• Recent
    • Unsolved
    • Tags
    • Popular
    • Users
    • Groups
    • Search
    • Register
    • Login

    Problem with domain join after deployement

    Scheduled Pinned Locked Moved Solved
    FOG Problems
    2
    31
    4.1k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      Sebastian Roth Moderator
      last edited by

      @benjamind Try resetting the encryption data in the host settings of the web ui and see if that helps.

      Web GUI issue? Please check apache error (debian/ubuntu: /var/log/apache2/error.log, centos/fedora/rhel: /var/log/httpd/error_log) and php-fpm log (/var/log/php*-fpm.log)

      Please support FOG if you like it: https://wiki.fogproject.org/wiki/index.php/Support_FOG

      1 Reply Last reply Reply Quote 0
      • B
        benjamind
        last edited by

        @Sebastian-Roth I can’t find the “Reset encryption data” button :

        f5e1ef10-4b95-4a55-b6d5-2387c235652f-image.png

        1 Reply Last reply Reply Quote 0
        • S
          Sebastian Roth Moderator
          last edited by

          @benjamind There is no MAC address set for this host? Might explain the problem as well?!?!

          Web GUI issue? Please check apache error (debian/ubuntu: /var/log/apache2/error.log, centos/fedora/rhel: /var/log/httpd/error_log) and php-fpm log (/var/log/php*-fpm.log)

          Please support FOG if you like it: https://wiki.fogproject.org/wiki/index.php/Support_FOG

          1 Reply Last reply Reply Quote 0
          • B
            benjamind
            last edited by

            @Sebastian-Roth I have edited the image to erase the MAC address but it is configured.

            1 Reply Last reply Reply Quote 0
            • B
              benjamind
              last edited by

              Hi,

              Does anyone , please, got an idea to solve my problem ?

              Thanks.

              1 Reply Last reply Reply Quote 0
              • S
                Sebastian Roth Moderator
                last edited by

                @benjamind Do you see this exact same error (``) on all your machines or is it just one single one?

                Please check if you have a file C:\Program Files (x86)\FOG\token.dat. I suppose you have that as the logs you posted don’t mention creating it. Please go to Windows service management, stop FOGService, rename the mentioned token.dat, start FOGService and keep an eye on the log again. Please post the full log starting from when you renamed that token.dat again.

                Web GUI issue? Please check apache error (debian/ubuntu: /var/log/apache2/error.log, centos/fedora/rhel: /var/log/httpd/error_log) and php-fpm log (/var/log/php*-fpm.log)

                Please support FOG if you like it: https://wiki.fogproject.org/wiki/index.php/Support_FOG

                1 Reply Last reply Reply Quote 0
                • B
                  benjamind
                  last edited by

                  @Sebastian-Roth Thanks for your return.

                  What error are you talking about exactly?

                  All our machines can’t join the domain automatically after a deployment by Fog. Do you talk about a specific error message from the fog.log ?

                  I’m doing a deployment again now and I’ll check if I have the file when it will be finished. I’ll keep you update.

                  1 Reply Last reply Reply Quote 0
                  • B
                    benjamind
                    last edited by

                    @Sebastian-Roth Here is the fog.log starting from when i renamed the token.dat.

                    1 Reply Last reply Reply Quote 0
                    • S
                      Sebastian Roth Moderator
                      last edited by

                      @benjamind Sorry, missed to paste the error message last time: Middleware::Response Failed to decrypt data

                      Here is the fog.log starting from when i renamed the token.dat.

                      Did you restart the FOG Service or the whole machine after renaming? Just want to make sure.

                      Can you please run the following commands on your FOG server and post output here [1]:

                      openssl x509 -dates -noout -in /var/www/fog/management/other/ssl/srvpublic.crt
                      openssl x509 -dates -noout -in /var/www/fog/management/other/ca.cert.pem
                      

                      Web GUI issue? Please check apache error (debian/ubuntu: /var/log/apache2/error.log, centos/fedora/rhel: /var/log/httpd/error_log) and php-fpm log (/var/log/php*-fpm.log)

                      Please support FOG if you like it: https://wiki.fogproject.org/wiki/index.php/Support_FOG

                      1 Reply Last reply Reply Quote 0
                      • B
                        benjamind
                        last edited by

                        @Sebastian-Roth I have restarted the FOG service.

                        root@fog:~# openssl x509 -dates -noout -in /var/www/fog/management/other/ssl/srvpublic.crt
                        notBefore=Sep  3 09:07:28 2018 GMT
                        notAfter=Aug 31 09:07:28 2028 GMT
                        root@fog:~# openssl x509 -dates -noout -in /var/www/fog/management/other/ca.cert.pem
                        notBefore=Nov 24 09:57:37 2016 GMT
                        notAfter=Nov 22 09:57:37 2026 GMT
                        
                        1 Reply Last reply Reply Quote 0
                        • S
                          Sebastian Roth Moderator
                          last edited by

                          @benjamind I am wondering, why is the server cert roughly two years younger than the CA? Did you update that server cert by intention last September?

