<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AD SSO Problem in NAC in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ad-sso-problem-in-nac/m-p/1207480#M763943</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You might check the time on the DC, the CAS, and the CAM.  ADSSO uses kerberos, which requires the times on the devices to be synced. (I believe within 5 minutes of each other)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 13 Mar 2009 21:51:34 GMT</pubDate>
    <dc:creator>jwjorgensen</dc:creator>
    <dc:date>2009-03-13T21:51:34Z</dc:date>
    <item>
      <title>AD SSO Problem in NAC</title>
      <link>https://community.cisco.com/t5/network-security/ad-sso-problem-in-nac/m-p/1207476#M763939</link>
      <description>&lt;P&gt;i have successfuly run the KT pass in AD. then as per the procedure i have sync the AD with CAS &amp;amp; CAM after that when i am going to start AD service&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Error : Could not start the SSO service. Please check the configuration. is comming. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Neither i have found the log file in cas &lt;/P&gt;&lt;P&gt;/perfigo/logs/perfigo-redirect-log0.log.0.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. i have checked the connectivty between AD and CAS its fine&lt;/P&gt;&lt;P&gt;2. As per the document i have completed all the steps still not able to integrate AD with CAS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;can any one help me out &lt;/P&gt;&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 11:21:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ad-sso-problem-in-nac/m-p/1207476#M763939</guid>
      <dc:creator>pandapritam</dc:creator>
      <dc:date>2020-02-21T11:21:09Z</dc:date>
    </item>
    <item>
      <title>Re: AD SSO Problem in NAC</title>
      <link>https://community.cisco.com/t5/network-security/ad-sso-problem-in-nac/m-p/1207477#M763940</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just wondering, are you using 2008 or 2003 domain controller(s).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Mar 2009 12:57:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ad-sso-problem-in-nac/m-p/1207477#M763940</guid>
      <dc:creator>greg.washburn</dc:creator>
      <dc:date>2009-03-13T12:57:38Z</dc:date>
    </item>
    <item>
      <title>Re: AD SSO Problem in NAC</title>
      <link>https://community.cisco.com/t5/network-security/ad-sso-problem-in-nac/m-p/1207478#M763941</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Follow the exact requirement of AD DC:&lt;/P&gt;&lt;P&gt;For Example Win2k3 with SP1 is supported while it is not supported without SP1...&lt;/P&gt;&lt;P&gt;Also, make sure the ktpass has the minimum required version. if not download it from Microsoft.&lt;/P&gt;&lt;P&gt;Make sure you follow the right procedure for ktpass. The procedures in case you have multiple DCs is different then the one with single DC.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Mar 2009 16:06:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ad-sso-problem-in-nac/m-p/1207478#M763941</guid>
      <dc:creator>jad.sadek</dc:creator>
      <dc:date>2009-03-13T16:06:21Z</dc:date>
    </item>
    <item>
      <title>Re: AD SSO Problem in NAC</title>
      <link>https://community.cisco.com/t5/network-security/ad-sso-problem-in-nac/m-p/1207479#M763942</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The reason I asked what OS your domain controllers are running is because you may need to run ktpass differently for CAS server to support authentication to 2k8.  We certainly did.  We were only able to use a single domain controller vs a domain for the "Account CAS on setting".&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Mar 2009 18:42:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ad-sso-problem-in-nac/m-p/1207479#M763942</guid>
      <dc:creator>greg.washburn</dc:creator>
      <dc:date>2009-03-13T18:42:27Z</dc:date>
    </item>
    <item>
      <title>Re: AD SSO Problem in NAC</title>
      <link>https://community.cisco.com/t5/network-security/ad-sso-problem-in-nac/m-p/1207480#M763943</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You might check the time on the DC, the CAS, and the CAM.  ADSSO uses kerberos, which requires the times on the devices to be synced. (I believe within 5 minutes of each other)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Mar 2009 21:51:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ad-sso-problem-in-nac/m-p/1207480#M763943</guid>
      <dc:creator>jwjorgensen</dc:creator>
      <dc:date>2009-03-13T21:51:34Z</dc:date>
    </item>
    <item>
      <title>Re: AD SSO Problem in NAC</title>
      <link>https://community.cisco.com/t5/network-security/ad-sso-problem-in-nac/m-p/1207481#M763944</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;"Neither i have found the log file in cas&lt;/P&gt;&lt;P&gt;/perfigo/logs/perfigo-redirect-log0.log.0"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What version of Cisco NAC do you have installed?  If NAC 4.5+, look for the log file at /perfigo/access/tomcat/logs/nac-server.log&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Dan Laden&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 14 Mar 2009 06:08:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ad-sso-problem-in-nac/m-p/1207481#M763944</guid>
      <dc:creator>Daniel Laden</dc:creator>
      <dc:date>2009-03-14T06:08:50Z</dc:date>
    </item>
    <item>
      <title>Re: AD SSO Problem in NAC</title>
      <link>https://community.cisco.com/t5/network-security/ad-sso-problem-in-nac/m-p/1207482#M763945</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The location od CAS log fines differes based on the version.&lt;/P&gt;&lt;P&gt;in 4.1.x its /perfigo/logs&lt;/P&gt;&lt;P&gt;in 4.5 and later its /perfigo/control/tomcat/logs/&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try to understand whats going on by reading the logs.&lt;/P&gt;&lt;P&gt;Also please make sure the time is synchronized on AD and CAS &amp;amp; CAM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 14 Mar 2009 06:38:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ad-sso-problem-in-nac/m-p/1207482#M763945</guid>
      <dc:creator>vishekha</dc:creator>
      <dc:date>2009-03-14T06:38:07Z</dc:date>
    </item>
    <item>
      <title>Re: AD SSO Problem in NAC</title>
      <link>https://community.cisco.com/t5/network-security/ad-sso-problem-in-nac/m-p/1207483#M763946</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just a point of clarity.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For 4.5+, the NAC Manager log files are at /perfigo/control/tomcat/logs and the NAC Server log files are at /perfigo/access/tomcat/logs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Dan Laden&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 14 Mar 2009 19:44:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ad-sso-problem-in-nac/m-p/1207483#M763946</guid>
      <dc:creator>Daniel Laden</dc:creator>
      <dc:date>2009-03-14T19:44:56Z</dc:date>
    </item>
    <item>
      <title>Re: AD SSO Problem in NAC</title>
      <link>https://community.cisco.com/t5/network-security/ad-sso-problem-in-nac/m-p/1207484#M763947</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;The procedures in case you have multiple DCs is different then the one 
with single DC.&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Somewhere I heard that if you run KTPASS from the latest supported version of Windows Server in your domain, then the proper Kerberos mappings will replicate throughout. Your statement seems to contradict that; where did you find this information?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are having a problem similar to the OP, where one of our two CAS servers is failing to start the SSO service. This after attempting to run the KTPASS routine to allow for Windows 7 support. I do believe GUI utility is called for in a situation like this.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Mar 2010 21:40:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ad-sso-problem-in-nac/m-p/1207484#M763947</guid>
      <dc:creator>netjustin</dc:creator>
      <dc:date>2010-03-30T21:40:21Z</dc:date>
    </item>
  </channel>
</rss>

