Looks like MS strikes again with another buggy patch. We had applied the Nov monthly update to half our domain controllers yesterday. Turns out there's a bug in the patch that for whatever reason is expecting RC4 to be enabled for Kerberos authentication
https://twitter.com/SteveSyfuhs/status/1590417822030917632?s=20&t=IFx9d0YDMIQcNoquj_lPDw
We have RC4 disabled in our environment. I was seeing the following error in the System log on the SF server every time the auth failed.
Client Time:
Server Time: 0
715.0000 11/11/2022 Z
Error Code: 0xe KDC_ERR_ETYPE_NOTSUPP
I got with our domain admin and had him apply the following registry keys to the DCs that were updated with the November patch per:
https://www.reddit.com/r/sysadmin/comments/ypbpju/comment/ivu62l7/?utm_source=share&utm_medium=web2x&context=3
reg add "HKLM\SYSTEM\CurrentControlSet\services\kdc" /v KrbtgtFullPacSignature /t REG_DWORD /d 0 /f
reg add "HKLM\SYSTEM\CurrentControlSet\Services\Netlogon\Parameters" /v RequireSeal /t REG_DWORD /d 0 /f
reg add "HKLM\SYSTEM\CurrentControlSet\services\kdc" /v ApplyDefaultDomainPolicy /t REG_DWORD /d 0 /f
I assume what happened was after the patch was applied to certain domain controllers, Kerberos could no longer negotiate a ticket due to RC4 being disabled. So, if the SFs are trying to contact the domain controllers using Kerberos, the process fails there and doesn't even attempt to contact FAS. The generic error message I was seeing on the SF "Could not contact any Federated Authentication Servers" might be technically true but the cause appeared to be a Kerberos issue.
Be careful with the November update on domain controllers + FAS in an environment where RC4 is disabled. Hopefully MS will correct the bug because RC4 isn't something you probably wouldn't want turned on anyway