SEP 11 security event id 599 on Domain Controller
Updated: 21 May 2010 | 39 comments
We are in the process of testing SEP 11 in our network we have 8 clients (All SEP Features installed) one dedicated SEPM (W2K3) test server, one domain controller and member server (Antivirus and Antispyware installed). All has been good with the test, the client rollout via the SEP Console, the SEP remote Console install. The one issue that we have had in our two week test besides that SEP decomposer LiveUpdate problem last week is that we are seeing these Failed Security Audits on our domain controller:
Event Type: Failure Audit
Event Source: Security
Event Category: Detailed Tracking
Event ID: 599
Date: 2/25/2008
Time: 4:48:04 PM
User: NT AUTHORITY\SYSTEM
Computer: DC1
Description:
Unprotection of auditable protected data.
Data Description: CValidateComCaller
Key Identifier: 921466af-0fa9-4321-8e94-eba34a0b7959
Protected Data Flags: 0x0
Protection Algorithms: 3DES-168 , SHA1-160
Failure Reason: 0xD
Event Source: Security
Event Category: Detailed Tracking
Event ID: 599
Date: 2/25/2008
Time: 4:48:04 PM
User: NT AUTHORITY\SYSTEM
Computer: DC1
Description:
Unprotection of auditable protected data.
Data Description: CValidateComCaller
Key Identifier: 921466af-0fa9-4321-8e94-eba34a0b7959
Protected Data Flags: 0x0
Protection Algorithms: 3DES-168 , SHA1-160
Failure Reason: 0xD
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Event Type: Success Audit
Event Source: Security
Event Category: Detailed Tracking
Event ID: 600
Date: 2/25/2008
Time: 4:48:03 PM
User: NT AUTHORITY\SYSTEM
Computer: DC1
Description:
A process was assigned a primary token.
Assigning Process Information:
Process ID: 744
Image File Name: C:\WINDOWS\system32\svchost.exe
Primary User Name: DC1$
Primary Domain: SCOPE
Primary Logon ID: (0x0,0x3E7)
New Process Information:
Process ID: 4604
Image File Name: C:\Program Files\Symantec\Symantec Endpoint Protection\SescLU.exe
Target User Name: DC1$
Target Domain: SCOPE
Target Logon ID: (0x0,0x3E7)
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Event Type: Success Audit
Event Source: Security
Event Category: Detailed Tracking
Event ID: 592
Date: 2/25/2008
Time: 4:48:03 PM
User: NT AUTHORITY\SYSTEM
Computer: DC1
Description:
A new process has been created:
New Process ID: 4604
Image File Name: C:\Program Files\Symantec\Symantec Endpoint Protection\SescLU.exe
Creator Process ID: 744
User Name: DC1$
Domain: SCOPE
Logon ID: (0x0,0x3E7)
According to eventid 599 is for encrypted data. the server has no encrypted data and I verfied with Efsinfo. Obviously these errors are created when these processes are initiated. The LiveUpdate Policy is set as: "Use the default management server". Any input or help would be greatly appreciated!
Dennis
Discussion Filed Under:
Comments
Event Source: Security
Event Category: Detailed Tracking
Event ID: 599
Date: 2/28/2008
Time: 8:39:26 AM
User: NT AUTHORITY\SYSTEM
Computer: DC1
Description:
Unprotection of auditable protected data.
Data Description: CValidateComCaller
Key Identifier: 921466af-0fa9-4321-8e94-eba34a0b7959
Protected Data Flags: 0x0
Protection Algorithms: 3DES-168 , SHA1-160
Failure Reason: 0xD
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Event Source: Security
Event Category: Detailed Tracking
Event ID: 599
Date: 2/28/2008
Time: 8:39:26 AM
User: NT AUTHORITY\SYSTEM
Computer: DC1
Description:
Unprotection of auditable protected data.
Data Description: CValidateComCaller
Key Identifier: 921466af-0fa9-4321-8e94-eba34a0b7959
Protected Data Flags: 0x0
Protection Algorithms: 3DES-168 , SHA1-160
Failure Reason: 0xD
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Event Source: Security
Event Category: Detailed Tracking
Event ID: 599
Date: 2/28/2008
Time: 8:57:10 AM
User: NT AUTHORITY\SYSTEM
Computer: DC1
Description:
Unprotection of auditable protected data.
