Cryptographic Services failed while processing the OnIdentity() call

Anonymous
2013-11-09T16:45:39+00:00

Since UPGARDING to Windows 8.1 on October 17, 2013 have been getting the following error

Log Name:      Application

Source:        Microsoft-Windows-CAPI2

Date:          11/09/13 10:19:48 AM

Event ID:      513

Task Category: None

Level:         Error

Keywords:      Classic

User:          N/A

Computer:      Michael-HP

Description:

Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.

Details:

AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.

System Error:

Access is denied.

.

Event Xml:

<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">

  <System>

    <Provider Name="Microsoft-Windows-CAPI2" Guid="{5bbca4a8-b209-48dc-a8c7-b23d3e5216fb}" EventSourceName="Microsoft-Windows-CAPI2" />

    <EventID Qualifiers="0">513</EventID>

    <Version>0</Version>

    <Level>2</Level>

    <Task>0</Task>

    <Opcode>0</Opcode>

    <Keywords>0x8080000000000000</Keywords>

    <TimeCreated SystemTime="2013-11-09T15:19:48.537403000Z" />

    <EventRecordID>54879</EventRecordID>

    <Correlation />

    <Execution ProcessID="1164" ThreadID="4752" />

    <Channel>Application</Channel>

    <Computer>Michael-HP</Computer>

    <Security />

  </System>

  <EventData>

    <Data>

Details:

AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.

System Error:

Access is denied.

</Data>

  </EventData>

</Event>

Saw a similar thread Since upgrading Windows backup fails at http://answers.microsoft.com/en-us/windows/forum/windows8_1-system/since-upgrading-windows-backup-fails-cryptographic/aee23306-09df-4182-a549-da1084e20513 and followed the advice there and didn't have issues. There was a link to EventID 513 Capi2 error at http://social.technet.microsoft.com/Forums/windows/en-US/14abbc90-cab5-4fc6-953a-96c1929f9a7b/eventid-513-capi2-error?forum=itprovistasp which goes back to 2009 slightly before Windows 8.1. In any event this article (which I only glanced at) suggest checking 1409 files for errors.

Is this problem another of the newly introduced Windows 8.1 bugs or ishere a solution that can be applied? Thanks.

Windows for home | Previous Windows versions | Devices and drivers

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2014-01-23T22:34:19+00:00

Hope I can help to someone.

I had the same issue with the fresh Windows 8.1 Pro.

Couldn't find answer so had to debug Windows to find a solution.

"Microsoft Link-Layer Discovery Protocol" binary is \Windows\system32\DRIVERS\mslldp.sys

Its config registry key is HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MsLldp

During backup a VSS process running under NETWORK_SERVICE account calls cryptcatsvc!CSystemWriter::AddLegacyDriverFiles(), which enumerates all the drivers records in Service Control Manager database and tries opening each one of them. , The function fails on MSLLDP record with "Access Denied" error.

Turned out it fails because MSLLDP driver's security permissions do not allow NETWORK_SERVICE to access the driver record.

The binary security descriptor for the record is located here:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MsLldp\Security

It should be modified, I used SC.EXE and Sysinternals' ACCESSCHK.EXE to fix it.

The original security descriptor looked like below:

>accesschk.exe -c mslldp

mslldp

  RW NT AUTHORITY\SYSTEM

  RW BUILTIN\Administrators

  RW S-1-5-32-549       <- these are server operators

  R  NT SERVICE\NlaSvc

No service account is allowed to access MSLLDP driver

The security descriptor for the drivers that were processed successfully looked this way:

>accesschk.exe -c mup

mup

  RW NT AUTHORITY\SYSTEM

  RW BUILTIN\Administrators

  R  NT AUTHORITY\INTERACTIVE

  R  NT AUTHORITY\SERVICE  <- this gives access to services

How to add access rights for NT AUTHORITY\SERVICE to MSLLDP service:

  1. Run: SC sdshow MSLLDP

You'll get something like below (SDDL language is documented on MSDN):

D:(D;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BG)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;CCDCLCSWRPDTLOCRSDRCWDWO;;;BA)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SO)(A;;LCRPWP;;;S-1-5-80-3141615172-2057878085-1754447212-2405740020-3916490453)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)

  1. Run: SC sdshow MUP

You'll get:

D:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)

  1. Take NT AUTHORITY\ SERVICE entry, which is (A;;CCLCSWLOCRRC;;;SU) and add it to the original MSLLDP security descriptor properly, right before the last S:(AU... group.
  2. Apply the new security descriptor to MSLLDP service :

sc sdset MSLLDP D:(D;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BG)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;CCDCLCSWRPDTLOCRSDRCWDWO;;;BA)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SO)(A;;LCRPWP;;;S-1-5-80-3141615172-2057878085-1754447212-2405740020-3916490453)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)

