Troubleshooting: Newly Created Realms Won't FileSync After Installation

Follow
    Applies to:
  • SecureAuth Identity Platform
Deployment model:
  • Cloud
  • Hybrid
  • On Premises
  • Version Affected: All
     
     

    Overview

    After installing FileSync between two or more servers, newly created realms may not properly synchronize.

     

    Cause

    The file permission or share settings for the new realm(s) may not be properly configured for FileSync.

     

    Resolution:

    1. Create the new realm(s) to be synced on all servers in the cluster -- primary and secondary (for example, SecureAuth16, SecureAuth22).
    2. Right-click and run Reset-File-Perms.bat as Administrator on all servers in the cluster -- primary and secondary. Order does not matter.

    D:\MFCApp_Bin\Extras\Reset-File-Perms.bat

    If Reset-File-Perms prompts for an account name, enter the local user account associated with FileSync (for example, svc-xxx-xxx).

    Reset-File-Perms requires an IIS reset. As an alternative, FileSync Helper can be used instead, which works the same way without requiring an IIS reset.

    1. Configure the new realm(s) from the primary server. This updates the web.config files for those realms on the primary server, making them the most current version. By default, FileSync checks for updates every 10 minutes; this interval can be reduced by adjusting the interval value in FileSyncService.exe.config (see FileSync Service Troubleshooting for details).
    2. On the secondary server(s), confirm the web.config files for the newly created realm(s) have the same Date modified timestamp as the same files on the primary server.

    File Explorer showing a realm's folder, with the web.config file's Date modified column highlighted.

    If the realm(s) are still not syncing, check the following:

    1. Open the Services console and confirm SecureAuth FileSync Service is running on each secondary server. Start or restart it if needed.

    Services console showing the SecureAuth FileSync Service selected, with its status highlighted as Running.

    1. On each FileSynced server, open Computer Management and go to System Tools > Shared Folders > Shares. Confirm the newly created realm(s) are listed.

    Computer Management's Shared Folders Shares list, showing share names for realms SecureAuth0 through SecureAuth998.

    1. Go to the new realm's directory (for example, D:\Secureauth\SecureAuth16). Right-click the web.config file, open Properties, then the Security tab. Confirm the FileSync service account (typically named something like svc-XXXXX) has Modify, Read & execute, Read, and Write permissions.

    web.config Properties Security tab, showing the FileSync service account with Modify, Read and execute, Read, and Write permissions all allowed.




     

    SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.

    Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.

    0 out of 0 found this helpful

    Comments

    0 comments

    Please sign in to leave a comment.