802.1x random failures

I am in the process of implementing machine based 802.1x to my company. I have 2 radius servers and 1 CA. The machines get their certificates via group policy. The group policy is working fine and everyone has been issued their certificates that are supposed
to have them. I wait til they get their certificates, then enter the commands for 802.1x on their port. I have about 50 machines that are working as they should, but I have three random machines that will not communicate whenever I flip the port on the switch.
The three machines have valid certificates and have full connectivity to the two radius servers and the CA. I do not believe it is a switch problem, because I have other machines connected to this switch that are authenticating properly. Also, I have
tried the 802.1x hotfix on these machines with no luck. I am wondering if there is anything that I could try on the clients that would keep them from authenticating. All of my clients are Windows 7 SP1 64 bit. Any suggestions would be appreciated! 

Hi,
Based on your description, you are deploying 802.1x authenticated wired network access. The issue is that three machines in your network can’t pass the 802.1x authentication.
About “The three machines have full connectivity to the two radius servers and the CA.” Does it mean that the three machines can ping two radius servers?
What errors did three machines receive when the three machines logon? Or are there any related event logs in the RADIUS server?
For example, in Windows 2012 R2 NPS server, you could check Security-Auditing event in Custom Views\Server Roles\Network Policy and Access Services.
You could also check the Audit Failure event. It is in the Windows Logs\Security directory.
Please also check if the wired network (IEEE 802.3) group policy was applied to the three machines.
You could run
gpresult /h c:\report.html to generate the result of group policy.
If you couldn’t find the group policy which you created, please run
gpupdate /force command in the three clients.
Best Regards,
Tina
Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Subscriber Support, contact [email protected]

Similar Messages

  • Random Failure to power up.

    I have bootcamp installed and I run XP and Mac osx. Occasionally, my computer will either just freeze or shutdown. This generally only happens in XP, but when I go to turn the computer back on, the dvd drive whizzes but the computer will not give the starting sound. At this point, it just refuses to boot up, and the power button flashes three times in sequence continuously. I am not sure what is causing this, but if I boot up the computer without the power plugged in, I can sort of force it to boot up. I just bought the computer Last month, so it shouldn't be having any serious issues.

    Welcome to the Forums!
    Assuming you have an MBP, the power button does not flash (no light there). So, either the latch light (aka power LED) is flashing, or you have a desktop Mac.
    Either way, your RAM is the culprit. The 3 flash-pause-repeat sequence indicates "marginal RAM" (vs. flashing once per second, which means bad RAM or no RAM installed).
    See this page:
    http://docs.info.apple.com/article.html?artnum=303363
    So, your first step is to remove and re-seat your RAM - it may have become loose. The 'random' failure to start up would also be caused by this. This step solved the problem for the last poster with this same problem, see this thread.
    These instructions will show you how to access the MBP's RAM:
    http://docs.info.apple.com/article.html?artnum=303491
    If that does not allow you to boot normally, try booting with only one RAM chip inserted, then the other (i.e. test each chip independently). If a chip is bad, contact AppleCare.
    Hope this helps...

  • Random failure with "hdiutil create"

    Hi everyone
    I'm working on a Shell script supposed to build disk image files with hdiutil. The problem is that it randomly fails. Here is the output :
    +hdiutil: create failed - erreur 49168+
    That's all I get when using
    +hdiutil create -format UDBZ -volname "SFML-1.6-dev-macosx" -srcfolder "/Users/me/sfml/trunk/dist/SFML-1.5-dev-macosx" "$/Users/me/sfml/trunk/dist/SFML-1.6-dev-macosx.dmg" > /dev/null+
    When dropping "> /dev/null" and adding -debug, I noticed these lines before the end :
    +2009-07-24 18:31:40.620 diskimages-helper\[25526:1603] deleting /Users/lucas/sfml/trunk/dist/SFML-1.6-dev-macosx.dmg+
    +2009-07-24 18:31:40.620 diskimages-helper\[25526:1603] DIHelperNBI performOperation: returning 49168+
    +DIHLDiskImageCreate() returned 49168+
    +2009-07-24 18:31:40.842 diskimages-helper\[25526:10b] DIHelper dealloc.+
    +2009-07-24 18:31:40.843 diskimages-helper\[25526:10b] -DIHelperAgentMaster terminateUIAgentConnection.+
    +hdiutil: create failed - erreur 49168+
    I don't understand why it would try to delete the dmg file I'm trying to make...
    Here is the full log is you want to have look at it : http://pagesperso-orange.fr/c.sobecki/ceylo/data/hdiutil-failure-log.txt
    All I was able to find on this error is here : http://lists.apple.com/archives/Carbon-dev/2007/Aug/msg00357.html
    Where it says :
    +1) Some of the files you're trying to archive are being used exclusively by another process. A couple of people figured that their Anti-Virus software (Norton AV) was to blame.+
    +2) Disk space is low, and the hdiutil tool cannot perform its internal caching.+
    +3) A file system error which is not detected by Disk Utility prevents proper accessing some crucial files. Repairing the disk using "Disk Warrior" did help.+
    +4) Files which were put into the trash can but were not deleted yet cause problems when tried to being put into the disk image.+
    1) I'm not using an antivirus
    2) I've about 70 GB remaining
    3) But why would it be random ? It's always the same files that are being packed.
    4) I've no file in my trash.
    Does anyone have an idea why it fails ?
    Thanks
    Ceylo

    Ceylo wrote:
    Hi everyone
    I'm working on a Shell script supposed to build disk image files with hdiutil. The problem is that it randomly fails. Here is the output :
    +hdiutil: create failed - erreur 49168+
    Where it says :
    +1) Some of the files you're trying to archive are being used exclusively by another process. A couple of people figured that their Anti-Virus software (Norton AV) was to blame.+
    1) I'm not using an antivirus
    That's not the only reason, it's just one example. If the file is locked because it's being used by another process, that might explain the randomness of what is happening.
    Try running
    lsof
    and seeing if any of the files in question are open.

