04-30-2012 08:14 AM - edited 03-12-2019 05:40 PM
We are deploying ACS 5.2 to replace our ACS 4.2 in production. I have two wireless networks setup as WPA2-Enterprise. One points at the ACS 4.2 and the other at the ACS 5.2. Both use the same SSL certificate with the same CN. Both authenticate Windows 7 clients. However, Windows 8 CP will only authenticate to the ACS 4.2 and not to ACS 5.2. The error it gives is:
11051 Radius packet contains invalid state attribute
It also shows no authentication method (most of the time).
Occasionally, I get a request that actually shows an authentication method of PEAP (EAP-MSCHAPv2) which is what it should be. On those requests, I get error:
24444 Active Directory operation has failed because of an unspecified error in the ACS.
Both ACs 4.2 and ACS 5.2 are pointed at the same Windows AD source.
Anyone have any ideas? Is there any other information I can provide to help troubleshoot? I know Windows 8 is not even out yet. But, it would be nice to have it working.
Thanks!
Jodie
05-02-2012 01:10 AM
Jodie,
If you want to troubleshoot this issue you can do the following:
ssh into the ACS 5.2 appliance, > "acs-config" > enter you web credentials
After logging in (takes 45 seconds for the username to prompt) "debug-adclient enable"
After this reproduce the issue, then under monitoring and reporting note the time the authentication occured.
You can download the support bundle from the monitoring and reports section, uncheck the encryption option for the support bundle, only check to gather debug-logs for the last 1 day.
After you get the support bundle then extract and go to the debug-logs directory and open the ACSADAgent.log file and capture the output at the timestamp you saw, and post it here.
Thanks
Tarik Admani
05-02-2012 06:26 AM
Thanks Tarik! I appreciate the detailed steps to collect the information to help troubleshoot this issue.
Here are the logs requested:
May 2 08:16:36 sh-netacs2 adclient[7987]: DEBUG <19 ping=""> daemon.execute executing request 'ping' in thread 302971996819>
May 2 08:16:36 sh-netacs2 adclient[7987]: DEBUG <19 ms-rpc="" user="" authentication=""> daemon.execute executing request 'MS-RPC user authentication' in thread 305489808019>
May 2 08:16:36 sh-netacs2 adclient[7987]: DEBUG <19 ms-rpc="" user="" authentication=""> daemon.execute I:IPCClient1::doNetLogonSamLogon - user=SH-HIS\jcrouch19>
May 2 08:16:36 sh-netacs2 adclient[7987]: DEBUG <19 ms-rpc="" user="" authentication=""> base.adagent Find GUID: fa61e77fbfc98044b7153bf5abc9fd78 (7)19>
May 2 08:16:36 sh-netacs2 adclient[7987]: DEBUG <19 ms-rpc="" user="" authentication=""> com.centrify.smb.smbserver SMB Connect to server sh-dc03.shv.lsuhsc-s.edu19>
May 2 08:16:36 sh-netacs2 adclient[7987]: DEBUG <19 ms-rpc="" user="" authentication=""> base.adagent Domain Level for '' is not PreW2K819>
May 2 08:16:36 sh-netacs2 adclient[7987]: DEBUG <19 ms-rpc="" user="" authentication=""> dns.findsrv FindSrvFromDns(0): _kerberos._tcp.LSUHSC-S._sites.SHV.LSUHSC-S.EDU19>
May 2 08:16:36 sh-netacs2 adclient[7987]: DEBUG <19 ms-rpc="" user="" authentication=""> dns.findsrv FindFromDns(0): _kerberos._tcp.LSUHSC-S._sites.SHV.LSUHSC-S.EDU19>
May 2 08:16:36 sh-netacs2 adclient[7987]: DEBUG <19 ms-rpc="" user="" authentication=""> dns.findsrv FindSrvFromDns(0): _kerberos._tcp.SHV.LSUHSC-S.EDU19>
