04-18-2013 04:12 AM - edited 03-10-2019 08:19 PM
We are running NAC OS 4.9.2 in OOB L2 Virtual Gateway...
We have CAS Cluster
Primary CAS -- 10.245.220.5 & Secondary CAS -- 10.245.220.6 and Service-IP 10.245.220.4
When in HA Cluster Primary is Active and Secondary is Standby Ok , ADSSO is Working and Service is started
We have capture details of same .
10.245.220.5
------------------------------------------------------------------------------------------------------
2013-04-18 15:46:21.833 +0530 Thread-70 INFO com.perfigo.wlan.jmx.adsso.GSSServer - GSSServer - done building kdc list for domain kotakgroup.com
2013-04-18 15:46:21.833 +0530 Thread-70 INFO com.perfigo.wlan.jmx.adsso.GSSServer - GSSServer - KDC(s) :[kgp-gor-dc01.kotakgroup.com, kgp-gor-dc02.kotakgroup.com, kgp-gor-dc03.kotakgroup.com, kgp-gor-dc04.kotakgroup.com, kgp-gor-dc05.kotakgroup.com, kgp-dr-dc01.kotakgroup.com, kgp-dr-dc03.kotakgroup.com, kgp-dr-dc02.kotakgroup.com]
2013-04-18 15:46:21.833 +0530 Thread-70 INFO com.perfigo.wlan.jmx.adsso.GSSServer - GSSServer - writeKrbFile: writing to file ../conf/krb.txt
2013-04-18 15:46:21.833 +0530 Thread-70 INFO com.perfigo.wlan.jmx.adsso.GSSServer - GSSServer - writeKrbFile: wrote to file ../conf/krb.txt
2013-04-18 15:46:21.834 +0530 Thread-70 INFO com.perfigo.wlan.jmx.adsso.GSSServer - GSSServer - creating login context ...
2013-04-18 15:46:21.834 +0530 Thread-70 INFO com.perfigo.wlan.jmx.adsso.GSSServer - GSSServer - created login context ...javax.security.auth.login.LoginContext@bb3f71
2013-04-18 15:46:39.207 +0530 Thread-70 INFO com.perfigo.wlan.jmx.adsso.GSSServer - Notifying GSSServer status Started
2013-04-18 15:47:07.540 +0530 Timer-3 INFO com.perfigo.wlan.jmx.adsso.GSSRetrier - GSSR - Windows SSO is running
When Primary is rebooted and Secondary becomes Active Ok , ADSSO is not working and Service is not started
10.245.220.6
------------------------------------------------------------------------------------------------------
2013-04-18 15:50:42.933 +0530 Timer-3 INFO com.perfigo.wlan.jmx.adsso.GSSServer - Server starting server ...
2013-04-18 15:50:42.933 +0530 Timer-3 INFO com.perfigo.wlan.jmx.adsso.GSSServer - Server is now running ...
2013-04-18 15:50:42.933 +0530 Thread-68 INFO com.perfigo.wlan.jmx.adsso.GSSServer - GSSServer - SPN : [casadsso/kotakgroup.com@KOTAKGROUP.COM]
2013-04-18 15:50:42.933 +0530 Thread-68 INFO com.perfigo.wlan.jmx.adsso.GSSServer - GSSServer - building kdc list for domain kotakgroup.com
2013-04-18 15:50:42.934 +0530 Thread-68 ERROR com.perfigo.wlan.jmx.adsso.GSSServer - Unable to start server ... kotakgroup.com.
2013-04-18 15:50:42.937 +0530 Thread-68 INFO com.perfigo.wlan.jmx.adsso.GSSServer - Notifying GSSServer status Stopped
2013-04-18 15:50:42.937 +0530 Thread-68 INFO com.perfigo.wlan.jmx.adsso.GSSServer - server is exiting .
Our Observation is krb.txt is not getting generated when Secondary is Active Ok ...
Can any one suggest how to fix the issue...
04-19-2013 06:25 AM
Hi,
Can you check and see if dns and ntp are accurate and can you verify your AD environment? What version of domain controllers are in service if there are a mix then other steps like modifying a few files maybe needed.
Also was the secondary CAS replaced or reimaged recently?
Thanks,
Sent from Cisco Technical Support iPad App
05-04-2013 02:37 AM
Hi
Issue got resolve , it was dns issue ...
After adding proper Local DNS , ADSSO started working for Secondary also
Thanks for response
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide