Solved

AD-LDS Instance 2008 Question

Posted on 2014-01-02
7
324 Views
Last Modified: 2014-02-05
We have an ADAM instance that was migrated from 2003 to AD-LDS 2008. After doing so, the application broke after conecting to the AD-LDS 2008. We are using a wide IP alias that was never changed. The application works if we connect to 2003 but not to the 2008 instance. Any ideas? Thank you!
0
Comment
Question by:syseng007
  • 3
  • 2
  • 2
7 Comments
 
LVL 35

Expert Comment

by:Mahesh
ID: 39752121
Have you done in place gradation from 2003 server to 2008 server  as per below link ?
http://technet.microsoft.com/en-us/library/cc732566(WS.10).aspx
In that case you should not face any issues

Is AD-LDS 2008 is also Domain controller or just member server ?

if its member server, then request you to just disjoin server from domain and re-join again and check if application is working

Mahesh
0
 

Author Comment

by:syseng007
ID: 39752239
Hi Mahesh, the migration is not in place, and AD-LDS is a member server....
0
 

Author Comment

by:syseng007
ID: 39752327
We are getting this error when we are trying to connect:

Caused by: java.security.PrivilegedActionException: javax.naming.AuthenticationException: GSSAPI [Root exception is javax.security.sasl.SaslException: GSS initiate failed [Caused by GSSException: No valid credentials provided (Mechanism level: Server not found in Kerberos database (7))]]

        at java.security.AccessController.doPrivileged(Native Method)

        at javax.security.auth.Subject.doAs(Unknown Source)

        at mesh.entitlements.provider.adam.DirectoryConnection.doAsCurrentUserWithRetry(DirectoryConnection.java:104)

        at mesh.entitlements.provider.adam.DirectoryConnection.doAsCurrentUserWithRetry(DirectoryConnection.java:122)

        at mesh.entitlements.provider.adam.DirectoryConnection.doAsCurrentUser(DirectoryConnection.java:97)

        at mesh.entitlements.provider.adam.DirectoryConnection.getRootContext(DirectoryConnection.java:77)
0
Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

 
LVL 35

Expert Comment

by:Mahesh
ID: 39752335
Have you tried disjoin \ re-join of 2008 ADLDS server please ?

If problem still persists you could give a try in place upgrade of 2003 machine as per above link

Mahesh
0
 
LVL 19

Expert Comment

by:compdigit44
ID: 39755247
Judging by the error message it sounds like the proper service DNS entries are missing for the app to find the correct ADLDS instance also ADLDS security may be more stringent that 2003..

I would suggest you follow Mahesh advice and run through the upgrade graduation processess
0
 

Author Comment

by:syseng007
ID: 39756042
@Mahesh - there are 5 instances on the member server and there's only that's kicking off an error though...So I don't think disjoin and re-add to the domain would be the solution....
0
 
LVL 19

Accepted Solution

by:
compdigit44 earned 500 total points
ID: 39756302
I would suggest to try to re-register your SPN for ADLDA to make sure the service account for this ADLDS instance is registered in AD


http://technet.microsoft.com/en-us/library/cc816802(v=ws.10).aspx
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

The recent Microsoft changes on update philosophy for Windows pre-10 and their impact on existing WSUS implementations.
This script can help you clean up your user profile database by comparing profiles to Active Directory users in a particular OU, and removing the profiles that don't match.
This tutorial will give a short introduction and overview of Backup Exec 2012 and how to navigate and perform basic functions. Click on the Backup Exec button in the upper left corner. From here, are global settings for the application such as conne…
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…

863 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

27 Experts available now in Live!

Get 1:1 Help Now