  • ISE - AD 802.1x Authentication Failure (All of the sudden)

    I have a WLC using ISE to authenticate through AD.  (No certificates - only username & password)
    ISE is single node deployment.
    Its been running fine for the past 6 months, but all of a sudden I get the following errors:
    Failure Reason:  12953 Received EAP packet from the middle of conversation that contains a session on this PSN that does not exist
    Resolution:  Verify known NAD issues and published bugs. Verify NAD configuration. Turn debug log on DEBUG level to troubleshoot the problem.
    Root cause:  Session was not found on this PSN. Possible unexpected NAD behaviour. Session belongs to this PSN according to hostname but may has already been reaped by timeout. This packet arrived too late.
    Any Ideas why this would happen ?

    im recevieing this error message also 
    Failure Reason:  12953 Received EAP packet from the middle of conversation that contains a session on this PSN that does not exist
    Resolution:  Verify known NAD issues and published bugs. Verify NAD configuration. Turn debug log on DEBUG level to troubleshoot the problem.
    Root cause:  Session was not found on this PSN. Possible unexpected NAD behaviour. Session belongs to this PSN according to hostname but may has already been reaped by timeout. This packet arrived too late.
    but im running ISE 1.3 with patch 1 only noticed this after the upgrade.
    nad is a 3560v2-24ps-s running c3560-ipservicesk9-mz.122-55.SE10.bin
    any ideas anyone?

  • 802.1x authentication failure

    hi, i'm not sure if i'm posting this in the right category but here goes
    i wanna use 802.1x on our network but can't seem to get it to work. i followed all the instruction on the web site. it says authentication failed. i'm pretty sure the radius works because i use that same radius for our vpn authentication.
    btw i'm using 48 port 2950-EI
    config
    aaa new-model
    aaa authentication dot1x default group radius
    interface FastEthernet0/3
    switchport access vlan 52
    switchport mode access
    no ip address
    dot1x port-control auto
    dot1x timeout reauth-period 1
    dot1x max-req 10
    dot1x reauthentication
    radius-server host x.x.x.x auth-port 1812 acct-port 1813 key <password>
    radius-server retransmit 3
    am i missing something? thanks

    Hello,
    ok, the config looks all right then. Is there a firewall or some other filter active between the switch and the RADIUS server that might be blocking the ports 1812 and 1813 ?
    Regards,
    GP

  • Random failures to CSS doing https balancing.

    So I have a cluster of about 10 machines behind a 11503, each server is setup like
    service server-1
    ip address 192.168.10.171
    port 443
    string cluster01
    keepalive type script ap-kal-httplist "192.168.10.171 /webct/about.jsp"
    keepalive frequency 15
    active
    and clustered in a service via
    content ssl-rule
    balance leastconn
    protocol tcp
    port 443
    advanced-balance sticky-srcip-dstport
    vip address 192.168.200.19
    add service server-1
    add service server-2
    add service server-3
    add service server-9
    add service server-10
    active
    I am not currently doing ssl termination, just balancing.
    Ok, so recently the load has started to rise (it is an e-learning application for a university and it's finals time) and now I see a scenario where random users are unable to connect to the https://elearningapp.somedomain.ca URL, while the person sitting next to them (both physically and IP-wise) connects fine. It is only a percentage of users who see this, seemingly no correlation between them, and if I reset the css it goes away for a while.

    You'll need to collect some info.
    First, capture a sniffer trace on one of the host showing the problem.
    Check if the client gets a response to the SYN.
    Check if the client can ping the CSS.
    Then verify that the SYN comes to the CSS.
    [capture a sniffer trace in front of CSS].
    Then use 'sho flows x.x.x.x' to see if a flow is created.
    Verify if the SYN is forwarded to a server.
    Could be the server not responding.
    What version do you run ?
    Gilles.

  • Unable to bulk copy data. - Random failure, running as SQL Agent with Admin rights and timeouts=0

    Hello,
    My setup is SQL Server 2012 (11.0.5522) and SSIS, but still running the 2008 R2 created packages. The server is Windows Server 2008 R2 with 32GBs of memory.
    I am running a control package which calls 4 packages at once to run simultaneously for performance reasons. It runs every day with issues, but maybe once a month I get the failure:
    'Unable to bulk copy data. You may need to run this package as an administrator.'
    The SQL Agent is setup as admin, it has access to the create global objects the source and destination databases are on the same server and the timeout is set to zero. Each package has the standard batch size and takes about 3-4 minutes to complete.
    Its not easily re-creatable and always runs fine when I re-start the package.
    Any help would be appreciated.
    Kind regards, Graham.

    see
    https://popbi.wordpress.com/2012/09/03/ssis-unable-to-bulk-copy-data-you-may-need-to-run-this-package-as-administrator/
    https://support.microsoft.com/kb/2216489?wa=wsignin1.0
    Please Mark This As Answer if it solved your issue
    Please Vote This As Helpful if it helps to solve your issue
    Visakh
    My Wiki User Page
    My MSDN Page
    My Personal Blog
    My Facebook Page

  • MDT installation and random failures

    We have MDT 2012 Update 1 x64 and we use MDT to install new machines. MDT is installed to virtual machine running Windows Server 2012 (hypervisor is also Windows Server 2012) We boot machines with PXE and start task sequence from there. Randomly MDT task
    sequence fails on some computers and few or more random applications wont install. We just start installation again and usually then it goes without errors. 
    When I open BDD.log it contains these errors:
    WARNING - unable to set working directory:  (-2147024832)
    ZTIApplications 11.3.2014 13:12:38
    0 (0x0000)
    Error installing application Microsoft Office 2010 ProPlus 32-bit ENG: The specified network name is no longer available.
    ZTIApplications 11.3.2014 13:12:38
    0 (0x0000)
    Any idea what could be causing this?

