Cannot Add ADFS 2012 R2 to Existing Farm

In the process of building ADFS into our AD. Have 2008 R2 DCs so we added a 2012 R2 DC to take advantage of gMSA. Have two 2012 R2 servers to function in HA/NLB array for ADFS 3.0. Installation of first server in farm has been successful and allowed wizard
to create gMSA user after waiting 10 hours for results of Add-KDSRootKey to replicate. Although installation procedure failed to add local IP address to cert bindings that was easily remedied with netsh followed by "http add sslcert ipport ...."
The problem now comes in adding a server to the farm. Prerequisite fails with "There were no SPNs set on the following service account..." and "The user name or password is incorrect" and a few other errors. Packet capture shows Kerberos
pre-authentication failure. To work around this, "nltest /SC_RESET:domain-name\2012R2-DC was run to force secure channel on host to point to Server 2012 R2 DC. Still the error. Wait and wait and wait.. Still the error. The SPN is clearly and properly
set on the gMSA account.
What to do? Anyone encounter this or could point us in the right direction to get a second ADFS server into the farm?

Hi Peter,
How have you configured the SPN?
Here are some references below I suggest you refer to:
SPN settings in a ADFS 3.0 lab setup
http://social.technet.microsoft.com/Forums/windowsserver/en-US/70e7dcb9-32aa-4ae0-85c0-9ce06ccc6777/spn-settings-in-a-adfs-30-lab-setup?forum=winserverDS
SetSPN for ADFS
http://social.technet.microsoft.com/Forums/en-US/1c070f25-cb93-4198-92a9-a76588cba169/setspn-for-adfs?forum=winserverDS
AD FS 2.0: How to Configure the SPN (servicePrincipalName) for the Service Account
http://social.technet.microsoft.com/wiki/contents/articles/1427.ad-fs-2-0-how-to-configure-the-spn-serviceprincipalname-for-the-service-account.aspx
Can not find SPNs set on a service account when installing AFDS 2.0
http://social.msdn.microsoft.com/Forums/vstudio/en-US/3fcedb1b-1076-4475-bd74-8301b559efb3/can-not-find-spns-set-on-a-service-account-when-installing-afds-20?forum=Geneva
Best Regards,
Amy

Similar Messages

  • Cannot add new contact or edit existing one

    Cannot add new contact or edit existing one. TH GSM, curve 8900, OS v5.0.01067, file free none ,battery pull didn't fix the problem, applications Google maps 3.0.2, whatsapp 2.6.2177. Device even freezes when trying to add or edit . Thanks

    I am having the exact same problem!!  I hope we get an answer.

  • Cannot add new selectors or edit existing CSS file with my Mac

    I have just subscibed to Dreamweaver CC and I cannot add new selectors or edit the exisiting "main" css that comes with the tutorial. When asked to add selector a box appears but when I press enter/return twice it disappears. Also there is no option to edit existing properties. for example, to change a font color I pick color but there is no enter or "OK" option. I'm very puzzled and stuck.

    The trial version of Dreamweaver is fully functional. The only limitation is that it stops working after 30 days. If you're having problems with getting the software to work correctly, it might be a good idea to try posting a question in the Downloading, Installing, Setting Up forum, mentioning the fact that you've already posted here (otherwise, they might just transfer you back to this or one of the other Dreamweaver forums).
    If you can't make changes to files, it might have something to do with permissions or the user account that you've logged onto the computer with.
    When asking for help in the other forum, mention your operating system, and which version you're using. The problem might be related to your computer setup.

