00PM PDT, ID: 21496767

Rank: Master

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.04.2008 at 05:59PM PDT, ID: 21497583

Rank: Genius

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.05.2008 at 01:15AM PDT, ID: 21498673

Rank: Master

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.05.2008 at 05:02AM PDT, ID: 21499308

Rank: Genius

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.05.2008 at 09:07AM PDT, ID: 21500979

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.05.2008 at 10:06AM PDT, ID: 21501362

Rank: Genius

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.05.2008 at 10:11AM PDT, ID: 21501398

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.05.2008 at 10:12AM PDT, ID: 21501403

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.05.2008 at 10:13AM PDT, ID: 21501407

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.05.2008 at 10:15AM PDT, ID: 21501419

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.05.2008 at 11:24AM PDT, ID: 21501926

Rank: Genius

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.05.2008 at 11:33AM PDT, ID: 21501995

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.05.2008 at 02:03PM PDT, ID: 21502982

Rank: Genius

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.05.2008 at 02:25PM PDT, ID: 21503158

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.05.2008 at 04:08PM PDT, ID: 21503721

Rank: Genius

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.05.2008 at 05:26PM PDT, ID: 21503995

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.07.2008 at 08:02AM PDT, ID: 21517155

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.07.2008 at 09:44AM PDT, ID: 21518163

Rank: Genius

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.08.2008 at 02:39PM PDT, ID: 21528705

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.08.2008 at 03:16PM PDT, ID: 21528917

Rank: Genius

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.08.2008 at 03:38PM PDT, ID: 21529048

Rank: Master

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.08.2008 at 04:15PM PDT, ID: 21529235

Rank: Genius

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.08.2008 at 04:39PM PDT, ID: 21529387

Rank: Master

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.08.2008 at 04:51PM PDT, ID: 21529467

Rank: Genius

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.12.2008 at 09:43AM PDT, ID: 21548475

