sk181801 - "Error logging into domain" in Web SmartConsole when connecting to a Domain on a peer Multi-Domain Security Management Server
"Error logging into domain" in Web SmartConsole when connecting to a Domain on a peer Multi-Domain Security Management Server
Product: Multi-Domain Security Management, Web SmartConsole
Version: R81 (EOS), R81.10 (EOS), R81.20
Last Modified: 2024-06-05
Symptoms
- "
Error logging into domain" in Web SmartConsole in this scenario:
- This is a Management High Availability configuration of Multi-Domain Security Management Servers
- Administrator logs in to Web SmartConsole on one Multi-Domain Security Management Server
- Administrator connects to a Domain on a peer Multi-Domain Security Management Server
Error popup:
Cause
Possible reasons:
- The current version of the Multi-Domain Security Management Servers does not support the login-to-domain feature on a peer Multi-Domain Security Management Server.
- Missing or corrupted certificate of the peer Multi-Domain Security Management Server.
Solution
This problem was fixed. The fix is included in:
- Jumbo Hotfix Accumulator for R81.20 starting from Take 54
- Jumbo Hotfix Accumulator for R81.10 starting from Take 141
- Jumbo Hotfix Accumulator for R81 starting from Take 99
If you choose not to upgrade, follow these instructions:
- Install the required software version:
| Version | Required Jumbo Hotfix |
| R81.20 | R81.20 Jumbo Hotfix Accumulator - Take 8 or higher |
| R81.10 | R81.10 Jumbo Hotfix Accumulator - Take 93 or higher |
| R81 | R81 Jumbo Hotfix Accumulator - Take 82 or higher |
Copy the Gaia OS certificate from the peer Multi-Domain Security Management Server, on which the Domain login failed, to the Multi-Domain Security Management Server, on which you logged in to Web SmartConsole.
Connect to the command line on the Multi-Domain Security Management Server, on which you logged in to Web SmartConsole.
Log in to the Expert mode.
Back up the current certificate file:
cp -v $MDS_FWDIR/conf/mds_web_cert/<Primary_IP_Address_of_Peer_Server>.crt{,_BKP}Example:
If these are the IP addresses:
- Source Multi-Domain Security Management Server = 192.168.22.33 - Peer Multi-Domain Security Management Server = 192.168.22.44then this is the syntax on the server 192.168.22.33:
cp -v $MDS_FWDIR/conf/mds_web_cert/192.168.22.44.crt{,_BKP}
Copy the Gaia OS certificate from the peer Multi-Domain Security Management Server, on which the Domain login failed:
ssh admin@<Primary_IP_Address_of_Peer_Server> 'cat /web/conf/server.crt' | cat > $MDS_FWDIR/conf/mds_web_cert/<Primary_IP_Address_of_Peer_Server>.crtExample:
If these are the IP addresses:
- Source Multi-Domain Security Management Server = 192.168.22.33 - Peer Multi-Domain Security Management Server = 192.168.22.44then this is the syntax on the server 192.168.22.33:
ssh admin@192.168.22.44 'cat /web/conf/server.crt' | cat > $MDS_FWDIR/conf/mds_web_cert/192.168.22.44.crtAssign the required permissions to the copied certificate file:
chmod -v 644 $MDS_FWDIR/conf/mds_web_cert/<Primary_IP_Address_of_Peer_Server>.crt
```
**Example:**
> If these are the IP addresses:
>
> - Source Multi-Domain Security Management Server = 192.168.22.33
> - Peer Multi-Domain Security Management Server = 192.168.22.44
>
> then this is the syntax on the server 192.168.22.33:
>
> ```
> chmod -v 644 $MDS_FWDIR/conf/mds_web_cert/192.168.22.44.crt
> ```
As an **immediate workaround** - connect with Desktop SmartConsole to the IP address of the applicable Domain.
#### NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.