Quantcast
Channel: SQL Server High Availability and Disaster Recovery forum
Viewing all articles
Browse latest Browse all 4532

Setting up availability group listener in security-constrained environment

$
0
0

I am attempting to set up an availability group for a client.  This AG is on two subnets and is composed of three nodes.  Problems are arising attempting to create an availability group.

I have a situation where the client requires the computer objects to be created in a non-default AD container.  This worked fine for the cluster name object, but creating the availability group listener entry is posing problems.

1 - if I attempt to allow the listener creation process to create the AD computer object, it attempts to create it in the default computer group, rather than in the container in which the cluster name object is stored, which causes a failure.  Is there a way to force creation in a non-default container?

2 - if I attempt to pre-stage the listener in the correct container, the cluster logs tell me that the object is found, but the first time the cluster attempts to update a property of the listener object, it fails.  Attempting to add a disabled listener account fails on an attempt to re-enable it, and attempting to add an enabled listener account fails on an attempt to modify the password.

I have verified that the cluster name object computer account has full control over the listener object, and the cluster account has "create computer object" permissions in its own container.  What  could be causing this update to fail?

Any ideas would be appreciated,

Thanks,

John


Viewing all articles
Browse latest Browse all 4532

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>