Cryptographic Services failed while processing the OnIdentity() call

Anonymous
2013-11-09T16:45:39+00:00

Since UPGARDING to Windows 8.1 on October 17, 2013 have been getting the following error

Log Name:      Application

Source:        Microsoft-Windows-CAPI2

Date:          11/09/13 10:19:48 AM

Event ID:      513

Task Category: None

Level:         Error

Keywords:      Classic

User:          N/A

Computer:      Michael-HP

Description:

Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.

Details:

AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.

System Error:

Access is denied.

.

Event Xml:

<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">

  <System>

    <Provider Name="Microsoft-Windows-CAPI2" Guid="{5bbca4a8-b209-48dc-a8c7-b23d3e5216fb}" EventSourceName="Microsoft-Windows-CAPI2" />

    <EventID Qualifiers="0">513</EventID>

    <Version>0</Version>

    <Level>2</Level>

    <Task>0</Task>

    <Opcode>0</Opcode>

    <Keywords>0x8080000000000000</Keywords>

    <TimeCreated SystemTime="2013-11-09T15:19:48.537403000Z" />

    <EventRecordID>54879</EventRecordID>

    <Correlation />

    <Execution ProcessID="1164" ThreadID="4752" />

    <Channel>Application</Channel>

    <Computer>Michael-HP</Computer>

    <Security />

  </System>

  <EventData>

    <Data>

Details:

AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.

System Error:

Access is denied.

</Data>

  </EventData>

</Event>

Saw a similar thread Since upgrading Windows backup fails at http://answers.microsoft.com/en-us/windows/forum/windows8_1-system/since-upgrading-windows-backup-fails-cryptographic/aee23306-09df-4182-a549-da1084e20513 and followed the advice there and didn't have issues. There was a link to EventID 513 Capi2 error at http://social.technet.microsoft.com/Forums/windows/en-US/14abbc90-cab5-4fc6-953a-96c1929f9a7b/eventid-513-capi2-error?forum=itprovistasp which goes back to 2009 slightly before Windows 8.1. In any event this article (which I only glanced at) suggest checking 1409 files for errors.

Is this problem another of the newly introduced Windows 8.1 bugs or ishere a solution that can be applied? Thanks.

Windows for home | Previous Windows versions | Devices and drivers

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2014-01-23T22:34:19+00:00

Hope I can help to someone.

I had the same issue with the fresh Windows 8.1 Pro.

Couldn't find answer so had to debug Windows to find a solution.

"Microsoft Link-Layer Discovery Protocol" binary is \Windows\system32\DRIVERS\mslldp.sys

Its config registry key is HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MsLldp

During backup a VSS process running under NETWORK_SERVICE account calls cryptcatsvc!CSystemWriter::AddLegacyDriverFiles(), which enumerates all the drivers records in Service Control Manager database and tries opening each one of them. , The function fails on MSLLDP record with "Access Denied" error.

Turned out it fails because MSLLDP driver's security permissions do not allow NETWORK_SERVICE to access the driver record.

The binary security descriptor for the record is located here:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MsLldp\Security

It should be modified, I used SC.EXE and Sysinternals' ACCESSCHK.EXE to fix it.

The original security descriptor looked like below:

>accesschk.exe -c mslldp

mslldp

  RW NT AUTHORITY\SYSTEM

  RW BUILTIN\Administrators

  RW S-1-5-32-549       <- these are server operators

  R  NT SERVICE\NlaSvc

No service account is allowed to access MSLLDP driver

The security descriptor for the drivers that were processed successfully looked this way:

>accesschk.exe -c mup

mup

  RW NT AUTHORITY\SYSTEM

  RW BUILTIN\Administrators

  R  NT AUTHORITY\INTERACTIVE

  R  NT AUTHORITY\SERVICE  <- this gives access to services

How to add access rights for NT AUTHORITY\SERVICE to MSLLDP service:

  1. Run: SC sdshow MSLLDP

You'll get something like below (SDDL language is documented on MSDN):

D:(D;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BG)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;CCDCLCSWRPDTLOCRSDRCWDWO;;;BA)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SO)(A;;LCRPWP;;;S-1-5-80-3141615172-2057878085-1754447212-2405740020-3916490453)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)

  1. Run: SC sdshow MUP

You'll get:

D:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)

  1. Take NT AUTHORITY\ SERVICE entry, which is (A;;CCLCSWLOCRRC;;;SU) and add it to the original MSLLDP security descriptor properly, right before the last S:(AU... group.
  2. Apply the new security descriptor to MSLLDP service :

sc sdset MSLLDP D:(D;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BG)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;CCDCLCSWRPDTLOCRSDRCWDWO;;;BA)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SO)(A;;LCRPWP;;;S-1-5-80-3141615172-2057878085-1754447212-2405740020-3916490453)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)

