This message was deleted.
# citrix-vad
s
This message was deleted.
c
Check the above reg key on the VDA's and check the event logs on the VDA's. I would also check your FAS Rule to see if there is any Storefront/VDA/User restrictions
j
Nothing on VDA event logs, registry key on VDA matches the SF box, what's odd is i don't see any outgoing traffic to FAS in the SF windows firewall log, it's like its not even trying to hit FAS
c
Check the Storefront access permissions in the FAS Rule make sure the SF server has the assert idenity perms
m
Check if the SF Store is still FAS enabled.
j
Looks like MS strikes again with another buggy patch. We had applied the Nov monthly update to half our domain controllers yesterday. Turns out there's a bug in the patch that for whatever reason is expecting RC4 to be enabled for Kerberos authentication https://twitter.com/SteveSyfuhs/status/1590417822030917632?s=20&t=IFx9d0YDMIQcNoquj_lPDw We have RC4 disabled in our environment. I was seeing the following error in the System log on the SF server every time the auth failed. Client Time: Server Time: 0715.0000 11/11/2022 Z Error Code: 0xe KDC_ERR_ETYPE_NOTSUPP I got with our domain admin and had him apply the following registry keys to the DCs that were updated with the November patch per: https://www.reddit.com/r/sysadmin/comments/ypbpju/comment/ivu62l7/?utm_source=share&utm_medium=web2x&context=3 reg add "HKLM\SYSTEM\CurrentControlSet\services\kdc" /v KrbtgtFullPacSignature /t REG_DWORD /d 0 /f reg add "HKLM\SYSTEM\CurrentControlSet\Services\Netlogon\Parameters" /v RequireSeal /t REG_DWORD /d 0 /f reg add "HKLM\SYSTEM\CurrentControlSet\services\kdc" /v ApplyDefaultDomainPolicy /t REG_DWORD /d 0 /f I assume what happened was after the patch was applied to certain domain controllers, Kerberos could no longer negotiate a ticket due to RC4 being disabled. So, if the SFs are trying to contact the domain controllers using Kerberos, the process fails there and doesn't even attempt to contact FAS. The generic error message I was seeing on the SF "Could not contact any Federated Authentication Servers" might be technically true but the cause appeared to be a Kerberos issue. Be careful with the November update on domain controllers + FAS in an environment where RC4 is disabled. Hopefully MS will correct the bug because RC4 isn't something you probably wouldn't want turned on anyway