You are viewing limited content. For full access, please sign in.

Question

Question

Adding LFDS Group/User to Repository - Error 9357

asked on January 24, 2024

Hello,

I am setting up a brand-new repository and LFDS. I have created LFDS, licensed the repository under the root organization. Create a user and group under the root organization and attempting to add it to the repository. I keep getting the following error:

Error Code: 9357
Error Message: LDAP query could not be completed. [9357]

------------ Technical Details: ------------

LFSO:
    Call Stack: (Exception)
        CLFDirectorySearcher::ThrowLastError
    Additional Details:
        HRESULT: 0xc004248d (CLFDirectorySearcher::ThrowLastError, LFDirectorySearcher.cpp:330)
         (LFSO/11.0.2101.7)
LFCommonDialogs110.dll (11.0.2102.79):
    Call Stack: (Current)
        CLFObjectPickerMain::FindLDAPAccounts
        CLFObjectPicker::DoPicker
    Call History:
        CLFObjectPicker::DoPicker
         CLFObjectPickerLocationTreeCtrl::GetDefaultPath
         CLFObjectPickerMain::FindLDAPAccounts

I have confirmed that traffic over 5048 and 5049 are open in to LFDS as attached in my picture below. Has anyone else experience this? My STSEndpointUtility and XMLEndpointUtility on the LFDS server are configured with the LFDS host name and same service account that is running the Repository, using a *wildcard certificate that is being used on the Repository server as well for WebClient and WebLink. Both servers are on the same domain and same subnet. 

2024-01-24_15h10_14.png
0 0

Answer

SELECTED ANSWER
replied on January 30, 2024

The answer to this question was that the AppPool user did not have access to the SQL database to perform this lookup task. I just so happened to be using a GMSA account but tested with a normal AD SVC account without SQL access and saw the same error.

0 0
replied on January 30, 2024

Which app pool specifically?

0 0
replied on May 30, 2024

both app pools for LFDS are LFDS DB_OWNERS in my case. Which app pool are you referring to?

0 0

Replies

You are not allowed to reply in this post.
You are not allowed to follow up in this post.

Sign in to reply to this post.