  1. Check the result:

>accesschk.exe -c mslldp

mslldp

  RW NT AUTHORITY\SYSTEM

  RW BUILTIN\Administrators

  RW S-1-5-32-549

  R  NT SERVICE\NlaSvc

  R  NT AUTHORITY\SERVICE

  1. Run you backup app, the error is gone for my Home Server backup.

!!! Do not forget to use your security descriptor for MSLLDP driver since I guess there can be some rare cases when its different for your machine. Do not copy my SDDL descriptions, just in case. And backup the old descriptor just in case !!!

I don't know what reason MS had behind all this, probably some security concerns or probably this is just a bug. Definitely not a security problem in my environment.

Good luck!

Was this answer helpful?

200+ people found this answer helpful.
0 comments No comments

225 additional answers

Sort by: Oldest
  1. Anonymous
    2016-02-23T14:32:21+00:00

    Well applied the fix and while no Cryptographic Services failed error when I create a Restore Point I now get two other Warning/Errors.

    * WARNING: VSS EVENT 8229

    A VSS writer has rejected an event with error 0x800423f2, The writer's timeout expired between the Freeze and Thaw events. Changes that the writer made to the writer components while handling the event will not be available to the requester. Check the event log for related events from the application hosting the VSS writer.

    * ERROR: SPP EVENT 16389 {Note, this occurs six instances...here are all six descriptions)

    Writer MSSearch Service Writer experienced retryable error during shadow copy creation. Retrying

    Writer COM+ REGDB Writer experienced retryable error during shadow copy creation. Retrying

    Writer Registry Writer experienced retryable error during shadow copy creation. Retrying

    Writer WMI Writer experienced retryable error during shadow copy creation. Retrying

    Writer Shadow Copy Optimization Writer experienced retryable error during shadow copy creation. Retrying

    Writer System Writer experienced retryable error during shadow copy creation. Retrying

    I ran the Create System Restore point and it ran instead of 20-30 seconds for almost a minute+.

    The restore point shows in the restore table as well as in CCLeaner that shows these points.

    However, I am now suspect about whether I helped or hurt with this new effort.

    I will run A Macrium backup image and see what Event Viewer says.

    I assume I can revert/remove the (A;;CC;;;S-1-5-80-242729624-280608522-2219052887-3187409060-2225943459)?

    If so, do I just use....

    sc sdset MSLLDP D**:**(D;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BG)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;CCDCLCSWRPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SO)(A;;LCRPWP;;;S-1-5-80-3141615172-2057878085-1754447212-2405740020-3916490453)

    UPDATE

    I rebooted PC and re-ran Create System Restore Point.

    Seemed to create quickly....checked Event Viewer and no warnings or errors.

    I rebooted and created several points.....no errors.

    I will now create a disk image using Macrium and report back.

    I did recheck using accesschk.exe -v -c mslldp

    .....and still shows..........

    R  NT SERVICE\CryptSvc

    SERVICE_QUERY_CONFIG


    MORE UPDATE

    Ok.....I performed a Macrium Reflect disk image to offline USB HDD.

    I had no Event Errors of any type.

    I also created several more restore points and no errors.......ran MUCH quicker than first time that had errors.

    I'll have to do some research on what the Warning & Errors I posted mean but it appears either a reboot or having run things once eliminated them for additional runs. 

    I'll see how my daily restore point and nightly Macrium imaging goes for the next few days and report back.

    I'll also keep eye on new O/S update and if this gets reset.

    Any experts who want to comment in are most welcome.

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2016-02-27T13:49:24+00:00

    Well, it has been a several days of daily restore point creation & nightly Macrium Reflect imaging backups.

    No errors in Event Viewer and so far no random lockup at that same time......granted this only happened perhaps one in 20+ restore creation / backup attempts.

    I will continue to monitor and also see what happens on next MS O/S build update.

    I'll see as others posted if "fix" needs to be re-applied.

    Not sure if this fix is bulletproof but for me I would say it is "safe" to use.

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2016-02-27T14:43:12+00:00

    When trying to run step 3, I get a message "device not ready" and the change doesn't happen.  Is there something else that I should be doing.  Am already running command prompt as administrator.

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2016-02-28T20:16:44+00:00

    Step 3? The "sc sdset (etc.)" line?

    Are you sure you copied and pasted the command as one line? Put the command in Notepad first. Click the "Format" menu and uncheck "Word Wrap".

    Was this answer helpful?

    0 comments No comments