Cluster Service Won’t Start: “A Specified Authentication Package Is Unknown”

0
14
Asked By MellowCedar42 On

Our Exchange SE server is a Windows Server 2022 Standard VM running on ESXi. After the server was updated overnight, the Cluster Service would no longer start. Event ID 7024 reports: "The Cluster Service service terminated with the following service-specific error: A specified authentication package is unknown." The cluster log also shows: "Service CreateNodeThread Failed, (80090305) because of Loading of security package failed."

A reboot did not help, temporarily disabling antivirus made no difference, and uninstalling the suspected .NET cumulative update also did not resolve the problem. Cluster validation reports that the configuration is healthy. The server uses SentinelOne rather than Falcon Sensor.

This is an Exchange DAG member, and Microsoft is currently investigating it under a Severity A support case. Has anyone encountered this particular authentication-package or security-package loading failure, or found another cause beyond the usual AllowCustomSSPsAPs policy setting?

3 Answers

Answered By QuietHarbor31 On

I have not run into this exact failure, but the timing may indicate a policy or security-hardening change that became active after the reboot rather than the .NET package itself. Check the effective computer policies and system event logs around the first failed Cluster Service start. I would also keep Microsoft involved before changing authentication or LSASS protections on an Exchange server, because a workaround could introduce a larger security or DAG stability problem.

Answered By PacketPioneer7 On

This error pattern can occur when ClusSvc cannot load CLUSAUTHMGR.DLL, which Failover Clustering needs for its authentication handling. One thing worth checking is whether this policy value exists and is set to zero: HKLMSOFTWAREPoliciesMicrosoftWindowsSystemAllowCustomSSPsAPs. You can inspect it with Get-ItemProperty or reg query. Also generate a gpresult report to confirm whether the value is coming from a security baseline or another applied policy. If the setting changed around the same time as the reboot, removing the .NET update would not necessarily undo it. Since this is an Exchange DAG node and Microsoft is already handling a Sev A case, I would avoid changing LSASS-related security settings without their guidance, but provide the engineer with the registry value and resultant policy.

MellowCedar42 -

Thanks, but I already checked that setting. We do not have the policy to allow custom SSPs and APs to be loaded into LSASS enabled through Group Policy.

Answered By BlueMaple88 On

The 80090305 status and “loading of security package failed” message point more toward a security-package or LSASS loading problem than a normal cluster configuration issue. I would compare the affected node with a healthy DAG member, including the relevant registry policy settings, security-baseline application, recent servicing changes, and any endpoint-security events. Since antivirus has already been disabled and validation is clean, the comparison data and the exact CLUSAUTHMGR.DLL load failure should be useful evidence for the Microsoft case.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.