    Unable to set working directory suggests that the directory is not there. Does this happen all the time for this specific application, or random?
    If it always happens for this application, then I would say the directory is not accessible from the OS Clients, either it does not exist, or perhaps some permissions issue.
    If you only get the error, once in a while, then I would suggest you have some network problems. Some debugging may be necessary.
    Keith Garner - keithga.wordpress.com

  • Random failure to load classes

    I am working for a client and we are playing with two versions
    of Oracle Portal. One is running on Windows 2000 and its version
    1.0.2.2 and the other is prior to this version and was supplied
    to us by the client. The client supplied machine is running
    Solaris. Unfortunately the version supplied to us by the client
    and the version that we are forced to use appears to randomly
    not load classes in the classpath defined by the
    jserv.properties.
    It even goes so far as to load SOME classes in a given package
    but not all of them. It is very bizarre. There are no
    dependencies on JDK versions not being used by Portal. I need to
    be able to locate this problem and fix it. Does anyone know of
    any .jar files that might contain the updated classloaders from
    the newer version of portal that I could replace on the older
    version.
    All of these classes load correctly under 1.0.2.2. It is very
    bizarre. Additionally does anyone know if it is possible upgrade
    Portal without reinstalling Portal?
    Thanks in advance,
    Gabriel Harrison
    [email protected]

    Did you solve this problem?
    I have the same issue....
    Fabio

  • Random failure starting new board

    I have just bought an MSI K8T board with Athlon64 and 512MB RAM as a package deal, to replace my Piii/600, Abit-BH6 rig which went belly up. After assembly I discovered that my PSU didn't have the JPW 12V connector for the PSU, so I hustled out and bought a new one.
    Now I get start-up problems. I've stripped right back to the following:
    mobo, cpu, ram, video. I've connected front panel LEDs & switches, keyboard, monitor, PSU & d-bracket.
    When I boot I get a whole range of failures. Out of ten attempts I get...
    7 at processor init
    1 at early chipset init
    1 at the AMI BIOS System Configuration Screen display
    1 at faiing to boot of network (which actually had all four green LEDs on the d-bracket! woo-hoo.
    Once I had it try to boot off floppy when the drive was connected.
    Any suggestions..? It's driving me mad actually!
    Spec of what i'm using ought to be right here on my sig....

    Having computer problems and frustrations do that to us all .
    Just think you get some replys faster there than here..
    Good luck

  • Random failure of Applications

    Two questions:
    1) I'm suffering from random application crashes. Typically the "errors" occur on launch, and typically these are applications that worked fine perviously.
    2) Anybody know of a small utility that displays disk space usage graphically as a Pie chart or "glass half full?"
    Thanks

    1) Easiest thing to try is delete the associated .plist file in Users/~/Library/Preferences to restore the app to default settings. Files are generally named by com.developer.appname.plist
    2) HD/Applications/Utilities/ActivityMonitor
    If you want a dashboard widget, try iStat:http://www.islayer.com/apps/istatpro/
    Message was edited by: Mike N. (nahyunil)

  • K8N neo2 raid0 issues... random failure

    I'm running 2x80 hitachi sata II in raid0 on sata 3 and 4.
    Although everything works fine most of the time, sometimes (rarely) when I turn the pc on only one disk is recognized by the bios, causing a blue screen in windows boot (of course). I push the reset button and all becomes fine then. All the data is still there.
    I've checked both disks for surface errors, they're both ok.
    Nvraid bios is 4.81.
    Does anybody has this issue with ocasional raid0 failure? This is really strange... I don't believe it's due the disks.

    I hope you like my signature now, lol... :-)
    Well, the PSU is a quality one, I guess, and the two hitachi drives aren't 1 month old yet. I already scanned them several times and found no problems at all.
    Also, all my disks have a HDD cooler.
    It could really be a power cable issue, since there's really a lot of cables inside... but I only have two sata power cables, and they're both powering the two disks... :-/ Besides, the SATA power cables are independent of all the other cables (that is, nothing else is connected to the wires where they are connected).
    The only thing I did today was adding a HDD cooler for my Seagate IDE drive (the only one that didn't have one), after powering the pc up one of the Hitachi drives wasn't detected, I just reset the pc (didn't turned it off) and it was fine... Maybe my system is soooo lightning fast that the electricity wasn't fast enough to reach the 2nd drive on time... bahaha.        

  • 802.1x credentials failure with ACS 5.2

    Hi all,
    I recently tried to deploy an ACS appliance with version 5.2 installed on it for a customer.
    After setting up the WLC to use the ACS as a radius server, and successfully testing connection from the ACS to the AD,
    I get an error message " 12321 PEAP failed SSL/TLS handshake because the client rejected the ACS local-certificate" anytime a client tries to connect to the network.
    This is surprising because I had already generated a certficate for the ACS from a CA and binded the CA signed certificate with the ACS, I also specified the CA in the client machine's wireless properties and checked the "validate certificate" button.
    When I tried to connect using the internal identity store, the client was successfully authenticated without any certificate issues.
    Any help on this will be appreciated.

    Hi,
    Can you please send me the pdf output of the authentication for the user which passes authentication to the internal identity store and for the user account that fails when pointing to AD? Are you using an identity sequence or are you modifying the identity settings? If it is ok please attach it to your next post. If not please PM me and i can setup a share for you to upload the files to securely.
    thanks,
    Tarik

  • Possible Imminent Hard Drive Failure?

