question

GordonSuchomski-6136 avatar image
0 Votes"
GordonSuchomski-6136 asked ·

Export keys fails using gMSA

Hello, I am about to install MIM Synchronization Service on a Windows 2012R2 system. I used SP2 if MIM2016 to install it and updated it to the lates hotfix release 4.6.359.0. I used the available descriptions to install the sync service using a gMSA account.
The service runs OK and I can access everything as expected with the service manager.
But one thing is just not working out - exporting the encryption keys via miiskmu.exe.
I started it via 'run as admin' and started miiskmu.exe via administrative command line: miiskmu.exe /e c:\configBU\exp3.bin /u:"mydomain\SVC-MIMSync$" The output is as follows:

 Installing assembly 'C:\Program Files\Microsoft Forefront Identity Manager\2010\ Synchronization Service\Bin\Microsoft.IdentityManagement.KeyProtectService.exe'. Affected parameters are: assemblypath = C:\Program Files\Microsoft Forefront Identity Manager\2010\Syn chronization Service\Bin\Microsoft.IdentityManagement.KeyProtectService.exe logfile = C:\Program Files\Microsoft Forefront Identity Manager\2010\Synchron ization Service\Bin\Microsoft.IdentityManagement.KeyProtectService.InstallLog Installing service MIMKeyProtectService...
 Creating EventLog source MIMKeyProtectService in log Application...

The contents of the installLog ends at the same line 'Creating EventLog source MIMKeyProtectService in log Application...'.
The same works without a problem when using a standard account instead of a gMSA account.
For any reason the spun up application is not able to create an event log source when running with a gMSA account.
Can someone give me a hint what I am missing? Thanks a lot!

73749-mim-gmsa-miiskmu-error.jpg


microsoft-identity-manager
10 |1000 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

LeoErlandsson avatar image
0 Votes"
LeoErlandsson answered ·
·
10 |1000 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

GordonSuchomski-6136 avatar image
0 Votes"
GordonSuchomski-6136 answered ·

Yes - the screenshot is from using the GUI. And yes I used 'run as admin'.

·
10 |1000 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

GordonSuchomski-6136 avatar image
0 Votes"
GordonSuchomski-6136 answered ·

Another question comes into my mind. What is the impact of this tool and the encryption keys anyways. I have changed the MIM Sync Service Account now for serval times from local to domain and gMSA users, but I was still able to start the service and my management agents without any problems so far. It is only miiskmu which is not working when using a domain account as a service account. Miiskmu is working when using a local account as service account.
To be more specific about the environment I am using. It is just the sync service I am using, no Sharepoint, MIM Service or anything else is running.

·
10 |1000 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.