QlikView Webserver (based on IIS) not able to resolve Group Membership through the DSC
Article Number: 000062714 | Last Modified: 2019/01/21
Using IIS as a QlikView WebServer, it appears that you cannot resolve group membership through the DSC. If you search users from the Qlik Management Console, the group membership is being resolved correctly.
In the QlikView WebServer log you can see the following event: Error Exception when trying to resolve groups for DSP1\user1 Exception DSC did not respond to request. Last exception (for http://qlikserver2:4730/DSC/Service): ANY did not respond to request. Last exception (for http://qlikserver2:4730/DSC/Service): An error occurred while making the HTTP request to https://qlikserver2:4730/ANY/Service. This could be due to the fact that the server certificate is not configured properly with HTTP.SYS in the HTTPS case. This could also be caused by a mismatch of the security binding between the client and the server.
There is two registry key to allow .net to use TLS 1.2 only. If those keys are not set IIS won't be able to send the request to the Directory Service Connector.
The following two registry keys needs to be set up on the QlikView WebServer (Based on IIS) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v4.0.30319\SystemDefaultTlsVersions -> DWORD set to 1 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\v4.0.30319\SystemDefaultTlsVersions -> DWORD set to 1
Collaborate with over 60,000 Qlik technologists and members around the world to get answers to your questions, and maximize success.