Cannot "connect as current user" via the Security Server

Hello community,

I had a problem using the "connect as current user" option against a network outside of the enterprise security server. Connection by manually keying in the name of user and password works very well from the outside the company network For internal connections using a connection to the server instead of security server, everything works as expected without having to manually type the name of user and password.

Single domain

Customer of the horizon is 3.5.2 and joined to a domain

2 Security Server 6.2.1 x

2 Server 6.2.1 connection x

On one of the servers of connection I got the following error message when you try to connect through the horizon customer using the option "connection as the current user:

2015 12-28 T 20: 21:15.207 + 01:00 INFO (B 0, 08 - 0E34) < ajp-nio-8009-exec-7 > [PAEContext] (SESSION: a774_ * _b2fb) Idle Timer executor by using 1 thread (s)

2015 12-28 T 20: 21:15.625 + 01:00 ERROR (0744-0AEC) < MessageFrameWorkDispatch > [ws_winauth] [GSSApiProcessServerContext]: negotiate failed. Error 0 x 0000000080090300 (not enough memory is available to complete this form) {SESSION: a774_ * _b2fb}

2015 12-28 T 20: 21:15.626 + 01:00 (B 0, 08-04 B 8) WARN < ajp-nio-8009-exec-8 > [GssapiHandler] (SESSION: a774_ * _b2fb) failed connection GSSAPI: not enough memory is available to complete this application

2015 12-28 T 20: 21:15.627 + 01:00 ERROR (B 0, 08-04 B 8) < ajp-nio-8009-exec-8 > [GssapiHandler] (SESSION: a774_ * _b2fb) cannot close the context 7 36 d-*-00D 3 with the error: unable to locate the context requested

2015 12-28 T 20: 21:15.627 + 01:00 ERROR (B 0, 08-04 B 8) < ajp-nio-8009-exec-8 > [GssapiAuthFilter] (SESSION: a774_ * _b2fb) authenticate GSSAPI performance problem - GSSAPI_ERROR: GSSAPI failed: not enough memory is available to complete this application

The connection to the server has 12 GB of memory in total and 9.5 GB of memory free/available.

In the windows event log, the following error message appears:

BROKER_USER_AUTHFAILED_GENERAL

Failed to authenticate the user < UNAUTHENTICATED >

Attributes:

Node = hostnameofconnectionsserver.mydomain.com

Gravity = AUDIT_FAIL

Time = Mon 28 Dec 19:51:16 THIS 2015

Module = broker

UserDisplayName = < UNAUTHENTICATED >

Source = com. VMware.VDI.Broker.filters.GssapiAuthFilter

Recognized = true

Just tried from a machine arrived in the area via the Security server. Cannot open a session as the current user. We also enabled on the external connections of MFA, but I don't think that should make a difference.

Tags: VMware

Similar Questions

  • Cannot connect directly to Esx via the vSphere Client.

    Hello

    I can not connect directly to ESX through the le VSphere client. I have the following message:

    "Can not connect to "xxx"vSphere Client. Un unknown connection error has occurred. (

    The customer not able to send a complete application on the server. (Underlying connection was closed. An unexpected error has occurred when sending.)). »

    Le ESX reply to ping et name resolution are correct. They are seen by the vCenter and sshh connection to ESX is possible.

    Version: Esxi, 5.5.0, 1892794
    VSphere Client 5.5.0, 1880841 on Windows XP SP3

    Thank you for your help

    Have a look here: vSphere Client 5.5 and WindowsXP/Windows2003 & #8211; Unknown connection error & laquo; Mike Landry & #8230;

  • View customer Horizon | Unable to login via the Security Server

    Hello people,

    We strive to deploy VMware View 5.3. Everything is complete we are able to access desktop of customer view through connection to the server. But when we try to connect to the desktop via security server, authentication of the user position get us the attached error.

    Can someone please help me to understand and resolve the error?

    Thank you!

    Hari.

    Thank you for your response. Issues was DNS resolution external URL referred to the client device. We decided. Thank you.