  • Cannot add a new server in existing server pool

    Hi,
    I am trying to add a new server into an existing server pool.
    I have the same agent password, the same root password (i don't think is important).
    It disovers the server and is on unassigned Servers.
    When trying to add into existing server pool it fail with:
    Job Internal Error (Operation)com.oracle.ovm.mgr.api.exception.FailedOperationException: OVMAPI_4010E Attempt to send command: dispatch to server: vmsibm2 failed. OVMAPI_4004E Server Failed Command: dispatch https://?uname?:[email protected]:8899/api/2 configure_server_for_cluster lun /dev/mapper/35000144f85151729 0004fb0000050000c696b251dc81a087 , Status: org.apache.xmlrpc.XmlRpcException: exceptions.OSError:[Errno 2] No such file or directory
    Any ideeas?
    Regards
    Nicolae

    Hi,
    I can see your point...
    From my error :Server Failed Command: dispatch https://?uname?:[email protected]:8899/api/2 configure_server_for_cluster lun /dev/mapper/35000144f85151729 0004fb0000050000c696b251dc81a087 , Status: org.apache.xmlrpc.XmlRpcException: exceptions.OSError:[Errno 2] No such file or directory
    /dev/mapper/35000144f85151729 is the path where the server pool uses for it's own...
    and
    0004fb0000050000c696b251dc81a087 is the Pool file System...
    On storage menu, at SAN Servers - Unmanaged iSCSI Storage Array - where I see my storage wich is with iSCSI at Add/Remove Admin Servers I added this new server.
    Also I went to Rescan Physical Discks for my new server.
    When I go with putty on my server and run
    df -h
    I don't see any storage...
    I belive I missed one step but I can't find wich one...
    Regards
    Nicolae

  • I cannot add any bookmarks to my existing ones with the new 30.0 firefox.

    I updated to firefox 30.0. Now, I can't create any new bookmarks. I've clicked on the little star icon and it bops over to the clipboard icon. However, when I check for unsorted bookmarks it does not appear. I have checked in the bookmarks button at the top of the page and it shows up nowhere. I've never had a problem with bookmarks before and have sorted them into many folders. I have tried several things, and no matter what I have done I cannot create a new bookmark. I reset firefox to default, but this still did not fix my bookmark problem. I tried erasing a few bookmarks to make room, but that didn't help. I tried dragging the address straight into my folders. This used to work on the old version. Now, no matter what I do I cannot create a new bookmark. This is very frustrating. I wish I hadn't updated. My MacBook Air is less than a year old and uses OS X.

    You can check for problems with the <b>places.sqlite</b> database file in the Firefox profile folder.
    *http://kb.mozillazine.org/Bookmarks_history_and_toolbar_buttons_not_working_-_Firefox
    *https://support.mozilla.org/kb/Bookmarks+not+saved#w_fix-the-bookmarks-file
    *Places Maintenance https://addons.mozilla.org/firefox/addon/places-maintenance/
    You can use this button to go to the currently used Firefox profile folder:
    *Help > Troubleshooting Information > Profile Directory: Show Folder (Linux: Open Directory; Mac: Show in Finder)

  • Cannot Add File Share to (any) File Server Role of a Cluster in Windows Server 2012

    Cannot Add File Share to (any) File Server Role of a Cluster in Windows Server 2012...
    Get this message in the Operational Log in "FileServices-ServerManager-EventProvider" section of MS-Windows Eventlogs:
    Exception: Caught exception Microsoft.Management.Infrastructure.CimException: The xsi:type attribute (MSCluster_Property_Resource_Network_Name) does not identify an existing class.
       at Microsoft.Management.Infrastructure.Internal.Operations.CimSyncEnumeratorBase`1.MoveNext(Boolean discardResultsAndErrors)
       at Microsoft.Management.Infrastructure.Internal.Operations.CimSyncEnumeratorBase`1.MoveNext()
       at Microsoft.FileServer.Management.Plugin.Services.FSCimSession.PerformQuery(String cimNamespace, String queryString)
       at Microsoft.FileServer.Management.Plugin.Services.ClusterEnumerator.BuildNodes(ICimSession session, ClusterRole scopeType, String query, IDictionary`2 groupNameToTypeMap)
       at Microsoft.FileServer.Management.Plugin.Services.ClusterEnumerator.GetClusterClientAccessPointNames(ICimSession session, IDictionary`2 groupNameToTypeMap)
       at Microsoft.FileServer.Management.Plugin.Services.ClusterEnumerator.RetrieveClusterConnections(ComputerName serverName, ClusterMemberTypes memberTypeToQuery)
    Thanks for help...(everything else works fine in other type of cluster roles).
    Thomas.

