Cryptographic Services failed while processing the OnIdentity() call

Anonymous
2013-11-09T16:45:39+00:00

Since UPGARDING to Windows 8.1 on October 17, 2013 have been getting the following error

Log Name:      Application

Source:        Microsoft-Windows-CAPI2

Date:          11/09/13 10:19:48 AM

Event ID:      513

Task Category: None

Level:         Error

Keywords:      Classic

User:          N/A

Computer:      Michael-HP

Description:

Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.

Details:

AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.

System Error:

Access is denied.

.

Event Xml:

<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">

  <System>

    <Provider Name="Microsoft-Windows-CAPI2" Guid="{5bbca4a8-b209-48dc-a8c7-b23d3e5216fb}" EventSourceName="Microsoft-Windows-CAPI2" />

    <EventID Qualifiers="0">513</EventID>

    <Version>0</Version>

    <Level>2</Level>

    <Task>0</Task>

    <Opcode>0</Opcode>

    <Keywords>0x8080000000000000</Keywords>

    <TimeCreated SystemTime="2013-11-09T15:19:48.537403000Z" />

    <EventRecordID>54879</EventRecordID>

    <Correlation />

    <Execution ProcessID="1164" ThreadID="4752" />

    <Channel>Application</Channel>

    <Computer>Michael-HP</Computer>

    <Security />

  </System>

  <EventData>

    <Data>

Details:

AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.

System Error:

Access is denied.

</Data>

  </EventData>

</Event>

Saw a similar thread Since upgrading Windows backup fails at http://answers.microsoft.com/en-us/windows/forum/windows8_1-system/since-upgrading-windows-backup-fails-cryptographic/aee23306-09df-4182-a549-da1084e20513 and followed the advice there and didn't have issues. There was a link to EventID 513 Capi2 error at http://social.technet.microsoft.com/Forums/windows/en-US/14abbc90-cab5-4fc6-953a-96c1929f9a7b/eventid-513-capi2-error?forum=itprovistasp which goes back to 2009 slightly before Windows 8.1. In any event this article (which I only glanced at) suggest checking 1409 files for errors.

Is this problem another of the newly introduced Windows 8.1 bugs or ishere a solution that can be applied? Thanks.

Windows for home | Previous Windows versions | Devices and drivers

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2014-01-23T22:34:19+00:00

Hope I can help to someone.

I had the same issue with the fresh Windows 8.1 Pro.

Couldn't find answer so had to debug Windows to find a solution.

"Microsoft Link-Layer Discovery Protocol" binary is \Windows\system32\DRIVERS\mslldp.sys

Its config registry key is HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MsLldp

During backup a VSS process running under NETWORK_SERVICE account calls cryptcatsvc!CSystemWriter::AddLegacyDriverFiles(), which enumerates all the drivers records in Service Control Manager database and tries opening each one of them. , The function fails on MSLLDP record with "Access Denied" error.

Turned out it fails because MSLLDP driver's security permissions do not allow NETWORK_SERVICE to access the driver record.

The binary security descriptor for the record is located here:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MsLldp\Security

It should be modified, I used SC.EXE and Sysinternals' ACCESSCHK.EXE to fix it.

The original security descriptor looked like below:

>accesschk.exe -c mslldp

mslldp

  RW NT AUTHORITY\SYSTEM

  RW BUILTIN\Administrators

  RW S-1-5-32-549       <- these are server operators

  R  NT SERVICE\NlaSvc

No service account is allowed to access MSLLDP driver

The security descriptor for the drivers that were processed successfully looked this way:

>accesschk.exe -c mup

mup

  RW NT AUTHORITY\SYSTEM

  RW BUILTIN\Administrators

  R  NT AUTHORITY\INTERACTIVE

  R  NT AUTHORITY\SERVICE  <- this gives access to services

How to add access rights for NT AUTHORITY\SERVICE to MSLLDP service:

  1. Run: SC sdshow MSLLDP

You'll get something like below (SDDL language is documented on MSDN):

D:(D;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BG)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;CCDCLCSWRPDTLOCRSDRCWDWO;;;BA)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SO)(A;;LCRPWP;;;S-1-5-80-3141615172-2057878085-1754447212-2405740020-3916490453)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)

  1. Run: SC sdshow MUP

You'll get:

D:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWLOCRRC;;;IU)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)

  1. Take NT AUTHORITY\ SERVICE entry, which is (A;;CCLCSWLOCRRC;;;SU) and add it to the original MSLLDP security descriptor properly, right before the last S:(AU... group.
  2. Apply the new security descriptor to MSLLDP service :

sc sdset MSLLDP D:(D;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BG)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;CCDCLCSWRPDTLOCRSDRCWDWO;;;BA)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SO)(A;;LCRPWP;;;S-1-5-80-3141615172-2057878085-1754447212-2405740020-3916490453)(A;;CCLCSWLOCRRC;;;SU)S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)

  1. Check the result:

>accesschk.exe -c mslldp

mslldp

  RW NT AUTHORITY\SYSTEM

  RW BUILTIN\Administrators

  RW S-1-5-32-549

  R  NT SERVICE\NlaSvc

  R  NT AUTHORITY\SERVICE

  1. Run you backup app, the error is gone for my Home Server backup.

!!! Do not forget to use your security descriptor for MSLLDP driver since I guess there can be some rare cases when its different for your machine. Do not copy my SDDL descriptions, just in case. And backup the old descriptor just in case !!!