    First off I have an Early 2011 MacBook Pro running OSX Mountain Lion.  Avast version 7.0 is running as my anti-virus software with current definitions.  I'm a network administration student so I run 2 or 3 virtual machines simultaneously to replicate a domain environment for learning.  With that I decided I need space for all these operating systems plus my music and pics, so 10 Days ago I purchased a new Seagate 750GB HD Microcenter and upgraded to 8GB from 4GB of ram while I had the case open.  HD has worked like a champ and the computer has been faster for days until last night.  I was on Facebook and suddenly I got the spinning beach ball of death.  Giving it the mac 3 the mac version of the three-finger salute didn't help me so I went for the hard restart.  After that I got the blank grey screen.  I restarted with the option key and all I saw was my Windows Partition, but when I tried to boot to it I got a kernel panic.  So I went and got the OSX Mountain Lion thumb drive I made (didn't expect to be needing that so soon) and used disk utility. Disk Utility could not verify the disk and told me to format the disk and reinstall OSX.  Knowing that I have everything recently backed up with time machine and Winclone I went ahead and formatted and restored my time machine backup along with my Winclone backup.  (My attitude was, what were my options)
    During the restoration process of OSX I had zero problems, while doing the restoration of my Windows partition with Winclone I was watching the console log and saw this.....
    9/19/12 7:20:44.653 AM Winclone[460]: 19.62 percent completed
    9/19/12 7:20:57.674 AM Winclone[460]: 20.63 percent completed
    9/19/12 7:21:10.989 AM Winclone[460]: 21.64 percent completed
    9/19/12 7:21:13.000 AM kernel[0]: (default pager): [KERNEL]: ps_allocate_cluster - send HI_WAT_ALERT
    9/19/12 7:21:13.000 AM kernel[0]: macx_swapon SUCCESS
    9/19/12 7:21:25.018 AM Winclone[460]: 22.65 percent completed
    9/19/12 7:21:26.489 AM com.apple.launchd.peruser.501[368]: (com.apple.coreservices.appleid.authentication[479]) Exited: Killed: 9
    9/19/12 7:21:26.000 AM kernel[0]: memorystatus_thread: idle exiting pid 479 [AppleIDAuthAgent]
    9/19/12 7:21:30.768 AM Messages[379]: [Warning] Could not find transfer for guid: E1C93988-7FB6-46D9-949C-3D0F0A6A35FF
    9/19/12 7:21:30.768 AM Messages[379]: [Warning] Could not find transfer for guid: 2E3B4C2A-007C-4877-A34E-9F2DDE148B18
    9/19/12 7:21:30.768 AM Messages[379]: [Warning] Could not find transfer for guid: 3FDFED6A-9F52-4F19-ACAE-8802867CE8EB
    9/19/12 7:21:30.768 AM Messages[379]: [Warning] Could not find transfer for guid: 21B6D0B5-DD7E-4442-A2FD-23C5572EB46F
    9/19/12 7:21:31.848 AM com.apple.launchd[1]: (com.apple.iCloudHelper[468]) Exited: Killed: 9
    9/19/12 7:21:31.000 AM kernel[0]: memorystatus_thread: idle exiting pid 468 [com.apple.iCloud]
    9/19/12 7:21:33.241 AM com.apple.launchd.peruser.501[368]: (com.apple.CalendarAgent[465]) Exited: Killed: 9
    9/19/12 7:21:33.000 AM kernel[0]: memorystatus_thread: idle exiting pid 465 [CalendarAgent]
    9/19/12 7:21:34.662 AM com.apple.launchd.peruser.501[368]: (com.apple.pbs[444]) Exited: Killed: 9
    9/19/12 7:21:34.000 AM kernel[0]: memorystatus_thread: idle exiting pid 444 [pbs]
    9/19/12 7:21:35.822 AM com.apple.launchd[1]: (com.apple.audio.SandboxHelper[440]) Exited: Killed: 9
    9/19/12 7:21:35.000 AM kernel[0]: memorystatus_thread: idle exiting pid 440 [com.apple.audio.]
    9/19/12 7:21:37.244 AM com.apple.launchd[1]: (com.apple.xpcd.CA000000-0000-0000-0000-000000000000[439]) Exited: Killed: 9
    9/19/12 7:21:37.000 AM kernel[0]: memorystatus_thread: idle exiting pid 439 [xpcd]
    9/19/12 7:21:37.598 AM Winclone[460]: 23.66 percent completed
    I'm not a beginner Mac user but I'm not an all-knowing genius of the Mac either, but I know the GUID has something to do with the file structure of the hard drive.... Either way after I performed the restoration everything seems to be back to normal. The same fast computer I had before with no glitches and disk utility has even verified my disk on several occasions now and hasn't reported any issues.
    So here is my ultimate question?  What would cause this random failure in the first place if not the HD?  Is the forum's consensus that I should take the HD back anyways even though all checks are passing currently?  And, if not the HD how can I prevent this from happening again?  Let's face it, I'm a college student, I need my computer.  Luckily it died when I was going to bed and I could let it restore overnight.  Also, It's lucky for me that I didn't have class this morning and have no assignments pending that are immediately due so I can complete the windows restoration in the morning.
    I'll be looking forward to everyone's insight.

    Thanks for the info.
    I just bought Techtool Pro last week when I my hard drive directories got chewed up the first time. The box has a "Tiger Compatible" sticker on it so I imagine it's at least v4.0.4 on the CD. (Although I will check now)
    However, I think now the problem has progressed. Now the hard drive goes into a 1-2 minute cycling routine a couple times per day even if the computer is idle. Out of nowhere it starts up and it makes this repetitious reading/writing sound. It lasts 1-2 minutes and during this time the computer is hung-up (round-rainbow animated icon) and can't do anything, just have to wait it out.
    At this point I'm thinking of calling it quits and I'm just going to take the machine in while there is still a warranty on it as I'm really starting to believe it's drive failure and not a problem with software.

