NetWorker:Active DirectoryユーザーがNetWorkerにログインできない、LDAPエラー コード49データ52f

Summary: Active Directoryユーザーは、NetWorkerおよびNMCにログインできません。「ユーザー名またはパスワードが正しくありません」というエラーが生成されます。

Acest articol se aplică pentru Acest articol nu se aplică pentru Acest articol nu este legat de un produs specific. Acest articol nu acoperă toate versiunile de produs existente.

Symptoms

Active Directoryユーザーは、NetWorkerコマンド ラインまたはユーザー インターフェイス(NetWorker管理コンソール、NetWorker Webユーザー インターフェイスなど)でログ認証を行うことはできません。
nsrlogin エラーを返します "incorrect username or password"; しかし、ユーザーのログオン名とパスワードは正しく入力されました。

この authc-server.log 次のメッセージがログに記録されました。

Unable to get user by name '<user name>'. Reason: Incorrect result size: expected 1, actual 0

Failed to bind as <Distinguished Name of the user> Users: org.springframework.ldap.AuthenticationException: [LDAP: error code 49 - 80090308: LdapErr: DSID-0C090434, comment: AcceptSecurityContext error, data 52f, v4f7c^@]; nested exception is javax.naming.AuthenticationException: [LDAP: error code 49 - 80090308: LdapErr: DSID-0C090434, comment: AcceptSecurityContext error, data 52f, v4f7c^@]
Linux: /nsr/authc/logs/authc-server.log
Windows: C:\Program Files\EMC NetWorker\nsr\authc-server\tomcat\logs\authc-server.log

NetWorkerで外部認証機関リソースを更新しようとすると、同じエラー メッセージが表示されます。

Cause

LDAP error code 49 は認証エラーを意味します。
LDAP data error code 52f は、アカウントの制限により、このユーザーのサインインが妨げられていることを意味します。
49 52f 1327 ERROR_ACCOUNT_RESTRICTION

このシナリオでは、NetWorker AUTHCをドメイン コントローラーにバインドするために使用されるADユーザー アカウントは、「Protected Users」ADグループに属していました。
 

Resolution

次のいずれかのアクションを実行します。

  • 保護されたユーザー グループからADユーザー アカウントを削除します。
  • Protected User Security Groupに含まれていない新しいADユーザー アカウントを作成します。新しいADユーザーは、NetWorkerユーザー ロールが付与されているADグループに追加する必要があります。
メモ: ADユーザーがProtected Usersグループに属していない場合は、ドメイン管理者に問い合わせてください。LDAPエラー49データ52fは、ドメイン コントローラーから返される制限付きアクセス エラー コードです。

Additional Information

次のAD PowerShellコマンドは、ユーザーが属するADグループを一覧表示します。 Get-ADPrincipalGroupMembership username | Select-Object Name

メモ: ここで、 username は、NetWorkerをActive Directoryにバインドするために使用されるユーザー アカウントです。このコマンドを実行するには、Active Directory PowerShellモジュールがインストールされている必要があります。これは、ドメイン コントローラーにデフォルトで含まれている必要があります。
PS C:\Users\Administrator> Get-ADPrincipalGroupMembership Administrator | Select-Object Name

Name
----
Domain Users
Administrators
Schema Admins
Enterprise Admins
Domain Admins
Group Policy Creator Owners
Protected Users
Organization Management
EMC App Agent Exchange Admin Roles

保護されたユーザー グループの詳細については、「https://learn.microsoft.com/en-us/windows-server/security/credentials-protection-and-management/protected-users-security-group 」を参照してください このハイパーリンクをクリックすると、デル・テクノロジーズ以外のWebサイトにアクセスします。

セキュリティを強化するために、LDAPではなくLDAPSを使用するようにNetWorkerを構成します。

Produse afectate

NetWorker

Produse

NetWorker Family
Proprietăți articol
Article Number: 000221735
Article Type: Solution
Ultima modificare: 11 Aug 2026
Version:  3
Găsiți răspunsuri la întrebările dvs. de la alți utilizatori Dell
Servicii de asistență
Verificați dacă dispozitivul dvs. este acoperit de serviciile de asistență.