Windows Server 2012集群DTC启用WS-AT时URL注册权限错误问题
Windows Server 2012集群DTC配置WS-AT后启动报错问题
在一台Windows Server 2012设备上,我配置了本地DTC和集群DTC,如下图所示:
故障转移集群管理器中的集群DTC展示如下:
我通过如下命令为集群DTC启用了WS-AT:
wsatconfig -network:enable -endpointCert:7c6361568413852afb471d5f8b92604cdde530dd -accountsCerts:3bcf068b0b984d2af9d2efa03e8a489c8483ba11 -virtualServer:ftsappdev -restart
其中endpointCert参数填写的是集群角色ftsappdev对应的证书指纹,accountscerts参数填写的是JBOSS服务器的证书指纹。
我同时也通过组件服务的WS-AT选项卡完成了本地DTC的WS-AT配置:
在故障转移集群管理器中将集群DTC资源离线再上线后,事件查看器的应用日志中出现如下报错:
The MSDTC WS-AT protocol failed at the beginning of recovery. As a result, WS-AT functionality will be disabled. Protocol ID: c05b9cad-ab24-4bb3-9440-3548fa7b4b1b Protocol Name: WS-AtomicTransaction 1.1 Exception: Microsoft.Transactions.Bridge.PluggableProtocolException: A channel factory could not be opened. ---> Microsoft.Transactions.Wsat.Messaging.MessagingInitializationException: A channel factory could not be opened. ---> System.ServiceModel.AddressAccessDeniedException: HTTP could not register URL https://+:2372/WsatService/. Your process does not have access rights to this namespace (see http://go.microsoft.com/fwlink/?LinkId=70353 for details). ---> System.Net.HttpListenerException: Access is denied at System.Net.HttpListener.AddAllPrefixes() at System.Net.HttpListener.Start() at System.ServiceModel.Channels.SharedHttpTransportManager.OnOpen() --- End of inner exception stack trace --- at System.ServiceModel.Channels.SharedHttpTransportManager.OnOpen() at System.ServiceModel.Channels.TransportManager.Open(TransportChannelListener channelListener) at System.ServiceModel.Channels.TransportManagerContainer.Open(SelectTransportManagersCallback selectTransportManagerCallback) at System.ServiceModel.Channels.TransportChannelListener.OnOpen(TimeSpan timeout) at System.ServiceModel.Channels.HttpChannelListener`1.OnOpen(TimeSpan timeout) at System.ServiceModel.Channels.CommunicationObject.Open(TimeSpan timeout) at System.ServiceModel.Channels.LayeredChannelListener`1.OnOpen(TimeSpan timeout) at System.ServiceModel.Channels.CommunicationObject.Open(TimeSpan timeout) at System.ServiceModel.Channels.DatagramChannelDemuxer`2.OnOuterListenerOpen(ChannelDemuxerFilter filter, IChannelListener listener, TimeSpan timeout) at System.ServiceModel.Channels.SingletonChannelListener`3.OnOpen(TimeSpan timeout) at System.ServiceModel.Channels.CommunicationObject.Open(TimeSpan timeout) at System.ServiceModel.Channels.InternalDuplexChannelFactory.OnOpen(TimeSpan timeout) at System.ServiceModel.Channels.CommunicationObject.Open(TimeSpan timeout) at System.ServiceModel.Channels.ServiceChannelFactory.TypedServiceChannelFactory`1.OnOpen(TimeSpan timeout) at System.ServiceModel.Channels.CommunicationObject.Open(TimeSpan timeout) at System.ServiceModel.ChannelFactory.OnOpen(TimeSpan timeout) at System.ServiceModel.Channels.CommunicationObject.Open(TimeSpan timeout) at Microsoft.Transactions.Wsat.Messaging.CoordinationService.OpenChannelFactory[T](ChannelFactory`1 cf) --- End of inner exception stack trace --- at Microsoft.Transactions.Wsat.Messaging.CoordinationService.OpenChannelFactory[T](ChannelFactory`1 cf) at Microsoft.Transactions.Wsat.Messaging.CoordinationService.Initialize(CoordinationServiceConfiguration config) at Microsoft.Transactions.Wsat.Messaging.CoordinationService..ctor(CoordinationServiceConfiguration config, ProtocolVersion protocolVersion) at Microsoft.Transactions.Wsat.Protocol.ProtocolState.RecoveryBeginning() --- End of inner exception stack trace --- at Microsoft.Transactions.Wsat.Protocol.ProtocolState.RecoveryBeginning() at Microsoft.Transactions.Wsat.InputOutput.TransactionManagerReceive.RecoveryBeginning() Process Name: msdtc Process ID: 12248

在组件服务中重启本地DTC后,事件查看器应用日志中显示如下正常启动日志:
The WS-AT protocol service successfully completed startup and recovery. Protocol ID: cc228cf4-a9c8-43fc-8281-8565eb5889f2 Protocol Name: WS-AtomicTransaction 1.0 Process Name: msdtc Process ID: 7744

两个DTC均以Network Service用户身份运行:

我需要解决以下两个问题:
- 两个DTC均使用相同的Network Service用户运行,为什么集群DTC没有对应命名空间的访问权限,而本地DTC可以正常访问?
- 如何配置才能让集群DTC成功注册URL https://+:2372/WsatService/ ?
问题解答
问题1原因
Windows系统的HTTP.sys URL访问权限是独立配置的ACL规则,和进程运行用户没有直接的默认绑定关系:
- 你在组件服务中配置本地DTC的WS-AT时,系统会自动在HTTP.sys的ACL中添加Network Service对
https://+:2372/WsatService/的注册权限,所以本地DTC可以正常启动。 - 用wsatconfig命令带
-virtualServer参数配置集群DTC时,工具不会自动添加对应的URL ACL规则,哪怕集群DTC的运行身份也是Network Service,触发注册的时候没有匹配的权限条目,就会报访问拒绝错误。
问题2解决方法
按以下步骤操作即可:
- 登录集群的所有节点,以管理员身份运行命令提示符,执行如下命令添加URL ACL规则:
netsh http add urlacl url=https://+:2372/WsatService/ user="NT AUTHORITY\NETWORK SERVICE"
执行成功会返回URL reservation successfully added的提示。
2. 确认集群DTC绑定的证书私钥权限已经开放给Network Service账户。
3. 在故障转移集群管理器中,将集群DTC资源先离线,再重新上线即可。
内容的提问来源于stack exchange,提问作者Alex
相关产品推荐
相关产品推荐

