000023124 - ACE WebAgent/IIS: Internal server error (500) after enabling SSO into MS SharePoint

Document created by RSA Customer Support Employee on Jun 14, 2016Last modified by RSA Customer Support Employee on Apr 21, 2017
Version 2Show Document
  • View in full screen mode

Article Content

Article Number000023124
Applies ToACE/Agent for Web 5.3 (IIS)
Microsoft Windows Windows Server SP1
Issue"Global Catalog query failed"
ACE WebAgent/IIS: Internal server error (500) after enabling SSO into MS SharePoint
Cause

Assumption: Windows 2003 SP1 is installed on both your DCs and on the sharepoint portal server machine. If not, install Win 2003 SP1 first, as otherwise this solution is likely not to apply.

After a successful SecurID authentication against an SSO enabled MS SharePoint server, the webbrowser shows an "Internal Server Error (500)".

If the problem is reproduced after enabling debugging on the agent (through the "Advanced" tab of the "RSA Agent" application in Window's "Control Panel"), the following would appear in the agent's debugging log:

[2392] 12:08:29.811 File:global_catalog.cpp Line:67 # Searching Global Catalog for user: ntadmin
[2392] 12:08:29.821 File:global_catalog.cpp Line:146 # Global Catalog query failed
[2392] 12:08:29.821 File:rsaSingleSignon.cpp Line:425 # HttpExtensionProc() - Global Catalog search failed != GC_UNIQUE_UPN
[2392] 12:08:29.821 File:rsaSingleSignon.cpp Line:427 # HttpExtensionProc() Global Catalog search failed - Release the writelock

The likely reason for for this error message is that no DC in the windows domain is a Global  Catalog (GC).

This can be verified by

  • running on a DC the "Active Directory Sites and Services" from the "Administrative Tools" program group
  • unfold "Sites" -> "Default first site name" -> "Servers" -> ServerName.
  • right click on "NTDS-Settings" a select "Properties"
  • in the window that opens up, make sure that "Global Catalog" is ticked
  • reboot the DC in order to enable the GC service
Make sure you repeat this operation for all DCs.
ResolutionEnable the Global Catalog service on your DC. See above for detailed instructions.
Legacy Article IDa32257

Attachments

    Outcomes