WS-6509 refusing SSH connections via TACACS+ 5.5

Hello everyone, we have our Core 6509's using AAA with TACACS+ version 5.5 appliance.
We have 4 appliances 2 each in 2 locations.
We have an issue where 6509's refuse to authorize/authenticate valid users for ssh connections.
When you ssh to the device you can enter your password but ssh tectia just closes or you see the login banner and "Authorization denied" and ssh closes.
The switches have there tacacs-server settings pointing to all four TACACS+ devices.
Occasionally one or both will attempt to use one of the 2 non local TACACS+ servers to authenticate/athorize connections.
You can login from the console if you interrupt it's connection to TACACS by disconnecting the fiber connections momentarily.
Has anyone seen something like this before?
This happens once or twice a year.

That's the funny part, TACACS shows green stating that I'm passing all the checks.
When I select the magnifying glass I see "passed" in green at the top.
when I check "Evaluating Identity Policy" it says.
Matched Default Rule
Selected Identity Store - Internal Users
Authenticating user against Active Directory
Could not establish connection with ACS Active Directory agent
Looking up User in Internal Users IDStore - "My username"
Found User in Internal Users IDStore
Wrong password or invalid shared secret
The advanced option that is configured for a failed authentication request is used.
The 'Continue' advanced option is configured in case of a failed authentication request.
But I'm able to access all other switches so my AD username/password are correct.
At first I was unable to access it's pair. After we did a hard reset on one of the ACS's that was resolved.
But I still can't get into the other pair.

