cancel
Showing results for 
Search instead for 
Did you mean: 

Crystal Enterprise 10 Login Error

Former Member
0 Kudos

Hi,

I am not sure if this is the correct forum to post this question but this is my problem:

Two of our admin users are having trouble logging into Crystal Enterprise 10. I've posted a message in service and support, but unfortunately, the SAP representative told me that the technical team is no longer support Enterprise 10. This is an alternative way to try here. Basically, two users just started getting this error since Wednesday. I checked the Crystal server, we have this group called "Crystal Other Domain" where we save all the NT users in this group. Once this ID is setup in Crystal Other Domain, the ID will automatically be populated in Crystal Enterprise. I will then add the ID to the appropriate group within Crystal Management Console so they can see the appropriate folders within the group. I even deleted the ID and added back, I removed all their groups, added everything back, but they still cannot login. I mean, the ID is in the Crystal Other Domain in Crystal server, and the ID is also in Enterprise with admin group, so I do not know what other route I should be looking into. On side note, we are using our WindowsNT password to sign on. 4 admins including myself have exactly the same group and our ids are all in the domain on the server, I do not understand why 2 of us can't get in. Please advise.

************************************************

Account Information Not Recognized

An internal error has occurred in the NT Authentication plugin while trying to establish group membership. Please make sure that each mapped NT group belongs to an accessible domain.

Please check that the appropriate CMS name and authentication type are specified.

Re-enter your user name and password, and click Log On.

If you are unsure of your account information, contact your system administrator

**************************************************

Thank you for the help in advance.

Simon

Accepted Solutions (1)

Accepted Solutions (1)

BasicTek
Advisor
Advisor
0 Kudos

Can you login to to client tools such as business views or Crystal reports?

I'm guessing that since you are on CE10 that your installation has been around a long time. The NT plugin which used to be fine when using windows 2000 mixed mode domains (NT 4 compatible) may be having trouble with newer AD versions. Do you know the domain and forest functional level of your AD domains or are the groups mapped in from direct servers (i.e.
servername\groupname\)?

I just handled an escalation where the NT plugin had trouble with all users from 1 domain in XIR2 (for unexplained reasons) and moving to the AD plugin resolved. Not saying you need to do that but it is a possibility since you cannot get support for CE10.

CMS traces and packet scanning can be helpful in situations but again it would be much easier with a support engineer to help. Any plans to upgrade to XR2 or XI 3.x?

Regards,

Tim

Former Member
0 Kudos

Hi Tim,

When they try to open Enterprise from Crystal Report, they are getting the same error. The groups are mapped in from direct servers (
servername\groupname). We are using Windows XP now and everyone is not having any problems logging in except for the two backup administrators. Their ID has been setup since the upgrade from 8.5 to 10.0. I have tried to create additional ID via Enterprise and it worked, so it has to be something within the NT group that is preventing them from logging in. I already checked with our IS department and they said their ID on the Crystal servers are fine and also in the active directory where all our NT IDs are stored. We are not attempting to change the plugin especially only 2 users out of 100 users who are being effected.

The domain we use is just company doman\ username, and we logged in using our NT password. Do you have any idea where we can look into before I give up and just create two additional NT IDs for them as a workaround?

We are planning to upgrade our system next year. We haven't set a date yet since we are working on a project right now.

Thanks for your help.

Simon

Edited by: Simon To on Nov 5, 2009 6:53 PM

BasicTek
Advisor
Advisor
0 Kudos

Well you can packet scan but I'll tell you from experience that troubleshooting an AD issue with the NT plugin is extremely difficult. In fact the NT plugin was never designed to allow login with AD users just local users from server (servername\username not domain\username) The NT plugin does not use the LDAP protocol that AD is based off of and instead uses something called SAML. When the CMS sends the request the OS then sends of a SAML request to the server. Whether this is occurring or not is difficult to spot in a packet scan but possible. CE only uses existing infrastructure, we do not cache anything in our system in regards to logging in so when it fails it's 99% of the time an AD/server issue As AD admins update their AD functional level and patches the odds of this continuing to work get less. While anything in CE 10 against newer AD is not guaranteed to work properly at least the AD plugin was designed for LDAP.

Regards,

Tim

Answers (0)