Data Description: CValidateComCaller
Key Identifier: 921466af-0fa9-4321-8e94-eba34a0b7959
Protected Data Flags: 0x0
Protection Algorithms: 3DES-168 , SHA1-160
Failure Reason: 0xD
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Event Source: Security
Event Category: Detailed Tracking
Event ID: 599
Date: 2/28/2008
Time: 8:39:26 AM
User: NT AUTHORITY\SYSTEM
Computer: ********
Description:
Unprotection of auditable protected data.
Data Description: CValidateComCaller
Key Identifier: 921466af-0fa9-4321-8e94-eba34a0b7959
Protected Data Flags: 0x0
Protection Algorithms: 3DES-168 , SHA1-160
Failure Reason: 0xD
Audit account managemnet Success, Failure
Audit directory service access Success, Failure
Audit logon events Success, Failure
Audit object access Failure
Audit policy change Success
Audit privilege use Failure
Audit system events Sucess
I get this on just about all of our servers. If anyone has a solution please inform.
Thanks a lot!!
Dose anyone have a solution to this problem it is very annoying!!
Data Description: CValidateComCaller
Key Identifier: a8c17b82-1493-423c-946d-4243c28fb5c4
Protected Data Flags: 0x0
Protection Algorithms: 3DES-168 , SHA1-160
Failure Reason: 0xD
Nobody else gets these? I get about 1 per server per minute, its ridiculous.
Event Source: Security
Event Category: Detailed Tracking
Event ID: 599
Date: 5/13/2008
Time: 12:18:52 PM
User: NT AUTHORITY\SYSTEM
Computer: CWIC-SEP
Description:
Unprotection of auditable protected data.
Data Description: CValidateComCaller
Key Identifier: 2b20f10c-849f-40cb-a98a-fbb3364541cb
Protected Data Flags: 0x0
Protection Algorithms: 3DES-168 , SHA1-160
Failure Reason: 0xD
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Audit account managemnet Failure
Audit directory service access No auditing
Audit logon events Failure
Audit object access Failure
Audit policy change Failure
Audit privilege use Failure
Audit system events Failure
Greetings,
I talked to our backline team and was told to send you this link regarding the event id 599.
http://www.microsoft.com/products/ee/transform.aspx?ProdName=Windows%20Operating%20System&ProdVer=5.1.2600.0&EvtID=599&Evtsrc=Security&FileVer=5.1.2600.0&FileName=MsAuditE.dll&EvtType=Failure%20Audit&LCID=
It states that the message is for informational purposes only, and a suggested workaround is to disable auditing.
If you would like to continue working this issue I would have to push it further up the line but it could take some time.
Let me know what you would like to do and I will take the appropriate steps to get this moving.
If you have any additional questions simply respond to this email and I will get back to you as soon as possible.
Sincerely,
Gaelan
Greetings,
Sincerely,
Gaelan
Symantec Corporation
So it seems that they are now seeing what we are experiencing. It is amazing that more users are not seeing this. Maybe they are and they are not reviewing their logs! But this is on our DC's which security auditing is a necessity. On one of the servers that I was getting this error it did not have IIS.
I recently installed SEP 11.0.2 on a W2003 DC (that already had SEPM installed) and have started getting hundreds of Event 599 audit failures each day with message:
I tried setting the default pool to run as Local Service, but that did not solve the problem.
Has anyone found any other fixes for this?
Thanks.
Did anyone get a proper fix from Symantec for this issue yet? I'm getting alot of the errors on a standard Windows 2003 R2 server like this:
Event Type: Failure Audit
Event Source: Security
Event Category: Detailed Tracking
Event ID: 599
Date: 07-07-2008
Time: 10:16:38
User: NT AUTHORITY\SYSTEM
Computer: VDM33FS1
Description:
Unprotection of auditable protected data.
Data Description: CValidateComCaller
Key Identifier: e8132209-2acc-4da3-bf60-cb190f67fb04
Protected Data Flags: 0x0
Protection Algorithms: 3DES-168 , SHA1-160
Failure Reason: 0xD
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
The solution is to disable Audit Process Tacking (Failures). This is policy set either by a GPO or LGPO. I had this originally set to audit failed process on our domain controller for security reasons. But since Seclu.exe was causing this event id to register i disabled this on my default domain controller policy and I am no longer getting these event id 599. By default this policy is set to not defined. it is not necessary to have it enabled as long as you know what apps should be running on your server and by who should be running it. Hope that helps but at this time that was the only available solution from symantec.
Would you like to reply?
Login or Register to post your comment.