Need help setting up GMSA account for AD connector here.
Followed DOCO and ran every command Sailpoint suggested
Getting below error during test connection:-
Error Received:
Detected password less authentication, but failed to retrieve passwords with error: Exception occurred while executing the RPCRequest: Errors returned from IQService. Buffer cannot be null. Parameter name: buffer
Hey Maninder, this looks more like a IQService is not able to retrieve the gMSA password at runtime.
Could you plz try checking the AD Domain Settings, keep the gMSA UPN in the user field, leave password blank, use Strong/SASL, enable passwordless auth, and use port 389 with SSL off?
Also IQService is running as the gMSA on your server, could you plz also verify that both the gMSA itself and the IQService server’s computer account (SERVERNAME$) are allowed to retrieve the gMSA password through PrincipalsAllowedToRetrieveManagedPassword ?
Thanks Harish for the response. I followed the same but still getting same buffer error, below is the entry for that field. The group mentioned has IIQ server in it so have access to it.
To add, I have two IIQ server (gmsa setup on both), on one server I got this error but when I switched to the other one I got this error: “message”: “returnMap {result=error, message={ExceptionType=sailpoint.connector.ConnectorException, LocalizedMessage=Detected password less authentication, but failed to retrieve passwords with error: Connection reset}}”,
Thanks for the details. Everything checked and looks good but still getting the error.
Found some points if need to add it in? Anyway tried but still failing.
Navigate to registry and search for SailPoint registry hive. Computer\HKEY_LOCAL_MACHINE\SOFTWARE\SailPoint\IQService Instances\IQService-InstanceName
Right-click on the Instance and select permission.
Along with the IQ server, The account used to run the IQ service should have the PrincipalsAllowedToRetrieveManagedPassword
Can you confirm if this is in place. Thank you
REf this line : Set-ADServiceAccount -Identity myMSAAccount$ -PrincipalsAllowedToRetrieveManagedPassword IQserviceuser1
The gMSA service account can also be used as the IQService LogOn User (Windows Service LogOn User). In this case, ensure that the gMSA service account has full access to the IQService Instance folder on the registry.
The gMSA account itself and the IQService server computer account are granted permission to retrieve the gMSA password, eliminating the need to set permissions for the IQService LogOn User.
Yes Naveen. There is a group created which has IQ server and the account listed under that parameter. One thing I observed that UPN value is missing on that gmsa account so working on that to get that added and will try next.
All prereq’s are there already with permission so wondering where the issue is coming from
I think I am guessing where the issue is as it seems something related to server certificate. I have initiated new cert and upload in server and updated the same for IQservice. But somehow its still giving me same error with old dns name which I cant find anywhere else on server or VA side.
Received header length as - Error in parsing - input string was not in a correct format