  1. Check the result:

>accesschk.exe -c mslldp

mslldp

  RW NT AUTHORITY\SYSTEM

  RW BUILTIN\Administrators

  RW S-1-5-32-549

  R  NT SERVICE\NlaSvc

  R  NT AUTHORITY\SERVICE

  1. Run you backup app, the error is gone for my Home Server backup.

!!! Do not forget to use your security descriptor for MSLLDP driver since I guess there can be some rare cases when its different for your machine. Do not copy my SDDL descriptions, just in case. And backup the old descriptor just in case !!!

I don't know what reason MS had behind all this, probably some security concerns or probably this is just a bug. Definitely not a security problem in my environment.

Good luck!

Was this answer helpful?

200+ people found this answer helpful.
0 comments No comments

225 additional answers

Sort by: Oldest
  1. Anonymous
    2016-12-10T03:59:29+00:00

    It is a 513 error, and the User is N/A, but the Details and System Error are different:

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2016-12-10T04:56:56+00:00

    A few threads do pop up on search for "0xc0000039 (unresolvable)". Has that computer lost its System Writer? Enter "vssadmin list writers" at a Command Prompt (Admin) to see whether it is listed...

    If not listed or it shows an error, then see...

    https://social.technet.microsoft.com/Forums/windowsserver/en-US/9803e91a-4bc4-4ebe-8a40-cb392f494b41/cryptographic-services-failed-while-processing-the-onidentity-call-in-the-system-writer-objec?forum=windowsbackup

    Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object

    It looks safe to do as MedicalS (MSFT CFG) says in there, as my EVENTSYSTEM matches what he says...

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2016-12-10T12:15:18+00:00

    Thanks for that thought and the reference.

    Yes, SystemWriter is missing from my list:

    (Edited) Writer List

    Writer name: 'Task Scheduler Writer'

    Writer name: 'VSS Metadata Store Writer'

    Writer name: 'Performance Counters Writer'

    Writer name: 'Shadow Copy Optimization Writer'

    Writer name: 'SqlServerWriter'

    Writer name: 'ASR Writer'

    Writer name: 'WMI Writer'

    Writer name: 'IIS Config Writer'

    Writer name: 'Registry Writer'

    Writer name: 'MSSearch Service Writer'

    Writer name: 'MSMQ Writer (MSMQ)'

    Writer name: 'COM+ REGDB Writer'

    But my permissions list from SDSHOW are identical to those of MedicalS.  In other words,

    (A;;CCLCSWLOCRRC;;;SU)

    is present in mine.  And I've both restarted cryptographic services, and also rebooted.

    Time to research further, unless you have other ideas.

    Ron

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2016-12-10T22:32:26+00:00

    (1) I see you posted into that MedicalS thread. Good move.

    Now, reading that thread more closely, I think you are right, what MedicalS posted just grants permissions to the "eventsystem" - it doesn't replace a missing System Writer. (Yet, he knows it's missing ??? Can it be it really is unneeded?).

    I'll BING for how to get it back - since SFC was no help & DISM too likely will fail.

    (2) And I see you ran "SFC /ScanNow".

    It is a real sin that SFC was no cure - the darned thing is supposed to repair/replace system files! I have little/no faith that the DISM command will do it, either...

    "DISM /Online /Cleanup-Image /RestoreHealth".

    (3) You appear also to be missing the BITS Writer...

    (4) Does any noticeable symptom in the computer accompany the CAPI2 error - for instance, does a backup operation fail with an error message outside the Event Viewer? If not - I'd still rather be rid of it - but probably the error itself is harmless/bogus. EXCEPT, I don't like that the System & Bits Writers are actually missing.

    (5) I see you tried it in a clean boot & it was the same. That proves it isn't a 3rd-party app at fault.

    Edit 12/10/16: I've found an article that promises to restore the System Writer...

    https://support.microsoft.com/en-us/kb/2009272

    System State backup using Windows Server Backup fails with error: System writer is not found in the backup

    (1) You will need to have the DOS command "icacls" to do this. I'm not sure whether it comes with Win 10, or I downloaded it separately. Try "icacls /?" at a Prompt to see whether you've got it. The steps do seem safe & doable otherwise.

    (2) My registry key matches what the article says. So, that's got to be safe enough...

    Was this answer helpful?

    0 comments No comments