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
 
Loading Advertisement...
Microsoft
  • Internet Protocols
  • Applications
  • Development
  • OS
  • Hardware
  • Windows Security
Apple
  • Operating Systems
  • Hardware
  • Programming
  • Networking
  • Software
Internet
  • Search Engines
  • File Sharing
  • WebTrends / Stats
  • Spy / Ad Blockers
  • Web Browsers
  • New Net Users
  • Web Development
  • Chat / IM
  • Anti Spam
  • Web Servers
  • Anti-Virus
  • Email Clients
Gamers
  • Tips
  • Online / MMORPG
  • Puzzle
  • Emulators
  • Action / Adventure
  • Role Playing
  • Consoles
  • Game Programming
  • Strategy
  • Sports
  • Misc
  • Computer Games
Digital Living
  • Hardware
  • New Net Users
  • New Users
  • Software
  • Digital Music
  • Gaming World
  • Home Security
  • Apple
  • Networking Hardware
Virus & Spyware
  • Vulnerabilities
  • IDS
  • Encryption
  • Anti-Virus
  • Operating Systems Security
  • Software Firewalls
  • WebApplications
  • Cell Phones
  • Operating Systems
  • Internet
  • Hardware Firewalls
Hardware
  • Handhelds / PDAs
  • Displays / Monitors
  • Components
  • Networking Hardware
  • Peripherals
  • Laptops/Notebooks
  • Storage
  • Servers
  • Desktops
  • New Users
  • Misc
  • Apple
Software
  • System Utilities
  • Industry Specific
  • Network Management
  • Photos / Graphics
  • Page Layout
  • VMWare
  • Misc
  • Web Development
  • OS
  • CYGWIN
  • Voice Recognition
  • Message Queue
  • Quality Assurance
  • Security
  • Firewalls
  • MultiMedia Applications
  • Development
  • Database
  • Office / Productivity
  • Business Management
  • OS/2 Apps
  • Server Software
  • Internet / Email
ITPro
  • OS
  • Storage
  • Encryption
  • Operating Systems Security
  • Apple Hardware
  • Laptops & Notebooks
  • Servers
  • Networking Hardware
  • Peripherals
  • Devices
  • Displays / Monitors
  • WebTrends / Stats
  • Search Engines
  • Firewalls
  • WebApplications
  • IDS
  • Vulnerabilities
  • Email Clients
  • File Sharing
  • Spy / Ad Blockers
  • Web Browsers
  • Web Servers
  • Networking
  • Anti-Virus
  • Chat / IM
  • Anti Spam
Developer
  • Web Servers
  • Web Browsers
  • Game Programming
  • Dev Tools
  • Industry Specific
  • Office / Productivity
  • Database
  • CYGWIN
  • Web Development
  • Search Engines
  • File Sharing
  • WebTrends / Stats
  • Programming
  • Content Management
  • Application Servers
  • Protocols
Storage
  • Removable Backup Media
  • Storage Technology
  • Servers
  • Grid
  • Remote Access
  • Backup / Restore
  • Misc
  • Hard Drives
OS
  • Miscellaneous
  • Security
  • Development
  • Linux
  • VMWare
  • MainFrame OS
  • Unix
  • Apple
  • OS / 2
  • AS / 400
  • BeOS
  • Microsoft
  • VMS / OpenVMS
Database
  • Oracle
  • Miscellaneous
  • MySQL
  • Software
  • Sybase
  • Contact Management
  • PostgreSQL
  • Data Manipulation
  • Clarion
  • InterSystems Cache
  • Siebel
  • MUMPS
  • OLAP
  • SQLBase
  • SAS
  • GIS & GPS
  • 4GL
  • Berkeley DB
  • DB2
  • Informix
  • Interbase / Firebird
  • FoxPro
  • Reporting
  • LDAP
  • Filemaker Pro
  • MS SQL Server
  • dBase
  • MS Access
Security
  • Misc
  • Web Browsers
  • Software Firewalls
  • Operating Systems Security
  • File Sharing
  • Spy / Ad Blockers
  • Vulnerabilities
  • WebApplications
  • IDS
  • Anti-Virus
  • Encryption
  • Anti Spam
  • Email Clients
  • VPN
  • Chat / IM
Programming
  • Editors IDEs
  • Installation
  • Handhelds / PDAs
  • Multimedia Programming
  • System / Kernel
  • Algorithms
  • Game
  • Signal Processing
  • Project Management
  • Open Source
  • Database
  • Misc
  • Languages
  • Processor Platforms
  • Theory
Web Development
  • Scripting
  • Blogs
  • Web Servers
  • Software
  • Search Engines
  • Web Graphics
  • Images
  • Internet Marketing
  • Images and Photos
  • Components
  • Document Imaging
  • Web Languages/Standards
  • Illustration
  • WebApplications
  • Fonts
  • WebTrends / Stats
  • Authoring
  • Digital Camera Software
  • Miscellaneous
Networking
  • Protocols
  • Apple Networking
  • Network Management
  • Message Queue
  • Application Servers
  • Content Management
  • File Servers
  • Email Servers
  • Misc
  • Java Editors & IDEs
  • Wireless
  • Networking Hardware
  • Backup / Restore
  • System Utilities
  • ISPs & Hosting
  • Web Servers
  • Storage Technology
  • Removable Backup Media
  • Servers
  • Broadband
  • Grid
  • OS / 2
  • Novell Netware
  • Unix Networking
  • Windows Networking
  • Security
  • Telecommunications
  • Operating Systems
  • Linux Networking
Other
  • Community Advisor
  • Lounge
  • Community Support
  • New Net Users
  • Philosophy / Religion
  • Math / Science
  • Miscellaneous
  • URLs
  • Expert Lounge
  • Politics
  • Puzzles / Riddles
Community Support
  • Suggestions
  • New to EE
  • New Topics
  • Community Advisor
  • CleanUp
  • Announcements
  • General
  • Feedback
  • Input
  • EE Bugs
 
05.04.2008 at 12:04PM PDT, ID: 21496622

Rank: Genius

Why are you using ADSIEdit?

You change this in the Default Domain Policy.  This is one reason you're seeing errors.

 
05.04.2008 at 01:00PM PDT, ID: 21496767

Rank: Master

You can't do the change in the normal Default Domain Policy when you want the value to be above 14.
 
05.04.2008 at 05:59PM PDT, ID: 21497583

Rank: Genius

Ok, you need to stay out of ADSIEdit for this.  Changing attributes directly like this is not recommended.

Find the GUID associated with your domain policy.
Drill down into %systemroot%\SYSVOL\domain\policies\{GUID of Default Domain Policy}\MACHINE\Microsoft\WindowsNT\SecEdit
Open GptTmpl.inf with Notepad - be sure not to associate Notepad permanently!!!!
Change the value of MinimumPasswordLength to 15
Save it.
Increment the the value for the version number in GPT.ini in the folder %systemroot%\SYSVOL\domain\policies\{GUID of Default Domain Policy} by, say, 5 to ensure no collisions.
Save it.
Allow the policies to refresh or run Gpudate /force.

Make sure you do this on the PDCe.

Advise.
 
05.05.2008 at 01:15AM PDT, ID: 21498673

Rank: Master

Yes, I had a similar thaught about replication conflict as I tested the ADSIedit-hack in a single server environment without having any problem.
 
05.05.2008 at 05:02AM PDT, ID: 21499308

Rank: Genius

The issue is more than simply collisions.  If you make that change in the Schema directly, then the above-mentioned files (basically your Default Domain Policy) are no longer in agreement with the settings.

 
05.05.2008 at 09:07AM PDT, ID: 21500979
No go.