I don't know what reason MS had behind all this, probably some security concerns or probably this is just a bug. Definitely not a security problem in my environment.

Good luck!

Was this answer helpful?

200+ people found this answer helpful.
0 comments No comments

225 additional answers

Sort by: Most helpful
  1. Anonymous
    2016-02-18T02:21:38+00:00

    Hallo thekochs,

    auch ich hatte keine S: -Gruppe am Ende, habe (A;;CCLCSWLOCRRC;;;SU) einfach ganz ans Ende gesetzt..

    (siehe mein Beispiel)  ..und es funktioniert.

    Warum willst du den String erweitern um ??

    (A ;; CC ;;; S-1-5-80-242729624-280608522-2219052887-3187409060-2225943459)

    ..und in deinem Beispiel mit sdset, fehlt auch am Anfang das D:

    sc sdset MSLLDPD:(D ;; CCDCLCSWRPWPDTLOCRSDRCWDWO ;;; BG) (A ;; CCDCLCSWRPWPDTLOCRSDR .....

    ......

    Warum nicht einfach ?

    sc sdset MSLLDP

    D:(D;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BG)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;CCDCLCSWRPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SO)(A;;LCRPWP;;;S-1-5-80-3141615172-2057878085-1754447212-2405740020-3916490453)(A ;; CCLCSWLOCRRC ;;; SU)

    bitte den String nich einfach übernehmen, sondern dein Origial erweitern.

    Aber vorher ein Disk-Backup machen!

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2016-02-18T02:04:58+00:00

    As you have discovered, accesschk is NOT part of W10 OS

    So far as your addition, you are adding a lot more to your MSLLDP than I did, and you have also removed the D: at the beginning.  I'm not versed well enough in this stuff to comment as to what the effects of removing the initial D:

    It does appear that you are adding Fearless's fix rather the one in the response marked answer, and that is probably a good thing.

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2016-02-17T21:06:09+00:00

    RonRosenfeld,

    Thx for your inputs.....and agreed....in fact I'm freaked out about all of this.

    Questions...........

    I would have assumed Accesschk is already part of W10 O/S.

    It seems from my efforts to use the cmd to check things it is not......thus, I need to install Accesschk ?

    If so, I assume thru Microsoft Technet ? https://technet.microsoft.com/en-us/sysinternals/accesschk.aspx

    Not sure if I read the links that explain I would truly understand....thus hoping with this lengthy thread things are fairly solid on what needs to be inputed.  Reading thru remaker post he had no S:(AU;FA;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;WD)........

    Just like you said.  I had paused at first since I didn't have a "S:" section.  When I read up on SDDL at https://msdn.microsoft.com/en-us/library/windows/desktop/aa379570%28v=vs.85%29.aspx

    I learned that you needed the O: G: D: and S: sections, in order.  I assumed taht if the S: section was missing from my original security descriptor, I assumed I could just add the CryptSvc declaration at the end.

    It would be nice if Microsoft released a FixIt for this.  Seems like a lot of people have it, and it is some delicate surgery to fix it.

    I sure 2nd he comment on Microsoft......would be VERY nice to have a FIXIT on this.

    I also found several Windows 10 posts that vary slightly from W7/8.1 but align exactly to what I got from my sdshow.

    I will read thru more carefully but could I trouble you to review the complete string as you see it...with adder ?

    Here is my.........

    C:&gt;sc sdshow MSLLDP

    D:(D;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BG)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;CCDCLCSWRPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SO)(A;;LCRPWP;;;S-1-5-80-3141615172-2057878085-1754447212-2405740020-3916490453)

    Here is my thought............

    C:&gt;sc sdset MSLLDP D:(D;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BG)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;SY)(A;;CCDCLCSWRPDTLOCRSDRCWDWO;;;BA)(A;;CCLCSWRPWPDTLOCRRC;;;SO)(A;;LCRPWP;;;S-1-5-80-3141615172-2057878085-1754447212-2405740020-3916490453)(A;;CC;;;S-1-5-80-242729624-280608522-2219052887-3187409060-2225943459)

    Comments ?

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2016-02-17T17:40:03+00:00

    I would be more fearful of installing some uninterpretable string provided over the internet than installing the sysinternals package.  With the latter, you can actually see what you are doing with regard to the security settings.  Without it, you should go to the reference cited somewhere in this thread so you understand exactly what you are doing (what all those characters actually mean). 

    Your MSLLDP string is the same as mine was before modification. 

    Your MUP string is different, but seems to include the proper substring.

    My best guess from what you write is that you should add the same string:

    (A;;CCLCSWLOCRRC;;;SU)

    to your MSLLDP string sdset argument as mentioned by others.   I would also suggest doing a full disk backup so that if your modifications make your system unusable, you will be able to recover.

    Was this answer helpful?

    0 comments No comments