                          Web GUI issue? Please check apache error (debian/ubuntu: /var/log/apache2/error.log, centos/fedora/rhel: /var/log/httpd/error_log) and php-fpm log (/var/log/php*-fpm.log)

                          Please support FOG if you like it: https://wiki.fogproject.org/wiki/index.php/Support_FOG

                          1 Reply Last reply Reply Quote 0
                          • B
                            benjamind
                            last edited by

                            @Sebastian-Roth Sorry, i give you the return on the commands form an other FOG server. Here is the return form the concerned server :

                            root@fog-dev:~# openssl x509 -dates -noout -in /var/www/fog/management/other/ssl/srvpublic.crt
                            notBefore=Mar 14 07:16:32 2019 GMT
                            notAfter=Mar 11 07:16:32 2029 GMT
                            root@fog-dev:~# openssl x509 -dates -noout -in /var/www/fog/management/other/ca.cert.pem
                            notBefore=Apr 5 13:49:36 2018 GMT
                            notAfter=Apr 2 13:49:36 2028 GMT

                            The srvprublic.crt date corresponds to our last FOG update from 1.5.0 to 1.5.5 and the ca.cert.pem should corresponds to the first installation of the server.

                            Is it a normal behaviour ?

                            1 Reply Last reply Reply Quote 0
                            • S
                              Sebastian Roth Moderator
                              last edited by Sebastian Roth

                              @benjamind Which command line options did you choose when updating?

                              @Tom-Elliott Any ideas??

                              Web GUI issue? Please check apache error (debian/ubuntu: /var/log/apache2/error.log, centos/fedora/rhel: /var/log/httpd/error_log) and php-fpm log (/var/log/php*-fpm.log)

                              Please support FOG if you like it: https://wiki.fogproject.org/wiki/index.php/Support_FOG

                              1 Reply Last reply Reply Quote 0
                              • B
                                benjamind
                                last edited by

                                @Sebastian-Roth Here is is the commands i used to update our server :
                                cd /root/fogproject/
                                git pull
                                cd bin/
                                ./installfog.sh

                                1 Reply Last reply Reply Quote 0
                                • S
                                  Sebastian Roth Moderator
                                  last edited by Sebastian Roth

                                  @benjamind Sorry, my fault. I went down the wrong road. CA cert should not be renewed (unless you specify so using command line options) but the server cert is renewed on FOG updates.

                                  We might need to take a look into your database to see if there are tokens pending that you don’t see in the host settings.

                                  Web GUI issue? Please check apache error (debian/ubuntu: /var/log/apache2/error.log, centos/fedora/rhel: /var/log/httpd/error_log) and php-fpm log (/var/log/php*-fpm.log)

                                  Please support FOG if you like it: https://wiki.fogproject.org/wiki/index.php/Support_FOG

                                  1 Reply Last reply Reply Quote 0
                                  • B
                                    benjamind
                                    last edited by

                                    @Sebastian-Roth What do you want to verify precisely on the database ?

                                    1 Reply Last reply Reply Quote 0
                                    • S
                                      Sebastian Roth Moderator
                                      last edited by

                                      @benjamind Try SELECT hostID,hostName,hostSecToken FROM hosts WHERE hostName LIKE '%PC2409M%';

                                      Web GUI issue? Please check apache error (debian/ubuntu: /var/log/apache2/error.log, centos/fedora/rhel: /var/log/httpd/error_log) and php-fpm log (/var/log/php*-fpm.log)

                                      Please support FOG if you like it: https://wiki.fogproject.org/wiki/index.php/Support_FOG

                                      1 Reply Last reply Reply Quote 0
                                      • B
                                        benjamind
                                        last edited by Sebastian Roth

                                        @Sebastian-Roth

                                        MariaDB [fog]> SELECT hostID,hostName,hostSecToken FROM hosts WHERE hostName LIKE ‘%PC2409M%’;

                                        +------------+-------------------+-------------------------+
                                        | hostID     | hostName          | hostSecToken            |
                                        +------------+-------------------+-------------------------+
                                        | 61         | PC2409M           |                         |
                                        +------------+-------------------+-------------------------+
                                        
                                        1 Reply Last reply Reply Quote 0
                                        • B
                                          benjamind
                                          last edited by

                                          Hi @Sebastian-Roth,

                                          Is the result of the command indicative ?

                                          1 Reply Last reply Reply Quote 0
                                          • S
                                            Sebastian Roth Moderator
                                            last edited by

                                            @benjamind Sorry for the deplay. Have been on travels over the weekend. The output is showing an empty sectoken field. So we need to look at other possibilites why this is going wrong.

                                            We have not had much requests from people with the error message “Failed to decrypt data” lately. All the old ones were due to an issue in the FOG server as far as I know but that shouldn’t be the case with FOG version 1.5.5 (which we see you have in the logs).

                                            Do you see that same error message on several (or all) of your clients?

                                            Could you please install tcpdump on your FOG server. Then stop the FOGService on your client run tcpdump -w fog-client.pcap host x.x.x.x and port 80 on your FOG server and start the FOGService on the client.

                                            Put in the client PC’s IP address instead of x.x.x.x and just leave the command for 30 seconds - then stop it with Ctrl+c and upload the resulting fog-client.pcap file to an online drive and post a link here. We should see the HTTP communication between FOG server and your client in that file. Hopefully we can figure out what’s going on.

                                            Web GUI issue? Please check apache error (debian/ubuntu: /var/log/apache2/error.log, centos/fedora/rhel: /var/log/httpd/error_log) and php-fpm log (/var/log/php*-fpm.log)

                                            Please support FOG if you like it: https://wiki.fogproject.org/wiki/index.php/Support_FOG

                                            1 Reply Last reply Reply Quote 0
                                            • 1
                                            • 2
                                            • 1 / 2
                                            • First post
                                              Last post

                                            128

                                            Online

                                            12.1k

                                            Users

                                            17.3k

                                            Topics

                                            155.3k

                                            Posts
                                            Copyright © 2012-2024 FOG Project