ERROR: [7054]S30442: Failed to start Security Translator, hr=80004005 (NETIQKB44959)

  • 7744959
  • 02-Feb-2007
  • 17-Apr-2008

Resolution

fact
Domain Migration Administrator 7.x

symptom
ERROR: [7054]S30442: Failed to start Security Translator, hr=80004005

cause

This error can occur if an Exchange 5.5 mailbox associated with a user account has the reference bit indicating a SACL set to ON when the value is actually NULL. When DMA encounters such a mailbox, the mailbox translation process fails for the current mailbox and then halts.

Mailboxes created using the native Exchange Administrator utility should not experience this issue, however, if a mailbox is created using a custom script or application, it is possible for the mailbox to have this bit set and still have a NULL SACL.



fix

Install DMA 7.2 Hotfix 45265. This hotfix enables DMA to translate mailboxes with a NULL SACL and continue the translation process. 

For more information, see the following Knowledge Base article:
What fixes are contained in DMA Hotfix 45265?
https://www.netiq.com/kb/esupport/consumer/esupport.asp?id=NETIQKB45265



note

You can verify if the SACL setting for a mailbox is causing the problem.

WARNING: Manually editing the NT-Security-Descriptor property on an Exchange mailbox is not supported and may create problems in later accessing the mailbox. The following instructions are intended only to help you verify whether the bit for a SACL is set.

To verify the SACL setting for a single mailbox:

  1. Open Exchange 5.5 Administrator in RAW mode (admin.exe /r).
  2. Select the problem mailbox.
  3. Click File > Raw Properties.
  4. In the Object attributes column, select NT-Security-Descriptor.
  5. Click Editor.
  6. For Editor type, select Text.
  7. Click OK.

If the bit for the SACL is not set, the NT-Security Descriptor hex number begins with 01000480.
If the bit for the SACL is set, the hex number begins with 01001480.



note
If you are unable to upgrade to DMA 7.2 Hotfix 45625, another workaround may be to clear the bit on the mailbox NT-Security-Descriptor property for the SACL. If there is no value for the SACL, there should be no problem created by clearing this bit. However, NetIQ Corporation cannot provide support to implement this resolution.

Additional Information

Formerly known as NETIQKB44959