  • AD authentication against Shared Services failing randomly

    We're seeing random failures in AD authentication against Shared Services both via the Excel Addin and via Maxl scripts.
    SQL server (v 10.50.2500), Shared Services and OHS (v 11.1.2.2.303), and Essbase server (v11.1.2.2.104) are installed on the same physical box (16 cores, 192GB RAM) in a single-server configuration. It happens every few days at no fixed time and is resolved either by itself in a few hours, or by stopping and starting EPM services (Hyperion Foundation Services - Managed Server, OPMN service for Essbase, and OPMN service for OHS are stopped by running <Middleware_Home>\user_projects\epmsystem1\bin\stop.bat, and started by running start.bat).
    While the AD authentication is down, nobody is able to connect (via the Excel Add-in or Maxl scripts) using their AD accounts and get the following error - "Analytical Services user [AD_user1] Authentication Fails against the Shared Services Server with Error [EPMCSS-00301: Failed to authenticate user. Invalid credentials. Enter valid credentials.]". Native authentication works at all times (even when AD authentication fails).
    Although it seems to apply to an older version and to Planning/Workspace, we did look into "Error "EPMCSS-00301: Failed To Authenticate User. Invalid credentials" Intermittently When MSAD User Logs Into Workspace. (Doc ID 1389871.1)". But even after making the suggested changes, the problem persists. Any ideas what might be causing AD authentication to fail randomly like this? Below are some relevant portions of the logs -
    From ESSBASE_ODL.log -
    [2014-01-10T04:41:06.693-05:00] [ESSBASE0] [ERROR:32] [AGENT-1440] [] [ecid: 1388972435616,0] [tid: 6312] Essbase user [hyperion_admin] Authentication Fails against the Shared Services Server with Error [EPMCSS-00301: Failed to authenticate user. Invalid credentials. Enter valid credentials.]
    [2014-01-10T04:41:06.693-05:00] [ESSBASE0] [WARNING:1] [AGENT-1003] [] [ecid: 1388972435616,0] [tid: 6312] Error 1051440 processing request [Login] - disconnecting
    From SharedServices_Security_Client.log -
    [2014-01-10T04:39:00.490-05:00] [EPMCSS] [NOTIFICATION:16] [EPMCSS-20330] [oracle.EPMCSS.CSS] [tid: 149] [ecid: disabled,0] [SRC_CLASS: com.hyperion.css.cache.CacheManager] [SRC_METHOD: getCache] Cache refresh started asynchronously. This is a status messages. No action required. [2014-01-10T04:39:42.547-05:00] [EPMCSS] [ERROR] [EPMCSS-07047] [oracle.EPMCSS.CSS] [tid: 150] [ecid: disabled,0] [SRC_CLASS: com.hyperion.css.spi.util.jndi.pool.JNDIConnectionPool] [SRC_METHOD: getBorrowObject] Failed to get connection  from connection pool for user directory AD. Error executing query. adweilcom:389. Verify user directory configuration.
    [2014-01-10T04:39:42.547-05:00] [EPMCSS] [ERROR] [EPMCSS-09102] [oracle.EPMCSS.CSS] [tid: 150] [ecid: disabled,0] [SRC_CLASS: com.hyperion.css.spi.impl.msad.JNDIHelper] [SRC_METHOD: getURLContext] Failed to initialize group cache for MSAD user directory AD. Error connecting to url. ad.weil.com:389. Verify MSAD user directory configuration.
    [2014-01-10T04:39:42.547-05:00] [EPMCSS] [ERROR] [EPMCSS-00107] [oracle.EPMCSS.CSS] [tid: 150] [ecid: disabled,0] [SRC_CLASS: com.hyperion.css.spi.CSSManager] [SRC_METHOD: pingConfiguredProviders] Failed to refresh group cache. Some of configured user directories not initialized [AD]. Verify user directory configuration.
    [2014-01-10T04:39:42.547-05:00] [EPMCSS] [WARNING] [EPMCSS-10029] [oracle.EPMCSS.CSS] [tid: 150] [ecid: disabled,0] [SRC_CLASS: com.hyperion.css.cache.CacheThread] [SRC_METHOD: run] Exception while building asynchronous group cache for user directory. EPMCSS-00107: Failed to refresh group cache. Some of configured user directories not initialized [AD]. Verify user directory configuration.. Verify Shared Services security user directory configuration.
    [2014-01-10T04:40:24.605-05:00] [EPMCSS] [ERROR] [EPMCSS-00301] [oracle.EPMCSS.CSS] [tid: 149] [ecid: disabled,0] [SRC_CLASS: com.hyperion.css.spi.util.jndi.pool.JNDIConnectionPool] [SRC_METHOD: getBorrowObject] Failed to authenticate user. Invalid credentials. Enter valid credentials.
    [2014-01-10T04:40:24.605-05:00] [EPMCSS] [ERROR] [EPMCSS-00301] [oracle.EPMCSS.CSS] [tid: 149] [ecid: disabled,0] [SRC_CLASS: com.hyperion.css.spi.impl.msad.JNDIHelper] [SRC_METHOD: getURLContext] Failed to authenticate user. Invalid credentials. Enter valid credentials.
    [2014-01-10T04:41:06.662-05:00] [EPMCSS] [ERROR] [EPMCSS-00301] [oracle.EPMCSS.CSS] [tid: 149] [ecid: disabled,0] [SRC_CLASS: com.hyperion.css.spi.util.jndi.pool.JNDIConnectionPool] [SRC_METHOD: getBorrowObject] Failed to authenticate user. Invalid credentials. Enter valid credentials.
    [2014-01-10T04:41:06.662-05:00] [EPMCSS] [ERROR] [EPMCSS-00301] [oracle.EPMCSS.CSS] [tid: 149] [ecid: disabled,0] [SRC_CLASS: com.hyperion.css.spi.impl.msad.JNDIHelper] [SRC_METHOD: getURLContext] Failed to authenticate user. Invalid credentials. Enter valid credentials.
    [2014-01-10T04:41:06.693-05:00] [EPMCSS] [WARNING] [EPMCSS-10033] [oracle.EPMCSS.CSS] [tid: 149] [ecid: disabled,0] [SRC_CLASS: com.hyperion.css.facade.impl.CSSAbstractAuthenticator] [SRC_METHOD: authenticateUser] Skipping user directory {0} failed to communicate with server. {1}. No action required.
    [2014-01-10T04:41:06.693-05:00] [EPMCSS] [ERROR] [EPMCSS-00301] [oracle.EPMCSS.CSS] [tid: 149] [ecid: disabled,0] [SRC_CLASS: com.hyperion.css.facade.impl.CSSAbstractAuthenticator] [SRC_METHOD: authenticateUser] Failed to authenticate user. Invalid credentials. Enter valid credentials.
    From console~Essbase1~EssbaseAgent~AGENT~1.log -
    [Fri Jan 10 04:40:22 2014EPMCSS-00301: Failed to authenticate user. Invalid credentials. Enter valid credentials.               
    at com.hyperion.css.facade.impl.CSSAbstractAuthenticator.authenticateUser(CSSAbstractAuthenticator.java:658)
    at com.hyperion.css.facade.impl.CSSAPIAuthenticationImpl.authenticate(CSSAPIAuthenticationImpl.java:69)               
    at com.hyperion.css.facade.impl.CSSAPIImpl.authenticate(CSSAPIImpl.java:102)               
    at com.hyperion.css.facade.impl.CSSAPIImpl.login(CSSAPIImpl.java:794)               
    at com.hyperion.css.facade.CSSAPIFacade.login(CSSAPIFacade.java:776) ]
    Local/ESSBASE0///9180/Info(1042059)