    This issue also happens in fresh Windows 2012R2 installations, not just upgrades from 2008R2!
    I have the issue where I cannot modify any settings on SMB shares.  Here is the stacktrace.  It appears to be WMI related.
    Error: ERROR: Task 'TEST.xxxxxxx.COM-ClusterStorage$-SmbShareUpdate-46bcabf6-1dd4-4a48-a525-5e5d374596c7' has failed: Microsoft.FileServer.Management.Plugin.FSACException: Error occurred while updating an SMB share: The requested operation is not supported.
    ---> Microsoft.Management.Infrastructure.CimException: The requested operation is not supported.
       at Microsoft.Management.Infrastructure.Internal.Operations.CimSyncEnumeratorBase`1.MoveNext()
       at System.Linq.Enumerable.SingleOrDefault[TSource](IEnumerable`1 source)
       at Microsoft.Management.Infrastructure.CimSession.ModifyInstance(String namespaceName, CimInstance instance, CimOperationOptions options)
       at Microsoft.FileServer.Management.Plugin.Services.FSCimSession.ModifyInstance(ICimInstance instance)
       at Microsoft.FileServer.Management.Plugin.Services.FSCimSession.ModifyInstance(ICimInstance instance, IEnumerable`1 propertiesWithKeys)
       at Microsoft.FileServer.Management.Plugin.Providers.WmiUpdateTaskBase.DoUpdateInstance(ICimSession session, ICimInstance instance)
       at Microsoft.FileServer.Management.Plugin.Providers.WmiUpdateTaskBase.DoWork(Object sender, DoWorkEventArgs e)
       --- End of inner exception stack trace ---
       at Microsoft.FileServer.Management.Plugin.Providers.WmiUpdateTaskBase.DoWork(Object sender, DoWorkEventArgs e)
       at System.ComponentModel.BackgroundWorker.WorkerThreadStart(Object argument)

  • RDS 2012 R2 cannot add 3rd party (parent domain) licensing server

    Hi,
    I have a RDS 2012 R2 farm and i cannot add a 3rd party licensing server that is in a parent domain (forest root domain - hosted by our corp HQ). I will edit deployment properties for the deployment in the first CB server to add a licensing server in per
    user mode. Seemes to work, however no licenses are given to SH servers. Have made GPO aswell to explicitly specify licensing server and mode, however i think this should not be neccessary.
    Any ideas?
    This posting is provided "AS IS" with no warranties or guarantees and confers no rights

    Hi,
    Thank you for posting in Windows Server Forum.
    1. In Server Manager -- RDS -- Overview -- Tasks -- Edit Deployment Properties -- RD Licensing tab, please make sure that the Licensing mode is set to match the type of licenses you purchased, and that the FQDN of your RD Licensing server is listed.
    2. In Server Manager -- RDS -- Collections -- <your collection> -- Host Servers, please make sure that your RDSH server is listed.  If you have more than one server with the RDSH Role Service in your deployment make sure that all of them are
    listed.  If they are not you may click Tasks -- Add RD Session Host Servers (make sure the servers are part of the Server Manager server pool prior to this).
    3. On Server 1, please open an Administrator PowerShell prompt and enter the following command:
    Add-WindowsFeature RDS-Licensing-UI
    4. After the above powershell command completes you should be able to open RD Licensing Manager (licmgr.exe) on Server 1 if you need to.  Please note that it is more important to have the licensing configured properly in deployment properties and your
    RDSH servers part of a collection than it is to be able to open RD Licensing Manager on both of your servers. 
    (Above one quoted from beneath thread)
    Source:
    RDS 2012 Can't add a licensing server
    In addition, check below article.
    RD Licensing Configuration on Windows Server 2012
    Hope it helps!
    Thanks.
    Dharmesh Solanki

