Video Screencast Help
Symantec Appoints Michael A. Brown CEO. Learn more.

EV 10.0.1 FSA Agent installation fails on Domain controller

Created: 29 Jan 2013 • Updated: 04 Feb 2013 | 5 comments
This issue has been solved. See solution.

Hi,

VSA is on DOMAIN-AAA and File server is on DOMAIN-BBB and File server is a Domain Controller. Both domains are two way trusted domains.

We have added VSA from Domain-AAA into built-in administrator's group in the domain controller (file server) in Domain-BBB

Deployment scanner reports no problem. However while trying to deploy FSA Agent it fails. Log below. Any idea please?

 

 
Checking for prerequisites.
Getting command line and credentials.
Command line:/i "C:\BEW-92c0e029cea74b35aa417fdb7df65f2e\temp\ScSetup\Enterprise Vault File System Archiving.msi" /l*v EVFSAInst.log REBOOT=ReallySuppress  FEATURE_PLACEHOLDER="1" ALLUSERS="2"
Domain name:DOMAIN-AAA
User name:VSA
MSI file: C:\BEW-92c0e029cea74b35aa417fdb7df65f2e\temp\ScSetup\Enterprise Vault File System Archiving.msi
MSI Log file: C:\WINDOWS\Temp\EVFSAInst.log
MSI Properties: REBOOT=ReallySuppress  FEATURE_PLACEHOLDER="1" ALLUSERS="2"
Checking MSIEXEC version...
MSI ImagePath: C:\WINDOWS\system32\msiexec.exe /V
msiexec.exe path:C:\WINDOWS\system32\msiexec.exe
Checking version of: C:\WINDOWS\system32\msiexec.exe
File Version: 3.1.4000.3959
Msi version OK
Detecting Visual Studio 2005 x86 Runtimes 
Detected Visual Studio 2005 x86 Runtimes 
Detecting Visual Studio 2008 x86 Runtimes 
Detected Visual Studio 2008 x86 Runtimes 
Getting Processor Identifier
Processor: x86 Family 15 Model 4 Stepping 1, GenuineIntel
AddUserToLocalAdminGroup() Succeeded.
GrantUserRight() Failed.
Installation failed with error code 5.

Comments 5 CommentsJump to latest comment

JesusWept3's picture

Error code 5 is access denied
You're installing an MSI right? is there a setup.exe with it?
What happens if you run it with elevated priveliges? i.e. run as administrator?
Also do you have UAC enabled?

And do you see anything in the Security event logs that might indicate an issue authenticating the user against the other domain?

Darren Locke's picture

You will not be able to install on a domain controller unless you give the VSA domain admin rights. Good news though, the 10.0.3 agent requires reduced permissions. It will need to be a member of the print operators group. Check out the FSA Installation guide from 10.0.3 for more details.

Darren

StephenConnolly's picture

There are also specific permissions\privileges that need to be set on the server with the PDCEmulator role, which may , in addition to being a member of the administrators group on the DC. FWIW I would suggest you copy the MSI locally to the DC and run it from there - the UI will guide you through setting up the additional privileges, depending on whether the DC is a PDC emulator or not.

Stephen Connolly | Configuration Manager| Cofunds Ltd | LinkedIn

SOLUTION
ia01's picture

Thanks everone for replying. What we did is copied the MSI manually and installed from within the DC  while logged in as Domain Admin.