    Server times are in sync. In fact, we see no such issues on the 9.3.1 environments (which are in the same server farm as the 11.1.2.2 environments).
    We're using the same MSAD configuration we have in the 9.3.1 environments as follows -
    Directory Server: Microsoft
    Name: AD Host Name: ad.mycompany.com
    Port: 389
    SSL Enabled: unchecked
    Base DN: DC=ad,DC=mycompany,DC=com
    ID Attribute: objectguid (greyed)
    Maximum Size: 200
    Trusted: checked
    Anonymous Bind: unchecked
    User DN: ad\hyperion_admin
    Append Base DN: unchecked
    User RDN: blank
    Login Attribute: cn
    First name Attribute: givenName
    Last name Attribute: sn
    Email Attribute: mail
    Object Class: person,organizationalPerson,user
    Support Groups: checked
    Group RDN: OU=groups
    Name Attribute: CN
    object class: group?member
    I also tried disabling AD groups (Support Groups = unchecked), but I still see a random AD authentication failure. Below are logs based on automated retrievals using an AD account at 14:37, 17:37, 20:37 and 21:40 today. The first 2 worked fine, the 3rd failed, the fourth worked fine again. From SharedServices_Security_Client.log -
    [2014-01-11T14:37:00.574-05:00] [EPMCSS] [NOTIFICATION:16] [EPMCSS-20330] [oracle.EPMCSS.CSS] [tid: 42] [ecid: disabled,0] [SRC_CLASS: com.hyperion.css.cache.CacheManager] [SRC_METHOD: getCache] Cache refresh started asynchronously. This is a status messages. No action required.
    [2014-01-11T14:37:00.917-05:00] [EPMCSS] [NOTIFICATION:16] [EPMCSS-20005] [oracle.EPMCSS.CSS] [tid: 43] [ecid: disabled,0] [SRC_CLASS: com.hyperion.css.cache.CacheThread] [SRC_METHOD: buildCache] Asynchronously started user directory cache building for user directory Native Directory. Status message. No action required.
    [2014-01-11T14:37:00.917-05:00] [EPMCSS] [NOTIFICATION:16] [EPMCSS-20005] [oracle.EPMCSS.CSS] [tid: 43] [ecid: disabled,0] [SRC_CLASS: com.hyperion.css.cache.CacheThread] [SRC_METHOD: buildCache] Asynchronously started user directory cache building for user directory AD. Status message. No action required.
    [2014-01-11T14:37:00.917-05:00] [EPMCSS] [NOTIFICATION:16] [EPMCSS-20008] [oracle.EPMCSS.CSS] [tid: 44] [ecid: disabled,0] [SRC_CLASS: com.hyperion.css.spi.impl.msad.MSADProvider] [SRC_METHOD: createCache] Group support is disabled for MSAD user directory AD returning empty cache map. Status message. No action required.
    [2014-01-11T14:37:00.917-05:00] [EPMCSS] [NOTIFICATION:16] [EPMCSS-20007] [oracle.EPMCSS.CSS] [tid: 44] [ecid: disabled,0] [SRC_CLASS: com.hyperion.css.cache.ProviderCacheThread] [SRC_METHOD: run] Group cache completed for user directory AD and size of group cache is 0. Status message. No action required.
    [2014-01-11T14:37:00.917-05:00] [EPMCSS] [NOTIFICATION:16] [EPMCSS-20007] [oracle.EPMCSS.CSS] [tid: 45] [ecid: disabled,0] [SRC_CLASS: com.hyperion.css.cache.ProviderCacheThread] [SRC_METHOD: run] Group cache completed for user directory Native Directory and size of group cache is 19. Status message. No action required.
    [2014-01-11T14:37:00.917-05:00] [EPMCSS] [NOTIFICATION:16] [EPMCSS-20331] [oracle.EPMCSS.CSS] [tid: 43] [ecid: disabled,0] [SRC_CLASS: com.hyperion.css.cache.CacheThread] [SRC_METHOD: buildCache] Cache building is done for the providers, now started unifying the cache. This is a status messages. No action required.
    [2014-01-11T14:37:01.151-05:00] [EPMCSS] [NOTIFICATION:16] [EPMCSS-20332] [oracle.EPMCSS.CSS] [tid: 43] [ecid: disabled,0] [SRC_CLASS: com.hyperion.css.cache.CacheThread] [SRC_METHOD: buildCache] Unify cache done and cache object set to the cache manager. This is a status messages. No action required.
    [2014-01-11T17:37:00.752-05:00] [EPMCSS] [NOTIFICATION:16] [EPMCSS-20330] [oracle.EPMCSS.CSS] [tid: 46] [ecid: disabled,0] [SRC_CLASS: com.hyperion.css.cache.CacheManager] [SRC_METHOD: getCache] Cache refresh started asynchronously. This is a status messages. No action required.
    [2014-01-11T17:37:01.174-05:00] [EPMCSS] [NOTIFICATION:16] [EPMCSS-20005] [oracle.EPMCSS.CSS] [tid: 47] [ecid: disabled,0] [SRC_CLASS: com.hyperion.css.cache.CacheThread] [SRC_METHOD: buildCache] Asynchronously started user directory cache building for user directory Native Directory. Status message. No action required.
    [2014-01-11T17:37:01.174-05:00] [EPMCSS] [NOTIFICATION:16] [EPMCSS-20005] [oracle.EPMCSS.CSS] [tid: 47] [ecid: disabled,0] [SRC_CLASS: com.hyperion.css.cache.CacheThread] [SRC_METHOD: buildCache] Asynchronously started user directory cache building for user directory AD. Status message. No action required.
