2 Replies Latest reply on May 14, 2009 3:07 PM by JesseB

    AutoDomain 5.0.1.0

      When I was using Autodomain 5.0.0.7 things worked OK...but we upgraded for the the benefits of RunOnceOnLogon to make our re-vamp of user assignments even more transparent to the users.

      Now, what is happening is I am getting these messages /errors in the logs:

      I tested the Endpoint Encryption API, it's working but the version is unknown as the API is not in this directory <--of course, c:\temp will not have the api in it. When I copy the script to the clientdir and run it, I don't get this. Is there something I am missing or forgetting to do with this new version?

      Driver access blocked so using alternate detection method
      Found Endpoint Encryption for PC's using alternate method.
      0xe0020021 | Access to driver not permitted
      <--I understand you have to be an admin...but what I don't understand is why this never happened with the previous version. What is it doing here that the previous versions didn't do?


      User domain SID is :S-1-5-21-682360685-2186607748-4282500629
      Matched SID against the domain ABC
      Skipped User (could not determine name):
      Skipped User (could not determine domain): with subkey S-1-5-21-682360685-2186607748-4282500629-24135
      <--now it is only adding the current user....and it is not processing all cached profiles. Is this by design? BTW, it does this regardless of the users permissions. It even does it on my laptop.
        • 1. RE: AutoDomain 5.0.1.0
          I tested the Endpoint Encryption API, it's working but the version is unknown as the API is not in this directory <--of course, c:\temp will not have the api in it. When I copy the script to the clientdir and run it, I don't get this. Is there something I am missing or forgetting to do with this new version?


          >no, it just does not know where the API is so can't check the version. I might fix this if I get a moment, but it's not important - all versions of the API are (currently) compatible.


          Driver access blocked so using alternate detection method
          Found Endpoint Encryption for PC's using alternate method.
          0xe0020021 | Access to driver not permitted <--I understand you have to be an admin...but what I don't understand is why this never happened with the previous version. What is it doing here that the previous versions didn't do?

          >they did, you probably didn't notice though. It's probably just throwing more debug than the old version you were using. It's getting around the fact that you are not an admin by using a sneaky alternate detection method.

          User domain SID is :S-1-5-21-682360685-2186607748-4282500629
          Matched SID against the domain ABC
          Skipped User (could not determine name):
          Skipped User (could not determine domain): with subkey S-1-5-21-682360685-2186607748-4282500629-24135 <--now it is only adding the current user....and it is not processing all cached profiles. Is this by design? BTW, it does this regardless of the users permissions. It even does it on my laptop.

          >You have exact domain matching switched on I guess, turn that off and it will be more lenient. Either that or fill in the right domain/sid lookups in your ini file so it can work them out.
          • 2. RE: AutoDomain 5.0.1.0
            I switched back to the previous version with the exact same configs (minus the additions in 5.0.1.0 everything is the same....SIDs et all) and it works perfectly. Processes all cached profiles, modifies the computers object etc... So I rolled back and just disabled HTML output and set it to run every time so it is transparent to the users.

            Not sure that the difference between versions, but our environment likes the old one better.

            Also, one thing I noticed with the new version was that if you deleted the log file, on the next run, a prompt appeared with no message, just an OK button. Only did that if the file didn't exist...didn't care if you wipe the contents of the file.


            Anyhow, thanks for the assistance happy