Answered by:
CRM 2011 on premises email router error: An unsecured or incorrectly secured fault was received from the other party. See the inner Faultexeption for the fault code and detail

Question
-
I am currently building a CRM 2011 test environment that replicates the production environment. I have configured a deployment in the Email Router Configuation Manager as follows:
- Deployment: My company
- Microsoft Dynamics CRM Server: http://crmserver/org
- Access Credentials: Other Specified
- Username: domain\crm_email_service_ts
- Incoming configuration profile: <none selected>
- Outgoing configuration profile: SMTP Outgoing
Every time I try to load data in the Email Router Configuration Manager i get the following error:
An unsecured or incorrectly secured fault was received from the other party. See the inner Faultexeption for the fault code and detail
I tried following the instructions of microsoft KB http://support.microsoft.com/kb/2531924 which says that the account might be locked, has insuficient AD rights or that there is a discrepancy in the time of the servers involved. However nothing like that applies.
- The crm_email_service_ts account is bound to a CRM user with system administration access.
- I can log-in with the crm_email_service_ts account without any issues at the CRM server, and I can also open Dynamics CRM on Internet Explorer with that account without any issues.
- Every single host and server in this domain has their clock synchronised with the domain controler, which is in turn synchronised with an atomic clock via NTP.
I have also tried using the Local system Account in the deployment configured for the email router (computer account is a member of the PrivUserGroup in AD) but that gives the exact same error.
I am all out of ideas here. Could anyone please advise what might be wrong?
Regards,
P.
- Edited by pmdci Friday, November 7, 2014 3:04 PM
Friday, November 7, 2014 2:46 PM
Answers
-
We found the solution to this issue at another knowledge base article. However the article does not refer to the error message we were having.
Basicaly we had to perform a change at the applicationhost.config file of both CRM servers so the system.webserver tag includes the useAppPool credentials. This procedure is outlined in the step 2 of the resolution in KB article 2536453:
https://support.microsoft.com/kb/2536453
Regards,
P.- Marked as answer by pmdci Friday, November 14, 2014 11:45 AM
Friday, November 14, 2014 11:45 AM
All replies
-
hi,
please make sure that email router is running as crm_email_service_ts.
also make sure that out going profile is using crm_email_service_ts.
please publish the changes once you have done the changes before loading the users.
make sure that crm_email_service_ts is also in privuser group.
please do not forget to change system settings - email tab.
good luck.
regards
Jithesh pl
Sunday, November 9, 2014 9:16 AM -
I´ve seen this error always when spn aren´t setted up or not correctly.
gruss Daniel Ovadia MBSS - Microsoft Dynamics CRM MCNPS
Monday, November 10, 2014 7:57 AM -
Hi,
Thanks for trying to help.
I have to say I would like to refrain from making such changes because that does not reflect how the system is in production -- and production is working fine.
We replicated the CRM production environment to the letter. The same number of servers (two full servers, email router running on server 01) and the same configuration for the service accounts. I also ran ADSIEdit in order to change the app account SPNs and make them look like production (pointing to the counterpart servers in test, of course).
So in my view, this must work like production. However I did add the crm_email_service_ts account into the respective privuser group but that did not change anything.
Regards,
P.Monday, November 10, 2014 9:53 AM -
Hi Daniel,
I copied ran ADSI Edit and ensured that the SPNs in the test environment reflect those of the production for the application service account. Anything else I should look into?
Regards,
P.Monday, November 10, 2014 10:08 AM -
check if you may have duplicated spn in network
gruss Daniel Ovadia MBSS - Microsoft Dynamics CRM MCNPS
Monday, November 10, 2014 10:20 AM -
Hi Daniel,
I am really running out of options here. The SPNs look exactly the same between both environments. The only accounts that have SPNs set for the production environment is the CRM Application Service Account. Below is the screenshot showing the SPNs for both accounts (production and test):
Production:
Test:
Any ideas?
Regards,
P.Monday, November 10, 2014 5:05 PM -
spn looks good..
did you tried to uninstall and install mailrouter again? I don´t have more ideas, as i wrote i saw this when spn aren´t setted up corectly, but yours looking correct. Sometimes it also stopped when spn the servernetbiosname with crmapppool, but as documentation it isn´t. you could give a try.
gruss Daniel Ovadia MBSS - Microsoft Dynamics CRM MCNPS
Tuesday, November 11, 2014 7:17 AM -
We found the solution to this issue at another knowledge base article. However the article does not refer to the error message we were having.
Basicaly we had to perform a change at the applicationhost.config file of both CRM servers so the system.webserver tag includes the useAppPool credentials. This procedure is outlined in the step 2 of the resolution in KB article 2536453:
https://support.microsoft.com/kb/2536453
Regards,
P.- Marked as answer by pmdci Friday, November 14, 2014 11:45 AM
Friday, November 14, 2014 11:45 AM