12-01-22 03:43 PM
Answered! Go to Answer.
19-01-22 07:29 PM
20-01-22 04:51 AM
20-01-22 06:30 AM
A follow-up regarding this matter, relating to the latest Microsoft Windows security update/patch for 'CVE-2022-21907,' which was released on January 11th, 2022.
Customers using Blue Prism with 'Windows Authentication' have reported that Blue Prism Interactive Clients/Runtimes are triggering an additional prompt for credentials; however, when these credentials are entered, it is resulting in the below error:
Blue Prism has released a solution/fix for this issue in the following KB article on our Support Portal:
We highly encourage that you speak to your IT team for assistance in applying this fix/solution, and that you first test this solution in a non-production environment.
The latest article update provides details about the issue, investigation and solution. Please also check the additional information in the article after solution section, including guidance for customers with complex environments.
21-01-22 06:36 AM
21-01-22 02:52 PM
Our IT Department has setup the SPN at the BP Application Server with Local System account.
But as soon as we installed KB5009543 (KB5009545 or KB5009546) on the BP Resources they started to not work.
So the Fix seems not to work.
21-01-22 03:01 PM
21-01-22 03:17 PM
We have the BP Service configured like the default, with the Local System account:
The Fix was applied with this command:
>Setspn -S HTTP/200000356-APP1.ptportugal-dev.local/BPServer 200000356-APP1
The SPN was registered:
>Setspn -L 200000356-APP1
Registered ServicePrincipalNames for CN=200000356-APP1,OU=CyberRPA,OU=LSB-PIC,OU=DC_PT,DC=ptportugal-dev,DC=local:
HTTP/200000356-APP1.ptportugal-dev.local/BPServer
But BP Resources or BP Clients with the Jan2022 Patches still do not work.
I will try with a dedicated service account.
Carlos Cabral
Security Analytics, Data Science and RPA Consultant
Altice Portugal
Cyber Security & Privacy (DCY)
Email: carlos-s-cabral@telecom.pt
Tlm: 966025853
Av. Fontes Pereira de Melo, 38/40
1069-300 LISBOA
meo.pt
AVISO DE CONFIDENCIALIDADE
Esta mensagem e quaisquer ficheiros anexos a ela contêm informação confidencial, propriedade da Altice Portugal e/ou das demais sociedades que com ela se encontrem em relação de domínio, Fundação Altice Portugal e ACS, destinando-se ao uso exclusivo do destinatário. Se não for o destinatário pretendido, não deve usar, distribuir, imprimir ou copiar este e-mail. Se recebeu esta mensagem por engano, por favor informe o emissor e elimine-a imediatamente.
Obrigado
Publico
26-01-22 12:45 PM
We have tried starting the BP Service with an domain account name, but still the FIX did not seem to work.
Since at the Application Server the executable binary is BPServerService.exe and not BPServer.exe should we replace the command:
Setspn -S HTTP/<server_fdqn>/BPServerService <accountname>
Instead of:
Setspn -S HTTP/<server_fdqn>/BPServer <accountname>
Or should we use the connection name "BPDCYPRD" in our case?
Carlos Cabral
Security Analytics, Data Science and RPA Consultant
Altice Portugal
Cyber Security & Privacy (DCY)
Email: carlos-s-cabral@telecom.pt
Tlm: 966025853
Av. Fontes Pereira de Melo, 38/40
1069-300 LISBOA
meo.pt
AVISO DE CONFIDENCIALIDADE
Esta mensagem e quaisquer ficheiros anexos a ela contêm informação confidencial, propriedade da Altice Portugal e/ou das demais sociedades que com ela se encontrem em relação de domínio, Fundação Altice Portugal e ACS, destinando-se ao uso exclusivo do destinatário. Se não for o destinatário pretendido, não deve usar, distribuir, imprimir ou copiar este e-mail. Se recebeu esta mensagem por engano, por favor informe o emissor e elimine-a imediatamente.
Obrigado
26-01-22 12:57 PM
26-01-22 01:04 PM