May 2 08:16:36 sh-netacs2 adclient[7987]: DEBUG <19 ms-rpc="" user="" authentication=""> dns.findsrv FindFromDns(0): _kerberos._tcp.SHV.LSUHSC-S.EDU19>
May 2 08:16:36 sh-netacs2 adclient[7987]: DEBUG <19 ms-rpc="" user="" authentication=""> dns.controllers Updated controller info: last update = Wed May 2 08:01:16 2012, siteName = 'LSUHSC-S', m_serviceType = KDC, domain = 'SHV.LSUHSC-S.EDU', site list = (sh-dc03.shv.lsuhsc-s.edu:88 sh-dc04.shv.lsuhsc-s.edu:88 sh-epic-dc01.shv.lsuhsc-s.edu:88), inferior list = (afm-dc01.shv.lsuhsc-s.edu:88)19>
May 2 08:16:36 sh-netacs2 adclient[7987]: DEBUG <19 ms-rpc="" user="" authentication=""> dns.findkdc Kerberos lookup of SHV.LSUHSC-S.EDU: DNS resolve to sh-dc03.shv.lsuhsc-s.edu:88 sh-dc04.shv.lsuhsc-s.edu:88 sh-epic-dc01.shv.lsuhsc-s.edu:88 afm-dc01.shv.lsuhsc-s.edu:8819>
May 2 08:16:36 sh-netacs2 adclient[7987]: DEBUG <19 ms-rpc="" user="" authentication=""> dns.findkdc Kerberos lookup of SHV.LSUHSC-S.EDU: DNS resolve to sh-dc03.shv.lsuhsc-s.edu:88 sh-dc04.shv.lsuhsc-s.edu:88 sh-epic-dc01.shv.lsuhsc-s.edu:88 afm-dc01.shv.lsuhsc-s.edu:8819>
May 2 08:16:36 sh-netacs2 adclient[7987]: DEBUG <19 ms-rpc="" user="" authentication=""> base.osutil Module=Kerberos : initSecurityContext - gss_init_sec_context failed (reference ../smb/utils/gsskerberos.cpp:198 rc: -1765328352)19>
May 2 08:16:36 sh-netacs2 adclient[7987]: DEBUG <19 ms-rpc="" user="" authentication=""> smb.rpc.schannel SecureChannel::close: m_fh=0x019>
May 2 08:16:36 sh-netacs2 adclient[7987]: DEBUG <19 ms-rpc="" user="" authentication=""> com.centrify.smb.smbserver SMB disconnect from server sh-dc03.shv.lsuhsc-s.edu19>
May 2 08:16:36 sh-netacs2 adclient[7987]: DEBUG <19 ms-rpc="" user="" authentication=""> daemon.execute O:IPCClient1::netLogonSamLogon - user=SH-HIS\jcrouch (ntStatus=0xc0000001)19>
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 last message repeated 3 times
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 last message repeated 3 times
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 last message repeated 3 times
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 last message repeated 3 times
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:46 sh-netacs2 adclient[7987]: DEBUG
May 2 08:16:59 sh-netacs2 debugd[2553]: [8075]: locks:file: lock.c[357] [daemon]: obtained repos-mgr lock
May 2 08:16:59 sh-netacs2 debugd[2553]: [8075]: config:repository: rm_repos_cfg.c[251] [daemon]: scanning the tmp dir
May 2 08:16:59 sh-netacs2 debugd[2553]: [8075]: locks:file: lock.c[371] [daemon]: released repos-mgr lock
May 2 08:16:59 sh-netacs2 debugd[2553]: [8075]: locks:file: lock.c[357] [daemon]: obtained repos-mgr lock
May 2 08:16:59 sh-netacs2 debugd[2553]: [8075]: config:repository: rm_repos_cfg.c[251] [daemon]: scanning the tmp dir
May 2 08:16:59 sh-netacs2 debugd[2553]: [8075]: locks:file: lock.c[371] [daemon]: released repos-mgr lock
05-03-2012 10:33 PM
Jodie,
Please check your ntp configuration, are you using an ntp server or did you manually set the clock on ACS 5? It look as if the ACS isnt able to connect to the domain using its computer account. Point the ACS to a reliable ntp server or set the clock as close as you can to the current time.
Thanks
tarik Admani
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide