Unable to install or upgrade
The most common installation or upgrade failure is that the Unix host cannot read the Safeguard Authentication Services application configuration in Active Directory. Ensure that you have followed the instructions in the Configure Active Directory for Safeguard Authentication Services section of the Safeguard Authentication Services Installation Guide and that the configuration has been created successfully.
During an upgrade, you may see an error that Safeguard Authentication Services cannot upgrade because the application configuration cannot be located. If you previously joined to a specific domain controller, Safeguard Authentication Services disabled DNS SRV record lookups. This means that Safeguard Authentication Services cannot resolve other domains in the forest and may be unable to locate the application configuration. In this case, you must ensure that the domain controller you specified is a global catalog. Otherwise, you must create the Safeguard Authentication Services application configuration in the domain that you join or you must properly configure DNS to return SRV records and join normally, rather than specifying a domain controller when you join.
For more information, see the About Active Directory Configuration section in the Safeguard Authentication Services Installation Guide.
Unable to join the domain
If you are unable to join the domain, run the preflight utility to validate your environment.
For more information, see The Safeguard Authentication Services Pre-Installation Diagnostic Tool in the Safeguard Authentication Services Installation Guide .
Then, verify the following:
- Check that the Active Directory account specified during join has rights to join the computer to the domain.
- Check that the Unix host is able to properly resolve the domain name through DNS.
If you are joining to a specific domain controller you must ensure that Safeguard Authentication Services can locate and read the configuration information in Active Directory. You should do one of the following:
Unable to log in
If you are unable to log in as an Active Directory user after installing, check the following:
- Log in as root on the Unix host.
- Check the status of the Safeguard Authentication Services subsystems. To do this, run the following command:
vastool status
Correct any errors reported by the status command, then try logging in again.
- Ensure the user exists locally and is allowed to log in. To check this, run the following command:
vastool user checklogin <username>
The output displays whether the user is a known Active Directory user. If not, you may need to map the user to an Active Directory account or Unix-enable the Active Directory account. If the user is known, an access control rule may prevent them from logging in. The output of the command displays which access control rules are in effect for the user.
You may need to restart window managers such as gdm in order for the window manager to reload NSS modules. Until the window manager reloads the NSS configuration, you will be unable to log in with an Active Directory user. Other services such as cron may also be affected by NSS changes. If you are unsure which services need to be reloaded, reboot the system.
Unix Account tab is missing in ADUC
If the Unix Account tab is missing when viewing the properties of a user or group in Active Directory Users and Computers, the most likely cause is that the extension module (AducExtensions.dll) was unable to load. Typically this is due to an invalid or corrupt installation. To resolve this issue, check the following:
- Ensure that Safeguard Authentication Services has been installed on the local computer.
- Ensure that you are logged in as a domain user or that ADUC is running as a domain user.
- The Safeguard Authentication Services installation may have become corrupted. Remove and re-install Safeguard Authentication Services.
- Certain software is required in order for the Unix Account tab to load. If any of the following software has been removed, please re-install it:
- Windows PowerShell
- VisualStudio C++ Runtime
- .NET Framework v4.5
- If you are working with One Identity Active Roles Server MMC Console, ensure that display specifiers have been installed and that you have restarted the Active Roles Service. Until you do this, the Unix Account tab will not appear in Active Roles Server MCC Console.
- If the Unix Account tab still does not appear, open Control Center and enable debug logging from the Preferences. Attempt to load the Unix Account tab, then send the generated log files to VARcompany.support.