  • Cannot add images to existing collection

    I cannot add images to an existing collection. When I am in the Library/navigator modus, and I grab one or more images, I can not drag them to an existing library. I do can however, drag an entire collection to a collection set, but that is not what I want.
    Anyone any idea?
    Lightroom 3.4.1 & windows 7
    gr,
    René

    René,
    I can think of three possibilities:
    --You can't drag images to smart collections. Only regular collections.
    --You can't drag an image to a collection set.
    --You have to drag by the image, not the border.
    Hal

  • Disks not avialable and cannot add new disks to existing pools

    I have a few disks that are RAW and I want to add them to existing pools.  However, only 1 disk shows up as a Primordial disk and the others do not.   I cannot add these drives to a new volume and when I try to add any drive to an existing
    pool, the add disk option is greyed out.  I have search everywhere to resolve this but no luck.
    What is interesting is one of the drives that shows available for a volume is the drive I have associated to backing up the OS on the server itself and is initialized, i.e. not RAW.

    Hi,
    Please try to run the following commands in PowerShell to obtain the information about disks:
    Get-physicaldisk
    Get-disk
    In additional, the physical disk added to a storage pool must be 4GB or larger. If the space is less 4GB, the disk will not appear in the storage pool window.
    For more information, please refer to the thread below:
    Storage Pool in WS2012
    http://social.technet.microsoft.com/Forums/windowsserver/en-US/d230ef80-8791-4eaf-84b5-a41b8f7fef10/storage-pool-in-ws2012?forum=winserver8gen
    Best Regards,
    Mandy 
    If you have any feedback on our support, please click
    here .
    We
    are trying to better understand customer views on social support experience, so your participation in this
    interview project would be greatly appreciated if you have time.
    Thanks for helping make community forums a great place.

  • My ichat will let me send video chats requests, but it will not let me accept them. What should i do? Also, sometimes it tells me i cannot add a 2nd or 3rd person to an existing chat because it is connected to AOL's relay servers. What does this mean?

    my ichat will let me send video chats requests, but it will not let me accept them. What should i do? Also, sometimes it tells me i cannot add a 2nd or 3rd person to an existing chat because it is connected to AOL's relay servers. What does this mean?

    Unfortunately, most of my advice is in the "hindsight is 20-20" category.
    First off, I would never have purchased the peripheral accessories until the 14 day return period had expired. Second, you learned the hard way what the "14 days" really means.
    Too bad you didn't do any homework, reading this and other forums and tech sites. Even word of mouth from others. That, more than anything could have steered you towards different phone choices from the get-go and I will leave that there with no further comment other than to say most of the issues you described have been discussed in this forum, ad nauseam.
    Once you got into the refurbished phone exchanges, that is where things really went haywire. What someone tells you over the phone is a sketchy proposition, and when it comes down to it, it's your word against theirs.
    I think Verizon tried to make it right, though. Remember, they don't make the phones. Don't throw the baby out with the bathwater.
    You stated yourself you were a satisfied Verizon customer before this. Had the first two phones performed as they should, you would still be a satisfied Verizon customer.
    Doubt any of that will make you any happier, but after you went through the effort of writing such a long post, I thought I'd try.

  • 'itunes cannot add any songs to the ipod 'bla bla' because no songs exist in the playlist 'leo tolstoy- etc' can be copied to this ipod' .

    When trying to copy an audio book that I have purchased in itunes (which I have done for years) a messge has suddenly started coming up saying 'Itunes cannot add any songs to the ipod 'bla bla' because no songs exist in the playlist name of book' can be copied to this ipod' ' It worked a couple of weeks ago when I copied half of a book and it has worked for the past few years, but suddenly now none of my ipods will work with audio book yet they will with songs in my playlists. Infact it seems as though my audio books have gone yet they are there in print ...aghhh this is so frustrating.. please can anyone help. thank you

    Was there an answer??!!! I have the same issue and its driving me nuts to the point I want to leave apple forever! Itunes *****!!

