sk181801 - "Error logging into domain" in Web SmartConsole when connecting to a Domain on a peer Multi-Domain Security Management Server

"Error logging into domain" in Web SmartConsole when connecting to a Domain on a peer Multi-Domain Security Management Server

Product: Multi-Domain Security Management, Web SmartConsole
Version: R81 (EOS), R81.10 (EOS), R81.20
Last Modified: 2024-06-05

Symptoms

  1. This is a Management High Availability configuration of Multi-Domain Security Management Servers
  2. Administrator logs in to Web SmartConsole on one Multi-Domain Security Management Server
  3. Administrator connects to a Domain on a peer Multi-Domain Security Management Server

Error popup:

Cause

Possible reasons:

  1. The current version of the Multi-Domain Security Management Servers does not support the login-to-domain feature on a peer Multi-Domain Security Management Server.
  2. Missing or corrupted certificate of the peer Multi-Domain Security Management Server.

Solution

This problem was fixed. The fix is included in:

If you choose not to upgrade, follow these instructions:

  1. Install the required software version:
Version Required Jumbo Hotfix
R81.20 R81.20 Jumbo Hotfix Accumulator - Take 8 or higher
R81.10 R81.10 Jumbo Hotfix Accumulator - Take 93 or higher
R81 R81 Jumbo Hotfix Accumulator - Take 82 or higher
  1. Copy the Gaia OS certificate from the peer Multi-Domain Security Management Server, on which the Domain login failed, to the Multi-Domain Security Management Server, on which you logged in to Web SmartConsole.

  2. Connect to the command line on the Multi-Domain Security Management Server, on which you logged in to Web SmartConsole.

    1. Log in to the Expert mode.

    2. Back up the current certificate file:

      cp -v $MDS_FWDIR/conf/mds_web_cert/<Primary_IP_Address_of_Peer_Server>.crt{,_BKP}
      

      Example:

      If these are the IP addresses:

        - Source Multi-Domain Security Management Server = 192.168.22.33
        - Peer Multi-Domain Security Management Server = 192.168.22.44
      

      then this is the syntax on the server 192.168.22.33:

      cp -v $MDS_FWDIR/conf/mds_web_cert/192.168.22.44.crt{,_BKP}
      
  3. Copy the Gaia OS certificate from the peer Multi-Domain Security Management Server, on which the Domain login failed:

    ssh admin@<Primary_IP_Address_of_Peer_Server> 'cat /web/conf/server.crt' | cat > $MDS_FWDIR/conf/mds_web_cert/<Primary_IP_Address_of_Peer_Server>.crt
    

    Example:

    If these are the IP addresses:

      - Source Multi-Domain Security Management Server = 192.168.22.33
      - Peer Multi-Domain Security Management Server = 192.168.22.44
    

    then this is the syntax on the server 192.168.22.33:

    ssh admin@192.168.22.44 'cat /web/conf/server.crt' | cat > $MDS_FWDIR/conf/mds_web_cert/192.168.22.44.crt
    
  4. Assign the required permissions to the copied certificate file:

      chmod -v 644 $MDS_FWDIR/conf/mds_web_cert/<Primary_IP_Address_of_Peer_Server>.crt
      ```
   
      **Example:**
      
      > If these are the IP addresses:
      >
      >    - Source Multi-Domain Security Management Server = 192.168.22.33
      >    - Peer Multi-Domain Security Management Server = 192.168.22.44
      >
      > then this is the syntax on the server 192.168.22.33:
      >
      > ```
      > chmod -v 644 $MDS_FWDIR/conf/mds_web_cert/192.168.22.44.crt
      > ```

As an **immediate workaround** - connect with Desktop SmartConsole to the IP address of the applicable Domain.

#### NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.