    [2014-01-11T17:37:01.174-05:00] [EPMCSS] [NOTIFICATION:16] [EPMCSS-20008] [oracle.EPMCSS.CSS] [tid: 48] [ecid: disabled,0] [SRC_CLASS: com.hyperion.css.spi.impl.msad.MSADProvider] [SRC_METHOD: createCache] Group support is disabled for MSAD user directory AD returning empty cache map. Status message. No action required.
    [2014-01-11T17:37:01.174-05:00] [EPMCSS] [NOTIFICATION:16] [EPMCSS-20007] [oracle.EPMCSS.CSS] [tid: 48] [ecid: disabled,0] [SRC_CLASS: com.hyperion.css.cache.ProviderCacheThread] [SRC_METHOD: run] Group cache completed for user directory AD and size of group cache is 0. Status message. No action required.
    [2014-01-11T17:37:01.174-05:00] [EPMCSS] [NOTIFICATION:16] [EPMCSS-20007] [oracle.EPMCSS.CSS] [tid: 49] [ecid: disabled,0] [SRC_CLASS: com.hyperion.css.cache.ProviderCacheThread] [SRC_METHOD: run] Group cache completed for user directory Native Directory and size of group cache is 19. Status message. No action required.
    [2014-01-11T17:37:01.174-05:00] [EPMCSS] [NOTIFICATION:16] [EPMCSS-20331] [oracle.EPMCSS.CSS] [tid: 47] [ecid: disabled,0] [SRC_CLASS: com.hyperion.css.cache.CacheThread] [SRC_METHOD: buildCache] Cache building is done for the providers, now started unifying the cache. This is a status messages. No action required.
    [2014-01-11T17:37:01.361-05:00] [EPMCSS] [NOTIFICATION:16] [EPMCSS-20332] [oracle.EPMCSS.CSS] [tid: 47] [ecid: disabled,0] [SRC_CLASS: com.hyperion.css.cache.CacheThread] [SRC_METHOD: buildCache] Unify cache done and cache object set to the cache manager. This is a status messages. No action required.
    [2014-01-11T20:37:00.634-05:00] [EPMCSS] [NOTIFICATION:16] [EPMCSS-20330] [oracle.EPMCSS.CSS] [tid: 50] [ecid: disabled,0] [SRC_CLASS: com.hyperion.css.cache.CacheManager] [SRC_METHOD: getCache] Cache refresh started asynchronously. This is a status messages. No action required.
    [2014-01-11T20:37:42.707-05:00] [EPMCSS] [ERROR] [EPMCSS-00301] [oracle.EPMCSS.CSS] [tid: 50] [ecid: disabled,0] [SRC_CLASS: com.hyperion.css.spi.util.jndi.pool.JNDIConnectionPool] [SRC_METHOD: getBorrowObject] Failed to authenticate user. Invalid credentials. Enter valid credentials.
    [2014-01-11T20:37:42.707-05:00] [EPMCSS] [ERROR] [EPMCSS-00301] [oracle.EPMCSS.CSS] [tid: 50] [ecid: disabled,0] [SRC_CLASS: com.hyperion.css.spi.impl.msad.JNDIHelper] [SRC_METHOD: getURLContext] Failed to authenticate user. Invalid credentials. Enter valid credentials.
    [2014-01-11T20:38:24.748-05:00] [EPMCSS] [ERROR] [EPMCSS-07047] [oracle.EPMCSS.CSS] [tid: 51] [ecid: disabled,0] [SRC_CLASS: com.hyperion.css.spi.util.jndi.pool.JNDIConnectionPool] [SRC_METHOD: getBorrowObject] Failed to get connection  from connection pool for user directory AD. Error executing query. adweilcom:389. Verify user directory configuration.
    [2014-01-11T20:38:24.748-05:00] [EPMCSS] [ERROR] [EPMCSS-09102] [oracle.EPMCSS.CSS] [tid: 51] [ecid: disabled,0] [SRC_CLASS: com.hyperion.css.spi.impl.msad.JNDIHelper] [SRC_METHOD: getURLContext] Failed to initialize group cache for MSAD user directory AD. Error connecting to url . ad.weil.com:389. Verify MSAD user directory configuration.
    [2014-01-11T20:38:24.748-05:00] [EPMCSS] [ERROR] [EPMCSS-00107] [oracle.EPMCSS.CSS] [tid: 51] [ecid: disabled,0] [SRC_CLASS: com.hyperion.css.spi.CSSManager] [SRC_METHOD: pingConfiguredProviders] Failed to refresh group cache. Some of configured user directories not initialized [AD]. Verify user directory configuration.
    [2014-01-11T20:38:24.748-05:00] [EPMCSS] [WARNING] [EPMCSS-10029] [oracle.EPMCSS.CSS] [tid: 51] [ecid: disabled,0] [SRC_CLASS: com.hyperion.css.cache.CacheThread] [SRC_METHOD: run] Exception while building asynchronous group cache for user directory. EPMCSS-00107: Failed to refresh group cache. Some of configured user directories not initialized [AD]. Verify user directory configuration.. Verify Shared Services security user directory configuration..
    [2014-01-11T20:39:06.806-05:00] [EPMCSS] [ERROR] [EPMCSS-00301] [oracle.EPMCSS.CSS] [tid: 50] [ecid: disabled,0] [SRC_CLASS: com.hyperion.css.spi.util.jndi.pool.JNDIConnectionPool] [SRC_METHOD: getBorrowObject] Failed to authenticate user. Invalid credentials. Enter valid credentials.
    [2014-01-11T20:39:06.806-05:00] [EPMCSS] [ERROR] [EPMCSS-00301] [oracle.EPMCSS.CSS] [tid: 50] [ecid: disabled,0] [SRC_CLASS: com.hyperion.css.spi.impl.msad.JNDIHelper] [SRC_METHOD: getURLContext] Failed to authenticate user. Invalid credentials. Enter valid credentials.
