This message was deleted.
# citrix-vad
s
This message was deleted.
d
Haven't seen it as I have never attempted to move a user between OUs, but sounds similar enough to account renames where the broker name cache keeps ahold of the old name and the user can't log in. Haven't done a rename that I'm aware of since I started using FAS though so I don't know if the error would happen or be the same or not.... I have had to run this against all of our delivery controllers to clear the cache and resolve the issue: Update-BrokerNameCache -Users -Machines -AdminAddress <delivery controller address>
k
We move users quite frequently and don't see this. Does anything else change with their account or the domain? Groups, forests, etc.
t
Its just the OU changing, it appears the certificate as displayed on the CA references the OU and it impacts our ability to login.
j
I move users often and don't see this as well... although I do see the OU in the subject of our user certs.
moved myself here in this window, even changed my default UPN suffix (listed as a SAN entry on the cert) and FAS still worked
t
ok interesting, chatting with support thanks for the post though
l
we had something similar with a locked down shared AD, and it turned out that the FAS storefront server couldn't read the OU of the shadow users. Added the computer accounts of the FAS SF servers and it all started working