    Hari.

  • Not able to connect with the Security Server

    Hello

    IM setting up a demo with view 6 environment, and when I try to connect locally on the servers of connection it works fine, but when I try to connect to the Security server fails with the image below.

    pic1.jpg

    The Security server has 2 network cards, now in the DMZ and in production. I guess I should also be able to connect directly to the ip production, but the same error.

    We have disabled the firewall between dmz and prod for troubleshooting, but same problem.

    The image below is the Security Server, the addresses here are the ip 'internet', I guess it's true?

    pic2.jpg

    The image below is the connection to server 1, the addresses here are internal, and is the FULL domain name, if it was "internet ip" instead?

    pic3.jpg

    If I try on the spot to connect to the ip address of prod on security with internet server explorer, im able to connect, but when I select the office that it will fail "cannot display this page", then shows the 'internet' ip in the address field.

    I guess there is just something simple I've missed... hope you understand my question

    Thanks for the support.

    If you do not already have a look at this description of the display configuration, it covers remote access via security servers as well. Setting up remote access with a view PCoIP 4.6 and newer https://communities.VMware.com/docs/doc-14974

    I guess the fact that you can connect through the servers of connection that the URL you configured in the view administrator for servers in connection is a production local IP address/address?

    External security URL server is also an IP/address of DMZ / external can be solved?

  • Problem with USB auto connect with clients that connect through the Security server...

    Lack of VMware View 5.0.1 with 2 servers connection and a security server. When the clients connect directly to the server connection, USB connection works very well... users can use their USB drives and other devices with their VM. The problem occurs when they attempt to use their USB devices when negotiated through the Security server.

    I know that port 32111 (TCP) must be open between the server security and the connection to the server, but even after doing so it does not always work... customers just to get the scrolling message of office in the USB menu initialization.

    Our current facility is:

    External IP address-> DMZ (Security Server)-> connect to server

    Entrust us our firewall config through our ISP (we are not overloaded with scientists here, it's just me, so things like little help my work load). They are certainly not incompetent (or at least were not in the past). I had to open the external 32111 IP port to the DMZ, then of the DMZ to our connection server that is used for external connections. Everything about VMware View works perfectly for the clients that connect this way, but not USB devices.

    One thing I give is if our having a configuration of VLAN dedicated for customers views influence what either. I'm trying to keep an eye on what ports are open that for our firewall for my records, but I do not see where I openly opened ports on the internal side of security server to our internal network. He must have the port opened directly from the internal face of security server of vmware 32111 discovers clients?

    The firewall Guys tell me that they checked over and over that port 32111 is open throughout the. They also said that they tried to telnet 32111 to our security server port and have nothing back (should have gotten garbage at least according to them).

    An idea of the next steps to take? It is obviously a blocked port, I just have no idea why at this stage.

    I know that port 32111 (TCP) must be open between the server security and the connection to the server, but even after doing it still does not work

    This is not what it takes. The agent is listening on the port 32111, you must open the firewall to allow connections to the Security server for the desktop on port 32111 (same thing you must allow RDP and PCoIP).

    Mike

  • Cannot connect my midnight user

    I disconnect my laptop, I tried to log in again and he said, it cannot connect to my user profile. someone pls wat shud I do.

    I disconnect my laptop, I tried to log in again and he said, it cannot connect to my user profile. someone pls wat shud I do.

    This is the error message when you tried to open a session?
    The user profile Service has not logon. Use the profile cannot be started.

    If this is the case, please use the following tutorial. It has a "Fix it for me" application as an instructions "Let me fix it myself":

    http://support.Microsoft.com/kb/947215

    If you have a different error message, then please report it.

    For the benefits of others looking for answers, please mark as answer suggestion if it solves your problem.

  • View the connections of the server to connect to the Security Server 5.2

    So, I wonder if it is anyway possible to not expose a subnet of office to the DMZ during the deployment of a security server?  I think remember me, there was a way to have the tunnel of security server all traffic through the connection to the server, but for the life of me, I can't seem to understand.

