Bug: New Experience Realms Stop Working on Secondary FileSync Servers

Follow
    Applies to:
  • SecureAuth Identity Platform
Deployment model:
  • Cloud
  • Hybrid
  • On Premises
  • Version Affected: 23.07 and 24.04
    Bug Number: N/A
    Bug Status: Closed - Fixed
    Fixed in Version(s): A later release of FileSync (the exact version isn't documented in the original report — contact SecureAuth Support to confirm your deployment has the fix)

     

    Overview

    On versions 23.07 and 24.04, New Experience realms stop working on the Secondary server(s) in a FileSync cluster.

     

    Cause

    FileSync replicates the SecureStore's password from the Primary server to each Secondary server. In 23.07 and 24.04, this replication has a defect: the Secondary incorrectly locks itself out of its own copy of the SecureStore, and New Experience realms on that Secondary throw a 500 error as a result.

     

    Resolution / Workaround

    Upgrade to a later release of FileSync that includes the fix for this issue.

    If you're not able to upgrade immediately, contact SecureAuth Support for the interim workaround. It requires temporarily disabling FileSync's replication of the SecureStore between the Primary and Secondary servers using a modified idpservices.list file, which Support can provide — while this workaround is in place, a service account password change has to be copied from the Primary to each Secondary manually.


     

    SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.

    Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.

    0 out of 0 found this helpful

    Comments

    0 comments

    Please sign in to leave a comment.