    [2014-01-11T20:39:06.806-05:00] [EPMCSS] [WARNING] [EPMCSS-10033] [oracle.EPMCSS.CSS] [tid: 50] [ecid: disabled,0] [SRC_CLASS: com.hyperion.css.facade.impl.CSSAbstractAuthenticator] [SRC_METHOD: authenticateUser] Skipping user directory {0} failed to communicate with server. {1}. No action required.
    [2014-01-11T20:39:06.806-05:00] [EPMCSS] [ERROR] [EPMCSS-00301] [oracle.EPMCSS.CSS] [tid: 50] [ecid: disabled,0] [SRC_CLASS: com.hyperion.css.facade.impl.CSSAbstractAuthenticator] [SRC_METHOD: authenticateUser] Failed to authenticate user. Invalid credentials. Enter valid credentials.
    [2014-01-11T21:40:41.799-05:00] [EPMCSS] [NOTIFICATION:16] [EPMCSS-20330] [oracle.EPMCSS.CSS] [tid: 52] [ecid: disabled,0] [SRC_CLASS: com.hyperion.css.cache.CacheManager] [SRC_METHOD: getCache] Cache refresh started asynchronously. This is a status messages. No action required.
    [2014-01-11T21:40:41.986-05:00] [EPMCSS] [NOTIFICATION:16] [EPMCSS-20005] [oracle.EPMCSS.CSS] [tid: 53] [ecid: disabled,0] [SRC_CLASS: com.hyperion.css.cache.CacheThread] [SRC_METHOD: buildCache] Asynchronously started user directory cache building for user directory Native Directory. Status message. No action required.
    [2014-01-11T21:40:41.986-05:00] [EPMCSS] [NOTIFICATION:16] [EPMCSS-20005] [oracle.EPMCSS.CSS] [tid: 53] [ecid: disabled,0] [SRC_CLASS: com.hyperion.css.cache.CacheThread] [SRC_METHOD: buildCache] Asynchronously started user directory cache building for user directory AD. Status message. No action required.
    [2014-01-11T21:40:41.986-05:00] [EPMCSS] [NOTIFICATION:16] [EPMCSS-20008] [oracle.EPMCSS.CSS] [tid: 54] [ecid: disabled,0] [SRC_CLASS: com.hyperion.css.spi.impl.msad.MSADProvider] [SRC_METHOD: createCache] Group support is disabled for MSAD user directory AD returning empty cache map. Status message. No action required.
    [2014-01-11T21:40:41.986-05:00] [EPMCSS] [NOTIFICATION:16] [EPMCSS-20007] [oracle.EPMCSS.CSS] [tid: 54] [ecid: disabled,0] [SRC_CLASS: com.hyperion.css.cache.ProviderCacheThread] [SRC_METHOD: run] Group cache completed for user directory AD and size of group cache is 0. Status message. No action required.
    [2014-01-11T21:40:42.002-05:00] [EPMCSS] [NOTIFICATION:16] [EPMCSS-20007] [oracle.EPMCSS.CSS] [tid: 55] [ecid: disabled,0] [SRC_CLASS: com.hyperion.css.cache.ProviderCacheThread] [SRC_METHOD: run] Group cache completed for user directory Native Directory and size of group cache is 19. Status message. No action required.
    [2014-01-11T21:40:42.002-05:00] [EPMCSS] [NOTIFICATION:16] [EPMCSS-20331] [oracle.EPMCSS.CSS] [tid: 53] [ecid: disabled,0] [SRC_CLASS: com.hyperion.css.cache.CacheThread] [SRC_METHOD: buildCache] Cache building is done for the providers, now started unifying the cache. This is a status messages. No action required.
    [2014-01-11T21:40:42.080-05:00] [EPMCSS] [NOTIFICATION:16] [EPMCSS-20332] [oracle.EPMCSS.CSS] [tid: 53] [ecid: disabled,0] [SRC_CLASS: com.hyperion.css.cache.CacheThread] [SRC_METHOD: buildCache] Unify cache done and cache object set to the cache manager. This is a status messages. No action required.

Maybe you are looking for

  • Is there a way to create different diskgroups in exadata?

    We have a need to have some other diskgroups other than +DATA and +RECO. How do we do that? Exadata version is x3. Thanks

  • How to load a jpg into my movie ???

    I want to load an image stored on my pc into my swf file. i know that i can use the loadMovie() method. but i didnt know how to enter the url of the target file. For example i have the file in the following directory - C:\Documents and Settings\Admin

  • A way to get information about colored points from a graph?

    Two questions: 1. Is there a possibility to know whether a specific point is already plotted in a graph and what is the color of that specific point? 2. Is there a way to use the legend in order to show what each colored point represents (not lines,

  • Repaint() in panel

    I have overridded the update method in a class I extended from panel. I first call my paint method then the standard paint method, like so: public void update(Graphics g) Dimension d = getSize(); // clear the exposed area g.setColor(Color.black); g.f

  • After Automatic Software Update I Can't Attach Photos in Hotmail via Safari

    Suddenly after my iMac update the software on my computer, I suddenly can't attach any photos in Hotmail when I launch Safari. I have been a Hotmail user for 10 years now and never have had this problem before. This has been my primary account for th