    Even in your previous PoC you should always have allowed some ports (PCoIP, RDP if use you it and the frame channel) from the server security for virtual offices. This has always been the case.

    The role of the Security Server is to protect exposure of desktop to the Internet. It provides a monitoring of protocols of the Internet (for example PCoIP) so make it succeed to check if the traffic is in the name of an authenticated user, and to ensure that if it is valid, it is transmitted over an office whose user is authorized to access. It is important to configure your internal firewall so that Office (PCoIP etc.) protocols can come only security servers. Then you give the required insurance. If such packets only packets UDP PCoIP arrive in your DMZ that are not on behalf of an authenticated user and then they are ignored in the DMZ without ever be passed in your data center. You know that all protocols for virtual desktops have been validated by the Security server.

    The Security server should also communicate with the login server and that's why you should also allow JMS, AJP13, and IPsec through. These should be only to the servers again only from servers to security and connection.

    You can always route the PCoIP packages through a proxy in your data center, but the security required inspection happens before that the Security Server so that eventually they can be thrown into the demilitarized zone.

    Mark

  • Trying to access the electronic books in the library of our audience. Downloaded the software, but I get an error saying: the current version of the security of MP's 2.5.0.0 and I need 2.

    Trying to access the electronic books in the library of our audience. Downloaded the software, (Overdrive Media Console) but I get an error saying: the current version of the security of MP's 2.5.0.0 and I need 2.5.0.1. How to do only what I can read ebooks? People have suggested using IE, but I prefer to much HELP Firefox!

    Try to update the media player while using Internet Explorer. Windows Updates site uses ActiveX to perform "duties. Firefox does not support ActiveX.

  • I changed my password but cannot connect. When I reset the password they send an e-mail to my other email account, but there is no text tell me how to change

    I changed my password but cannot connect. When I reset the password they send an e-mail to my other email account, but there is no text tell me how to change it. He repeats to me just 'loading '.

    frustrating

    If you are referring to a Windows Live account, you can get help here: http://www.windowslivehelp.com

  • When I opened the Windows Security Center it says "the Security Center is currently unavailable because the Security Center Service is not started or was stopped.

    When I opened the Windows Security Center it says "the Security Center is currently unavailable because the Security Center Service is not started or was stopped.  I can't see if any firewall or antivirus works etc.  Anyway to reinstall the Windows Security Center or is there something else I can do.  Concerning

    Hello

    · Do you remember all the recent changes on the computer before the show?

    · What is the service pack installed?

    Follow the procedure described at the link below and check if it will help: error message when you try to open the Windows Security Center in Control Panel on a Windows XP computer: http://support.microsoft.com/kb/919291

  • Cannot connect edimax wifi extender to the uverse router

    Cannot connect edimax wifi extender to the uverse router

    Hi Richard,

    Welcome to Microsoft Community where you can find the answers related to Windows.

    According to the description, it seems you face a problem while connecting edimax WiFi extender to a uverse router

    I suggest to refer to the following article and check if it helps.

    http://www.Edimax.com/images/image/FAQ/wireless/General-wireless/ConnectWirelessUnderVista.PDF

    http://www.Edimax.us/HTML/FAQ/EW-7438RPn-browser.PDF

    Note: There is for Windows 7 as well.

    If the problem persists, I recommend you contact edimax support for more help.

    http://www.Edimax.com/en/support.php

    If you need Windows guru, do not hesitate to post your questions and we will be happy to help you.

  • Usually, there is a way to upgrade for current users of the software at a reduced price. I don't see something like that for Lightroom 6. I have to pay full price just to upgrade to the new version of standalone LR6?

    Usually, there is a way to upgrade for current users of the software at a reduced price. I don't see something like that for Lightroom 6. I have to pay full price just to upgrade to the new version of standalone LR6?

    Just go to the products

    Scroll to Lightroom and click on buy and then replace I want to buy lots of upgrade. The price is $79.

