This message was deleted.
# citrix-vad
s
This message was deleted.
j
DDC Machine accounts need to be able to access the DB…
j
So the computer account needs to be named on the database access list?
j
I had a project that was not allowing the addition of a controller until perms were set for the machine account, but that’s not normal, the addition of the machine account is usually part of the join process which uses the admin creds - was a locked down sql environment, might be similar for you?
j
Got the db guy checking. The weird thing is I don't seem to be able to telnet to the db server on port 1433 though - don't suppose you have any idea what port it communicates with the db server on, is it the default?
f
Yes that is the default port, if you have access to the other DDC check the port to the sql server with a netstat.
j
Duh....the port is open, I was trying the wrong db server 🙂
🍻 1
Got the machine account added to the database and STILL getting prompted for creds on database connection....any other ideas? Is there actually a log written somewhere?
r
Are you sure the machine account name has not previously been used? If the same machine account with new SID is added I believe you will have problems, just a thought.
j
Don't think so, it's a new machine
s
can your sql resource confirm the new computer account has the same roles as the existing ones? and the account your using to do this is a full site admin in studio?
j
checking.....it's interesting when your Teams back-and-forths extend all over the world 🙂
m
j
Single zone, single DDC
m
Ok… Maybe network FU and try the registry above anyways!? The most detailed log will be CDF… But… It’s CDF :)
c
ask your DBA to give you sysadmin perms and retry 🙂 from memory you need securityadmin role /dbcreator role and db_owner on the DB but its easier if they give you sysadmin. Runtime permissions are different and use the DDC's computer account
I have attached the runtime permissions the DDC must have but these are done automatically when adding an additional controller through studio when you have the the correct SQL perms
j
Well have tried all suggestions and this new DDC does not want to connect to the database at all. How bizarre. Looks like I will need to do an in-place upgrade instead 😞
c
What type of SQL backend is it ? Standalone/Always on availability groups / Mirroring/ Clustered instances ? You run the command in powershell get-brokerdbconnection on the existing DDC and confirmed the existing DB string is not using a custom SQL port (default is 1433)?. Has your DBA also checked the SQL log as you would see login failures?. I would also run get-brokercontroller and and check the controllers node in studio to see if the failed controller join to site has left an invalid entry in the DB as you will need to evick it before re trying to re add the new controller with the correct sql perms
j
Thanks for the input - however in the interests of our lack of time I punted for an upgrade of the existing DDC straight to 2019 - which seems to have worked <mops brow>