0% found this document useful (0 votes)
209 views10 pages

Jason Trouble Shootying

The document provides error codes, reasons, and solutions for common issues seen when using WIN RC, ORA (Oracle Account), and CACPM tools. Some key errors include access denied due to missing local admin group, unknown user name or password, user not found on server, and password not meeting policy. Suggested solutions involve verifying accounts and permissions, resetting passwords, adding users, and checking network connectivity and firewall rules.

Uploaded by

ManideepVendra
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
209 views10 pages

Jason Trouble Shootying

The document provides error codes, reasons, and solutions for common issues seen when using WIN RC, ORA (Oracle Account), and CACPM tools. Some key errors include access denied due to missing local admin group, unknown user name or password, user not found on server, and password not meeting policy. Suggested solutions involve verifying accounts and permissions, resetting passwords, adding users, and checking network connectivity and firewall rules.

Uploaded by

ManideepVendra
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
You are on page 1/ 10

WIN Rc

Error Reason Solution


1. Raised incident to windows
Local admin group team and informed them to
was not found in add reconcile account on local
WIN RC=5 OS group admin group.
(Access Denied) 2. If not generate new password
& update in both OS &
CyberArk also.

WIN RC = 1326 Unknown user 1. Assign an incident to windows


(Unknown user name or bad password) name or bad team for password reset.
password 2. Check user name and
password and check does
account still exist or not?
WIN RC = 2102 User is not found in 1. Assign an incident to windows
(the work station driver is not installed) the server end team for either conforming or
creation of user account.
2. Once confirm by the windows
team perform change task.
WIN RC =2245 Password does not 1. Verify the password and
The password does not meet the match password change password to compile
password policy requirements. Check policy with cyberark password policy.
the minimum password length,
password complexity and password
history requirements
WIN RC=121 Possible network 1. If error persist further
Timeout period has expired. error on the target configuration need to verified
from member server by AD
team
WIN RC = 64 Can be a DNS error 1. Name is not available – is
The specified network name is no or address there a server with the same
longer available incorrect name?-IP may duplicate,
please check
2.
3.
4.

ORA (Oracle Account)

Error Reason Solution


ORA-12545 User Does not Exist(account has 1. Drop mail to DB team to
not yet been created at OS end) create account at OS
end
2. Update the password in
cyberark which is
provided by the DB
team.
ORA-28000 Account has been locked out at 1. Assign an incident to an
OS end Oracle DB team to reset
the password of
reconcile admin account
and unlock the account.
2. After resetting the
password update the
same in cyberark and
run change on that.

CACPM

Error Reason Solution


CACPM626E Account has been disabled at the 1. Check the CPM
(Account is disabled ) OS end status(account is active
or deactivate)
2. Assign incident to
windows team to enable
the account.
3. Initiate password
rotation.
Automatic management for this We were not able to add 1. Check the account
account was disabled by the reconcile account option in the onboarding correction
CPM windows account. 2. Delete the old file
category of the object
from safe end.
3. Add new file category
with correct details from
safe end.
4. Once it is added perform
reconcile task on the
account.
Unable to connect machine. Target server is not reachable to 1. The status of the server
Check machine address and port from CPM is retired or
code:8000 decommission then
check with the regional
windows team and
proceed accordingly
2. The server status is in
use then check the
password was last
successfully rotated
3. If the password rotated
ever by the CPM then
check with network
team and ask them why
the network connection
has been dropped
4. If the password is not
rotated from the time of
onboarding then check
the reachability on
specific port and rise a
firewall request.
1. Check whether the
server is work group or
member server
2. If it is work group verify
the password of the
account and if
verification is success
The user name or password is Mismatch of password in that means no error with
incorrect cyberark and at OS end. password.
3. If server is in domain
check whether the
reconcile account is
working or not and
perform reconciliation
on account else first
make the reconcile
account to work first.
Invalid prompt or did not Prompt while changing password 1. Login to CPM server
receive any prompt is not same as cyberark prompt check the log files to
make sure that it is not
following the prompt
define at cyberark end
while changing the
password
CACPM626E: account desables 1. Automatic management 1. First we have run the
for this account was reconcile task or change
disabled by the CPM task on account.
2. Reconciliation failed bcz 2. Again same error please
no reconcile account is check with AD team and
associated with the please enable the
account object. account.
CACPM072E: 1. Cannot connect to the 1. Please check access for
Login process on remote machine respective account to
machine failed the machine in remote
connection-access rights.
CACPM 243W This error when there is banner 1. Contact the concern
Fail to read from third party log length error team and ask them to
file/ check the banner
length .if any exits make
them to adjust the
banner length
2. Then try to rotate
password now.
3.

PSM

PSMSR606E Account configuration is not 1. Logon to cyberark search


(Error occurred while waiting correct. server unable to find for respective account
for dispatcher to communicate.) logon account which user is facing error
to login
2. Check logon domain or
logon to file category is
added for the account or
not. if not add the file
category .
3. Check with the user
once error will get
resolve
RDP connection is not 1. User system does not 1. Open cyberark web page
established have RDP rights and search for the
2. No connectivity from account.
cyberak PSM server 2. Check account is
3. Account used to access compliment or not.if it is
the server does not have in fail state please check
rights to access the the reason
server. 3. Logon to cyberark PSM
and check reachability
i.e for windows port 445
and linux port 22must be
used.
4. Logon to cyberark PSM
and check reachability
i.e windows port 3389
and for linux port 22
must be used.
5. Check the support
accounts which you are
using have access to that
sever or not
6. Raise firewall request or
contact respective
person who can raise it.
User could not open the session When installing PSM, the user 1. Please check RDC
was not connected as domain session host role config
administrator so the
PSMInitSession remote app
program was not added to the
published remote app program
list