  • My bookmarks are not only gone, I cannot add a new one or import my existing ones from presaved files. I have checked my profiles and I have only the default one.

    My bookmarks disappeared just before I left for Christmas. Not having time to deal with it then, I found a copy of html bookmarks that seemed to be current and made a copy of it. This copy starts up Firefox and opens in a window. I can use it to get to my sites. However I cannot import it to my bookmarks. I also cannot add a bookmark in real time. Using your forum, I decided to add the plug-in Torbutton. It did not help and something keeps turning it off. I even tried to import my old IE bookmarks since they have not changed a lot. Everything acts like it has worked but nothing shows up.

    No, I see the three areas at the bottom of the Bookmark area that you refer to, but that also highlights an issue.  When I want to save a story to my Reading List and click on Share then "Add to Reading List" then go back to look at what is stored in the Reading List, my recently-saved item is not there.
    I looked thru the History tab and the Reading List tab and have been in the Bookmark tab.  But even when I Save a Bookmark, that newly-saved Bookmark does not show up in the Bookmark area.
    But then again, the next day (and actually just in the last half-hour) all of the functionality came back.  When I look at the Bookmarks, suddenly, again, all of the Bookmarks that are on my Safari browser on my iMac are now there, and I can now Save a Bookmark.
    It keeps coming in and out and that is what is driving me a little nuts.
    Thanks.

  • Cannot add apps to iTunes Wish List for my ipod

    When using iTunes on my Macbook, I cannot add apps (for ipod, ipad, etc. NOT for computer) to my Wish List.  When I try, a pop up error alert box says that "Your request is temporarily unable to be processed., to try again later."  The odd thing is that I can add music albums to my Wish List.  I am not trying to add previously bought apps, but new ones that I find that I might want later.  I used to be able to do this, but not as of recently.  I even updated my Itunes to see if that would help.  No effect.  Is it my wifi network,?  Any ideas of how to remedy this?

    thanks.  I opened iTunes this morning and miraculously my wish list seems to be working.   i see one app i had added to be downloaded.  I am able to remove songs from wish list and add songs and preview all.
    last i heard from the customer service person was that they referred the issue to a senior level support person.  this after i sent them several screen shots of my wish list and the error about unable to add to existing wish list because ittem was already there.
    I have not heard from them that my issue is resolved.  I will give them a day or so to get back to me to confirm they fixed the problelm.
    very strange.  at least they acknowledged the problem did indeed exist as they referred me to the online user forum for possible solutions.  I indicated the problem persisted as early as June 2010 and as late as Jan 2012. and I had upgraded to ver 10.5.3 as well as remove and re-install even AFTER they kept telling me they removed my wishlist.

  • Cannot add apps to iTunes wish list

    When using iTunes on my Macbook, I cannot add apps (for ipod, ipad, etc. NOT for computer) to my Wish List.  When I try, a pop up error alert box says that "Your request is temporarily unable to be processed., to try again later."  The odd thing is that I can add music albums to my Wish List.  I am not trying to add previously bought apps, but new ones that I find that I might want later.  I used to be able to do this, but not as of recently.  I even updated my Itunes to see if that would help.  No effect.  Is it my wifi network,?  Any ideas of how to remedy this?

    thanks.  I opened iTunes this morning and miraculously my wish list seems to be working.   i see one app i had added to be downloaded.  I am able to remove songs from wish list and add songs and preview all.
    last i heard from the customer service person was that they referred the issue to a senior level support person.  this after i sent them several screen shots of my wish list and the error about unable to add to existing wish list because ittem was already there.
    I have not heard from them that my issue is resolved.  I will give them a day or so to get back to me to confirm they fixed the problelm.
    very strange.  at least they acknowledged the problem did indeed exist as they referred me to the online user forum for possible solutions.  I indicated the problem persisted as early as June 2010 and as late as Jan 2012. and I had upgraded to ver 10.5.3 as well as remove and re-install even AFTER they kept telling me they removed my wishlist.

