Push installation of RAS components (RDSH or Gateway) to the same server where Publishing Agent and Console are already installed fails. Alternative hostname was previously configured in DNS and is used during the push installation. The error received is "Current credentials used on this system do not allow remote installation":
Windows Event Viewer has the following errors in Security log:
Status 0xC000006D is specific for this issue.
This problem occurs because of Windows security feature named loopback check functionality, which is by default enabled in Windows Server 2003 SP1 and higher. Therefore, authentication fails if the FQDN or the custom host header that you use does not match the local computer name.
The resolution is described in Microsoft KB 926642.
Extract from the article:
The following actions should be performed on the affected server:
- Click Start, click Run, type regedit, and then click OK;
- Locate and then click the following registry subkey: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\MSV1_0;
- Right-click MSV1_0, point to New, and then click Multi-String Value;
- In the Name column, type BackConnectionHostNames, and then press ENTER;
- Right-click BackConnectionHostNames, and then click Modify;
- In the Value data box, type the CNAME or the DNS alias, that is used for this computer, and then click OK;
Note Type each host name on a separate line;
Note If the BackConnectionHostNames registry entry exists as a REG_DWORD type, you have to delete the BackConnectionHostNames registry entry;
- Quit Registry Editor, and then restart the server;
- Launch Parallels RAS Console in elevated mode (Right Mouse Button click → "Run as administrator") and repeat the installation procedure. As for usual remote push installation cases, UAC must be turned off and TCP ports 135 and 445 must be opened.