ITAT

Error Reason Solution


ITATS004E Due to invalid password enter 1. Please drop a mail to
(authentication Failure) too many times. respect LDAP team.
1. Inform the user to clear
the browsing history and
ITACM040S Check whether user is typing cache files from his
(user was automatically logged right password or not browser.
off by VAULT) 2. Please drop a mail to
respective LDAP team to
reset the password.
1. PUAM team to check
account status and
ITATS006E Due to invalid password entered enable account if
(station is suspended for user) too many times required reset will be
sent to LDAP team.
2. Log in to Privaterark
client tools-
administration tools-
users and group – search
the user – click on
trusted area network –
click on activate button.

OTHERS

Error Reason Solution


Remote desktop cannot find the 1. Target server address is 1. Log in to cyberark search
computer ABC or XYZ wrong the account through
2. Target server address is which you are trying to
not getting resolved by login to server.
DNS server. 2. Check and confirm the
address which you are
entering while
connecting to server.
3. Login to the CyberArk
CPM and run the telnet
to confirm the
reachability. If not
reachable proceed to
next step 4.
4. Do the NSLOOKUP and
check the DNS entries
available. If no entries
available search that
server in SILVA tool and
use the IP Address
instead of Hostname.
5. If Error persists while
using the IP Address,
Raise a firewall request
or contact the respective
person.
Not able to copy the files from 1. Configuration missing 1. Login to CyberArk
CyberArk to Local drive attached 2. Account does not have webpage, search for the
with Laptop or Computer rights to access Drives account you are trying to
login.
2. Enter that you are
clicking on Map Local
drives option.
3. Click on Ok and try again
once, Error may get
resolved. If Error persists
proceed to steps 4.
4. Check and confirm that
the required permission
is in place to see the
drive and copy the files.

RDP Session is getting 1. Target server is not 1. Login to cyberark


disconnected immediately (500 accepting connection webpage , search for the
Internal Server Error) request. Could be due to account you are trying to
high utilization of target login
server. 2. Check the account is in
complaint state or not ,if
not please check the
error
3. Check the port
reachability from
cyberark CPM
4. Check the port
reachability from
cyberark PSM
5. If there is no reachabilty
from PSM as well raise a
fire wall request or
contact the respective
person.

Network Error: This error mainly occurs, when 1. Check the port
Connection Refused/Connection there is no port reachability from reachability from
Timeout cyberark PSM to target machine cyberark PSM
2. If there is no reachabilty
from PSM as well raise a
fire wall request or
contact the respective
person.
Buffer length error When ever you are trying to 1. Please check account
connect to the target server and logon to update or not.
you don’t connect to the target
server.

User account locked The referenced account is 1. Please check with AD


currently locked out and may not team, whether user
be logged on to account is locked or not.
2. If locked please request
for account unlock.
RDP session is getting 1. Please check the server
disconnected immediately complaint or not and
server is non complaint
2. Please check the server
reachability with port
number(windows
445/linux 22) from CPM
or PSM server
3. In case port is not
reachable, please raise
firewall request or check
with network team.
Change password process Time while connecting target 1. Check the firewall rules-
terminated possible DNS reason too
–check the port.

Account locked by user or CPM Not released by user after 1. Go to account details
completion of their work locked page in cyberark and
by CPM while changing the unlock the account so
account password that other user can use
the accounts
User unable receive OTP after Due to in correct emailID 1. Guide the user to reach
enter credentials updated in users profile or 2FA out to AD/windows team
error to make email address
correction in case of
emailed wrong, if else
check with 2FA team.
Authentication failure for user Due to invalid user name and 1. Check the user name
program will be closed password incorrect. and password of account
and please do correct
the details.

Cannot access the driver in the It seems to be a user permission 1. Guide the user to ask
target machine error on the target. We don’t target admins to provide
manage permissions on the the permission to access
target. the drive.

The network path was not The error occurse when the 1. We need the check port
found target server is not reachable on reachability from the
specific port. respective CPM by the
command telnet .
ex: telnet XYZ port
number(for windows
445/linux 22)

2. We have to check for


ping (whether the server
is reachable or not)
3. Check the adreess
details and ticketing tool
status
4. If any of the above two
connectivity error exists
we need to raise the fire
wall request for the
networking team.
Reconcile account is not set This error occurse when we run 1. Associate the correct
reconcile task without reconcile account to the
associating the reconcile account account then run
reconcile task
2. Run only change on
logon and Reconcile
account , for root
account run
reconciliation
3. For the work group
accounts there is no
reconcile account.
Running reconcile task
may casue above error
so run change task for
work group servers.

The specific network name is no This error occurs when DNS 1. Check whether the DNS
longer available entry cannot be resolved from entries or getting
CPM sever resolved or not using
command nslookup.
2. If DNS entries are not
resolved please ask
windows and network
team to check
3. Then initiate password
rotation again
4. And also finally check
whether the service
called SERVER is running
or not.
Remote desktop cannot connect This error may occur when there 1. Check the connectivity
is firewall or routing error (ping and telnet) from
the PSM server for the
server which you need
to connect
2. If connectivity reason
exists then raise a
firewall request and get
it resolved
3. There may be chances
for the same error if
there is nspaces in the
host name.to avoid
human error make sure
to enter without spaces
in address attribute.

You might also like