  • VMware workstation 8 briged connection cannot get an ip address from the dhcp server

    Hello, I hope someone can help me with this problem, my virtual machines are unable to obtain an ip address from my dhcp server in windows server 2008R2.

    VMware workstation 8 is running in windows 7 proff. 64-bit OS. My gets physical computer an ip Server dhcp without problem have access to the internet and everything works fine, but my VMs for some reason any cannot obtain an ip address from the DHCP server.  I updated virtual nework Briged editor one of my physical network interface cards. Then I put my VM NIC to briged in for some reason my VMs are unable to obtain an ip address. The ips only I get are 169.254.43.129 Add 255.255.0.0. any help would be very happy. Thank you very much.

    FYI - you have posted some of the vmware.log

  • Help generate the SSL certificate for the Security Server

    Hi people,

    We have server (ss - 01.mydomain.local) security and connection server (cs - 01.mydomain.local). Now intend to install a certificate on the Security server. What should be the common name.

    our Web site is something like access.mydomain.local.

    Also, we plan to install SSL only on security for internet access server, this will affect the internal users, access to the connection to the server.

    Thanks and greetings

    J P Raj

    Take a look at the link below

    https://pubs.VMware.com/horizon-view-60/topic/com.VMware.ICbase/PDF/horizon-view-60-scenarios-SSL-certificates.PDF

    Internal users will not be affected when you install the Security server certificates

    Simply create a CSr file > get certificates and import them to the Security server in the MMC guide explains practically everything. If you already have certificates wildcard certificates, then you can follow the sub process

    (a) export the server certificates

    (1) to connect to the server that has certificates

    (2) for this server to export it to a PFX format certificate.

    (3) open the Microsoft MMC Certificates snap-in for the computer account.

    4) navigate to certificates (Local computer) > personal > certificates.

    (5) right-click on the signed certificate that is to be exported.

    6) click all tasks > export.

    (7) on the Welcome screen, click Next.

    8) click Yes, export the private key.

    (9) if it is an option, click on include all certificates in the certification path.

    (10) enter a password for the private key. This is required for the import certificates.

    (11) to enter a file name and location. For example, C:\certificates\certificate.pfx.

    12) click Next.

    13) click Finish.

    b) import it to the use of broker or planned connection securityr.

    Certificates of thye 1) import (preferable Pfx format) for the server broker or planned connection security.

    (2) open the Microsoft MMC Certificates snap-in for the computer account.

    3) navigate to certificates (Local computer) > personal > certificates.

    (4) right-click the certificates.

    5) click on Import.

    (6) through the pfx and click Next.

    (7) enter the certificate password.

    (8) select Mark keys as being exportable.

    9) click Next.

    10) click Finish.

    (c) restart Consulting Services

    To restart the services:

    Log in as an administrator on the server that is running the Server VMware View connection server VMware View connection or VMware View Server Security.

    Click Start > run, type services.msc and press ENTER.

    In the list of services, right-click on the VMware View connection Server or VMware View Server Security service.

    Click on restart and wait for service to stop and start.

  • SSL certificate for the Security Server external facing

    Dear all,

    Today, I bought an external SSL certificate of DigitCert for our security server. I imported the certificates in the personal certificate (computer account) on the Security Server store. DigiCert provided three certificates, root CA, CA server and the other with the name of our domain. I renamed the vdm to the friendly name of the existing self-signed certificate and used the friendly name for the certificate vdm has our domain name. Subsequently, I rebooted consulting on the Security server. They are all released on except the "Display Blast Secure Gateway" service which entered the suspended state.

    On our facility, we have a connection to the server and a security server. To the Security Server, we use a different domain name for connecting to the server. We have an internal PKI and the connection to the server uses an SSL certificate.

    connection to the server = server01.internaldomain.com

    Security Server = server02.externaldomain.com

    Why the certificate cannot be loaded to view Blast Secure Gateway? I missed something?

    Thank you

    Edy

    I solved it. It was with the private key of the certificate. This is the reason that the Blast Secure Gateway could not load.

Maybe you are looking for