I have made the changes as recommended above, replicated and tested. The workstation is still displaying the 1202 and 1058 error messages as soon as I make the change and run GPUDATE. If I back out of the changes, the error goes away.

I tried a few different combinations of changing on one server or the other and replicating etc. Still no luck. GPT.INI was incremented accordingly and replicated as expected.

The value in the GptTmpl.inf  and ADSIEDIT do not match however. The value in ADSIEDT stays the same when I change the GptTmpl.inf value. Currently the value is at 14. (That may be a red herring though.) If I make the password length 15 in either location either separately or together, the errors still occur. Currently the minPwdLength is set to 8.
 
05.05.2008 at 10:06AM PDT, ID: 21501362

Rank: Genius

Can you post the errors as they appear in the Event Log?

I need a few more parameters.
 
05.05.2008 at 10:11AM PDT, ID: 21501398
1202 - Userenv

The Group Policy client-side extension Security failed to execute. Please look for any errors reported earlier by that extension.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
 
05.05.2008 at 10:12AM PDT, ID: 21501403
1202 -  SCECLI

Security policies were propagated with warning. 0x57 : The parameter is incorrect.

For best results in resolving this event, log on with a non-administrative account and search http://support.microsoft.com for "Troubleshooting Event 1202's".
 
05.05.2008 at 10:13AM PDT, ID: 21501407
The first one should be "1085 - userenv" not "1202 - userenv". Sorry for the typo.
 
05.05.2008 at 10:15AM PDT, ID: 21501419
From winlogon.log

----Configure Security Policy...
Error 87: The parameter is incorrect.
       Error configuring password information.
      Configure account force logoff information.

      System Access configuration was completed with one or more errors.
 
05.05.2008 at 11:24AM PDT, ID: 21501926

Rank: Genius

In the Default Domain Policy - what have you set for Force Logoff?

 
05.05.2008 at 11:33AM PDT, ID: 21501995
It is disabled.

ForceLogoffWhenHourExpire = 0 in the test lab.
 
05.05.2008 at 02:03PM PDT, ID: 21502982

Rank: Genius

I wonder why it's complaining about that setting?

 
05.05.2008 at 02:25PM PDT, ID: 21503158
The ForceLogoffWhenHourExpire message "Configure account force logoff information." is a normal message and not an error. The error is really the password setting.

Error 87: The parameter is incorrect.
       Error configuring password information.
 
05.05.2008 at 04:08PM PDT, ID: 21503721

Rank: Genius

Theoretically, you should be able to increase the minimum via the method I posted earlier.  It seems, however, that your setup isn't happy with this.  I haven't got anything here ready to test this or I'd gladly do so.

Where did you get the info to use ADSIEdit?

 
05.07.2008 at 08:02AM PDT, ID: 21517155
Any other thoughts? I ran this against my home test lab and ran across the same issue. I am beginning to wonder if it is a "feature". :)
 
05.07.2008 at 09:44AM PDT, ID: 21518163

Rank: Genius

Does the policy actually work?  I'm thinking these errors may be benign.

You would think that the interface would accomodate considering the theoretical limit is much higher.

 
05.08.2008 at 02:39PM PDT, ID: 21528705
It does appear to be working OK. However, the error is fairly persistant on the workstations. Which clutters the logs....
 
05.08.2008 at 03:16PM PDT, ID: 21528917

Rank: Genius

What happens if you remove and rejoin a workstation with your policy set as you want it?

Perhaps the local copies of the Group Policy are not correct.

 
05.08.2008 at 03:38PM PDT, ID: 21529048

Rank: Master

Maybe you nead to rebuild secedit.sdb
If it's corrupt it can be tested with esentutl /g %windir%\security\atabase\secedit.sdb
Try to rename %windir%\security\database\secedit.sdb or repair it with esentutl/p
and reboot to recreate the secedit.sdb
 
05.08.2008 at 04:15PM PDT, ID: 21529235

Rank: Genius

@henjoh09 - it happens in both production and test lab, so I doubt both DBs would be corrupt.
 
05.08.2008 at 04:39PM PDT, ID: 21529387

Rank: Master

My thaught was that if trying to change to a value that normal isn't supported could maybe be treated to be a corrupt/inconsistent value compared to the definition of the database.
Other errors with eventid=1202 can been solved this way, so it's worth a try.
 
05.08.2008 at 04:51PM PDT, ID: 21529467

Rank: Genius

Don't try this in production.  Otherwise any application that adjusted or added to Security will need to be reinstalled.

 
05.12.2008 at 09:43AM PDT, ID: 21548475
I do believe that this change is supported by MS. I ran an inteirty check which came back as being OK. I then ran a repair for giggles, it too completed successfuly. The errors are still occuring. Any new thoughts?
 
 
20080236-EE-VQP-29 / EE_QW_2_20070628