æ¤ç›‘视器指示è”åˆèº«ä»½éªŒè¯æœåŠ¡æœªèƒ½åŠ 载其令牌ç¾åã€ä»¤ç‰Œè§£å¯†å’Œ SSL è¯ä¹¦ã€‚如果失败的è¯ä¹¦æ˜¯ä¸»è¯ä¹¦ï¼ŒAD FS Windows æœåŠ¡å°†æ— 法å¯åŠ¨ã€‚
如果在 15 分钟之内没有å†æ¬¡å‘生åŒæ ·çš„问题,æ¤ç›‘视器的è¿è¡ŒçŠ¶å†µçŠ¶æ€å°†å˜å›žç»¿è‰²çŠ¶æ€ã€‚è¦æŠ¥è§„则生æˆç›¸åº”çš„è¦æŠ¥å¿…须手动解除。
以下是æ¤äº‹ä»¶çš„å¯èƒ½åŽŸå› :
在与æ¤äº‹ä»¶ä¸æ‰€æä¾› X.509 è¯ä¹¦ç§é’¥å…±äº«ç›¸å…³çš„诊æ–ä¿¡æ¯ä¸çš„指定å¯åˆ†è¾¨å称下,缺少 Active Directory 对象。
诊æ–ä¿¡æ¯ä¸æ‰€æŒ‡å®šçš„ Active Directory 对象的访问控制列表 (ACL) æƒé™å·²æ›´æ”¹ï¼ŒAD FS çš„æœåŠ¡æ ‡è¯†ä¸å†æœ‰æƒé™è¯»å–或修改这些对象。
以下是æ¤äº‹ä»¶å¯èƒ½çš„解决方案:
您å¯èƒ½éœ€è¦è¿˜åŽŸæ¤äº‹ä»¶æ‰€å«è¯Šæ–ä¿¡æ¯ä¸æŒ‡å®šçš„å¯åˆ†è¾¨å称下的全部 Active Directory 对象。
在域管ç†å‘˜çš„å作下还原读/写 ACL æƒé™ã€‚
Target | Microsoft.ActiveDirectoryFederationServices.2016.CertificateManagement | ||
Parent Monitor | System.Health.ConfigurationState | ||
Category | ConfigurationHealth | ||
Enabled | True | ||
Alert Generate | True | ||
Alert Severity | Warning | ||
Alert Priority | Normal | ||
Alert Auto Resolve | True | ||
Monitor Type | Microsoft.Windows.SingleEventLogTimer2StateMonitorType | ||
Remotable | True | ||
Accessibility | Public | ||
Alert Message |
| ||
RunAs | Default |
<UnitMonitor ID="Microsoft.ActiveDirectoryFederationServices.2016.CertificateManagementDKMCertificateKeyLoadWarningMonitor" Accessibility="Public" Enabled="true" Target="Microsoft.ActiveDirectoryFederationServices.2016.CertificateManagement" ParentMonitorID="Health!System.Health.ConfigurationState" Remotable="true" Priority="Normal" TypeID="Windows!Microsoft.Windows.SingleEventLogTimer2StateMonitorType" ConfirmDelivery="true">
<Category>ConfigurationHealth</Category>
<AlertSettings AlertMessage="Microsoft.ActiveDirectoryFederationServices.2016.CertificateManagementDKMCertificateKeyLoadWarningMonitor_AlertMessageResourceID">
<AlertOnState>Warning</AlertOnState>
<AutoResolve>true</AutoResolve>
<AlertPriority>Normal</AlertPriority>
<AlertSeverity>Warning</AlertSeverity>
</AlertSettings>
<OperationalStates>
<OperationalState ID="EventRaised" MonitorTypeStateID="EventRaised" HealthState="Warning"/>
<OperationalState ID="TimerEventRaised" MonitorTypeStateID="TimerEventRaised" HealthState="Success"/>
</OperationalStates>
<Configuration>
<ComputerName>$Target/Host/Host/Host/Property[Type="Windows!Microsoft.Windows.Computer"]/NetworkName$</ComputerName>
<LogName>$Target/Host/Property[Type="Microsoft.ActiveDirectoryFederationServices.2016.FederationServer"]/ADFSEventLog$</LogName>
<Expression>
<Or>
<Expression>
<And>
<Expression>
<SimpleExpression>
<ValueExpression>
<XPathQuery Type="UnsignedInteger">EventDisplayNumber</XPathQuery>
</ValueExpression>
<Operator>Equal</Operator>
<ValueExpression>
<Value Type="UnsignedInteger">329</Value>
</ValueExpression>
</SimpleExpression>
</Expression>
<Expression>
<RegExExpression>
<ValueExpression>
<XPathQuery Type="String">PublisherName</XPathQuery>
</ValueExpression>
<Operator>MatchesMOM2005RegularExpression</Operator>
<Pattern>(^AD FS$)</Pattern>
</RegExExpression>
</Expression>
</And>
</Expression>
<Expression>
<And>
<Expression>
<SimpleExpression>
<ValueExpression>
<XPathQuery Type="UnsignedInteger">EventDisplayNumber</XPathQuery>
</ValueExpression>
<Operator>Equal</Operator>
<ValueExpression>
<Value Type="UnsignedInteger">331</Value>
</ValueExpression>
</SimpleExpression>
</Expression>
<Expression>
<RegExExpression>
<ValueExpression>
<XPathQuery Type="String">PublisherName</XPathQuery>
</ValueExpression>
<Operator>MatchesMOM2005RegularExpression</Operator>
<Pattern>(^AD FS$)</Pattern>
</RegExExpression>
</Expression>
</And>
</Expression>
<Expression>
<And>
<Expression>
<SimpleExpression>
<ValueExpression>
<XPathQuery Type="UnsignedInteger">EventDisplayNumber</XPathQuery>
</ValueExpression>
<Operator>Equal</Operator>
<ValueExpression>
<Value Type="UnsignedInteger">332</Value>
</ValueExpression>
</SimpleExpression>
</Expression>
<Expression>
<RegExExpression>
<ValueExpression>
<XPathQuery Type="String">PublisherName</XPathQuery>
</ValueExpression>
<Operator>MatchesMOM2005RegularExpression</Operator>
<Pattern>(^AD FS$)</Pattern>
</RegExExpression>
</Expression>
</And>
</Expression>
</Or>
</Expression>
<TimerWaitInSeconds>900</TimerWaitInSeconds>
</Configuration>
</UnitMonitor>