  • Adding a secure, internal-only SharePoint Web application / Site collection in existing farm

    Hi,
    We are currently working on creating a new internal-only SharePoint site that will host sensitive information. We are planning the architecture to provide a secure environment to host this information in SharePoint. We will create the new web app on a separate
    database with encryption enabled TDE; we are also planning to encrypt the data through the SharePoint (Insert third-party vendor here) forms before it gets to the SP DB. And obviously, SharePoint permissions will be set accordingly.
    Additionally, we would like to have the site accessible
    only through our internal network and keep it off the DMZ.
    Our current SharePoint environment consists of two web-front end servers (load-balanced) externally exposed (DMZ), one application server and the SQL server both behind the DMZ (internal-only). Currently all of our SharePoint web apps are accessible externally
    through SSL.
    What is the best way to accomodate this new internal-only web application within our existing farm providing the security measures explained before?
    I am thinking  on adding an extra WFE server to the existing farm and put it behind the DMZ (internal-only) in a similar way as our application server is configured right now, but just serving exclusively this new internal site's content. I would then
    have the NEtwork guys to make the site accessible only to users logged-in internally in our network and through this new dedicated server only. My concern is that since all of our other web apps in the farm are exposed externally, and since the new server
    would be part of the same farm, that could be open doors for bad guys to access this information. Are there any other topology options I should consider? I have thought about creating a small (one-server only) new farm just for this purpose, but I am trying
    to avoid going that route.
    Any thoughts?
    Thank you,
    Rob

    You're mostly going down the right track.
    A new web application in dedicated SQL DB and web application policies to deny all external accounts access to the sites will go a long way. You can also make sure that the DNS does not resolve externally.
    If you want security you will probably be building the web application on https alone, which is my preference for any farms these days. That might negate the need for your encrypted infopath system.
    However you cannot add a WFE to a farm and dedicate a web app soley to that server. Any server with the SharePoint Foundation Web Application role will host all web applications. You can steer traffic to one
    server or another but that's not really doing much for security. If it's on one WFE it's on them all. For that reason I would say that the standalone farm is the best, most secure, solution.
    All of what you've been describing will help with security but you'll have to spend hours testing connections, securing files and testing testing testing.  Whilst the standalone will just work.
    No, i don't know why that turned into tiny print either.

Maybe you are looking for

  • Old JSP pages loading // how to get new ones?

    I am new to the forum and hope that experts can help. I am running a JSP application on an Apache/tomcat setup. I encounter the problem that although I update a webpage (say 'example.jsp') with a date of 12 Jan 2009, the server continues to use a ver

  • Itunes and quicktime both fail to launch, giving error reports

    Getting a little ticked because ive been trying to get itunes to properly work. To clarafy, i've done the following to try and fix this problem Uninstalled itunes and quick time Re-installed Uninstalling just quick time and it almost loaded until it

  • [SOLVED] yaourt question

    is there a way to grab all the packages wherein the name contains a certain string? e.g. there are numerous fortune packages, it would be cool to do something like yaourt -S fortune-* possible? thx in advance. Last edited by wootsgoinon (2014-12-30 2

  • HP Pavilion 500-314 graphics card

    Hi I have the HP 500-314.  My son likes to play World of Warcraft and right now the screen is grainy when he plays it and hsays he is only getting between 1- and 25 FPS..  Can I get a better grahics card to put in the computer and if so can I do it w

  • No jdk installed after wls 6.1 installed

    so I download one from sun site. the version is 1.3.1-b24. I found some problem with String.getBytes(). when processing with chinese character string, it covert all byte to 63