You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Windows Server 2012集群DTC启用WS-AT时URL注册权限错误问题

Windows Server 2012集群DTC配置WS-AT后启动报错问题

在一台Windows Server 2012设备上,我配置了本地DTC和集群DTC,如下图所示:
组件服务界面显示本地和集群DTC

故障转移集群管理器中的集群DTC展示如下:
故障转移集群管理器显示DTC资源

我通过如下命令为集群DTC启用了WS-AT:

wsatconfig -network:enable -endpointCert:7c6361568413852afb471d5f8b92604cdde530dd -accountsCerts:3bcf068b0b984d2af9d2efa03e8a489c8483ba11 -virtualServer:ftsappdev -restart

其中endpointCert参数填写的是集群角色ftsappdev对应的证书指纹,accountscerts参数填写的是JBOSS服务器的证书指纹。

我同时也通过组件服务的WS-AT选项卡完成了本地DTC的WS-AT配置:
组件服务DTC节点WS-AT选项卡

在故障转移集群管理器中将集群DTC资源离线再上线后,事件查看器的应用日志中出现如下报错:

The MSDTC WS-AT protocol failed at the beginning of recovery. As a result, WS-AT functionality will be disabled.
 Protocol ID: c05b9cad-ab24-4bb3-9440-3548fa7b4b1b
 Protocol Name: WS-AtomicTransaction 1.1
 Exception: Microsoft.Transactions.Bridge.PluggableProtocolException: A channel factory could not be opened. ---> Microsoft.Transactions.Wsat.Messaging.MessagingInitializationException: A channel factory could not be opened. ---> System.ServiceModel.AddressAccessDeniedException: HTTP could not register URL https://+:2372/WsatService/. Your process does not have access rights to this namespace (see http://go.microsoft.com/fwlink/?LinkId=70353 for details). ---> System.Net.HttpListenerException: Access is denied
   at System.Net.HttpListener.AddAllPrefixes()
   at System.Net.HttpListener.Start()
   at System.ServiceModel.Channels.SharedHttpTransportManager.OnOpen()
   --- End of inner exception stack trace ---
   at System.ServiceModel.Channels.SharedHttpTransportManager.OnOpen()
   at System.ServiceModel.Channels.TransportManager.Open(TransportChannelListener channelListener)
   at System.ServiceModel.Channels.TransportManagerContainer.Open(SelectTransportManagersCallback selectTransportManagerCallback)
   at System.ServiceModel.Channels.TransportChannelListener.OnOpen(TimeSpan timeout)
   at System.ServiceModel.Channels.HttpChannelListener`1.OnOpen(TimeSpan timeout)
   at System.ServiceModel.Channels.CommunicationObject.Open(TimeSpan timeout)
   at System.ServiceModel.Channels.LayeredChannelListener`1.OnOpen(TimeSpan timeout)
   at System.ServiceModel.Channels.CommunicationObject.Open(TimeSpan timeout)
   at System.ServiceModel.Channels.DatagramChannelDemuxer`2.OnOuterListenerOpen(ChannelDemuxerFilter filter, IChannelListener listener, TimeSpan timeout)
   at System.ServiceModel.Channels.SingletonChannelListener`3.OnOpen(TimeSpan timeout)
   at System.ServiceModel.Channels.CommunicationObject.Open(TimeSpan timeout)
   at System.ServiceModel.Channels.InternalDuplexChannelFactory.OnOpen(TimeSpan timeout)
   at System.ServiceModel.Channels.CommunicationObject.Open(TimeSpan timeout)
   at System.ServiceModel.Channels.ServiceChannelFactory.TypedServiceChannelFactory`1.OnOpen(TimeSpan timeout)
   at System.ServiceModel.Channels.CommunicationObject.Open(TimeSpan timeout)
   at System.ServiceModel.ChannelFactory.OnOpen(TimeSpan timeout)
   at System.ServiceModel.Channels.CommunicationObject.Open(TimeSpan timeout)
   at Microsoft.Transactions.Wsat.Messaging.CoordinationService.OpenChannelFactory[T](ChannelFactory`1 cf)
   --- End of inner exception stack trace ---
   at Microsoft.Transactions.Wsat.Messaging.CoordinationService.OpenChannelFactory[T](ChannelFactory`1 cf)
   at Microsoft.Transactions.Wsat.Messaging.CoordinationService.Initialize(CoordinationServiceConfiguration config)
   at Microsoft.Transactions.Wsat.Messaging.CoordinationService..ctor(CoordinationServiceConfiguration config, ProtocolVersion protocolVersion)
   at Microsoft.Transactions.Wsat.Protocol.ProtocolState.RecoveryBeginning()
   --- End of inner exception stack trace ---
   at Microsoft.Transactions.Wsat.Protocol.ProtocolState.RecoveryBeginning()
   at Microsoft.Transactions.Wsat.InputOutput.TransactionManagerReceive.RecoveryBeginning()
 Process Name: msdtc
 Process ID: 12248

事件查看器显示集群DTC重启时的报错条目

在组件服务中重启本地DTC后,事件查看器应用日志中显示如下正常启动日志:

The WS-AT protocol service successfully completed startup and recovery.
 Protocol ID: cc228cf4-a9c8-43fc-8281-8565eb5889f2
 Protocol Name: WS-AtomicTransaction 1.0
 Process Name: msdtc
 Process ID: 7744

事件查看器显示本地DTC重启时的正常条目

两个DTC均以Network Service用户身份运行:
组件服务的服务节点显示DTC服务信息
任务管理器显示MSDTC进程信息

我需要解决以下两个问题:

  1. 两个DTC均使用相同的Network Service用户运行,为什么集群DTC没有对应命名空间的访问权限,而本地DTC可以正常访问?
  2. 如何配置才能让集群DTC成功注册URL https://+:2372/WsatService/ ?

问题解答

问题1原因

Windows系统的HTTP.sys URL访问权限是独立配置的ACL规则,和进程运行用户没有直接的默认绑定关系:

  • 你在组件服务中配置本地DTC的WS-AT时,系统会自动在HTTP.sys的ACL中添加Network Service对https://+:2372/WsatService/的注册权限,所以本地DTC可以正常启动。
  • 用wsatconfig命令带-virtualServer参数配置集群DTC时,工具不会自动添加对应的URL ACL规则,哪怕集群DTC的运行身份也是Network Service,触发注册的时候没有匹配的权限条目,就会报访问拒绝错误。

问题2解决方法

按以下步骤操作即可:

  1. 登录集群的所有节点,以管理员身份运行命令提示符,执行如下命令添加URL ACL规则:
netsh http add urlacl url=https://+:2372/WsatService/ user="NT AUTHORITY\NETWORK SERVICE"

执行成功会返回URL reservation successfully added的提示。
2. 确认集群DTC绑定的证书私钥权限已经开放给Network Service账户。
3. 在故障转移集群管理器中,将集群DTC资源先离线,再重新上线即可。


内容的提问来源于stack exchange,提问作者Alex

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.27 09:45:04