Cluster Service Won’t Start: “A Specified Authentication Package Is Unknown”

0
0
Asked By MellowJuniper42 On

Our Exchange SE server is a Windows Server 2022 Standard virtual machine running on ESXi. After it was updated overnight, the Cluster Service stopped starting the next morning and now fails with Event ID 7024: "The Cluster Service service terminated with the following service-specific error: A specified authentication package is unknown."

Rebooting the VM and temporarily disabling antivirus did not help. I also removed the recent .NET cumulative update, but the problem remained. Cluster validation reports the environment as healthy.

The cluster log contains this entry:

00001434.00003b78::2026/10/01-08:07:53.134 WARN [CS] Service CreateNodeThread Failed, (80090305) because of "Loading of security package failed"

The server uses SentinelOne rather than Falcon. I'm currently working with Microsoft on a Sev A support case. Has anyone dealt with this particular authentication-package error when starting the Cluster Service?

1 Answer

Answered By PatchworkOrchid7 On

This pattern can happen when the Cluster Service cannot load CLUSAUTHMGR.DLL, which it needs for its authentication package. One thing worth checking is whether this policy exists and what value it has:

HKLMSOFTWAREPoliciesMicrosoftWindowsSystemAllowCustomSSPsAPs

You can query it with:

Get-ItemProperty "HKLM:SOFTWAREPoliciesMicrosoftWindowsSystem" -Name AllowCustomSSPsAPs -ErrorAction SilentlyContinue

A value of 0 means custom security support providers and authentication packages are blocked from loading into LSASS. That has been associated with Event 7024 and Cluster Service startup failures. Also check the resulting Group Policy with `gpresult /h C:Tempgpresult.html`, since uninstalling a .NET update would not undo a security policy that became effective after the reboot.

Since this is an Exchange DAG member and Microsoft is already handling a Sev A case, I would avoid changing LSASS-related settings without their direction. However, providing the registry value and resultant policy to the Microsoft engineer should help narrow down whether CLUSAUTHMGR.DLL is being blocked.

MellowJuniper42 -

Thanks. I checked that setting already, and we don’t have the “Allow Custom SSPs and APs to be loaded into LSASS” policy enabled through Group Policy.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.