<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unable to log into ArcGIS Server Manager after Federating in ArcGIS Enterprise Portal Questions</title>
    <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/unable-to-log-into-arcgis-server-manager-after/m-p/567973#M7769</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A workaround!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The actual issue appears to be a lack of support for SNI in the ArcGIS Server proxy. &amp;nbsp;Our web server was set up with multiple sites, each bound to a FQDN. &amp;nbsp;On a hunch, I added a default HTTPS binding to the site that contains the Portal Web Adaptor and things began working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At one point I did have a default binding on the site in order to configure the Web Adaptor (so I could use &lt;A href="https://localhost/"&gt;https://localhost/&lt;/A&gt;&amp;nbsp;to get at the configuration page), which is why it worked for a while and then "stopped". &amp;nbsp;At the time, I didn't associate removing the default binding with the loading failures.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is an Esri &lt;A href="http://support.esri.com/bugs/nimbus/QlVHLTAwMDA5MzgyNw=="&gt;BUG-000093827&lt;/A&gt; that discusses an issue with the Portal proxy and SNI support that was fixed in 10.4.1, but nothing I could find that discussed the state of SNI support in the ArcGIS Server proxy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm hoping to get a resolution from Esri support that either&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Confirms this as a bug in the AGS proxy, or&lt;/LI&gt;&lt;LI&gt;Provides some details on how to enable SNI support&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For now, moving on from this issue....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;TLS Extension List sent from ArcGIS Server&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;extensions [extension_type: elliptic_curves,extension_type: ec_point_formats,extension_type: signature_algorithms]&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;TLS Extension List sent from Chrome Browser&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;extensions [extension_type: 31354,extension_type: renegotiation_info,&lt;STRONG&gt;extension_type: server_name&lt;/STRONG&gt;,extension_type: extended_master_secret,extension_type: SessionTicket_TLS,extension_type: signature_algorithms,extension_type: status_request,extension_type: 18,extension_type: application_layer_protocol_negotiation,extension_type: 30032,extension_type: ec_point_formats,extension_type: elliptic_curves,extension_type: 10794]&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 13 Jun 2017 17:02:45 GMT</pubDate>
    <dc:creator>LucasScharenbroich</dc:creator>
    <dc:date>2017-06-13T17:02:45Z</dc:date>
    <item>
      <title>Unable to log into ArcGIS Server Manager after Federating</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/unable-to-log-into-arcgis-server-manager-after/m-p/567959#M7755</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have federated Portal 10.5 with a single-machine ArcGIS Server 10.5 site. &amp;nbsp;Portal is configured to use Active Directory for its Identity Store. Portal and ArcGIS Server are on different virtual servers and their respective web adaptors are on a separate Web Server and configured under different IIS sites. I have done ArcGIS Enterprise Basic deployment in the past successfully.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This table summarized the configuration&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE class="j-table jiveBorder" style="border: 1px solid #c6c6c6;" width="100%"&gt;&lt;THEAD&gt;&lt;TR style="background-color: #efefef;"&gt;&lt;TH&gt;URL&lt;/TH&gt;&lt;TH&gt;Description&lt;/TH&gt;&lt;/TR&gt;&lt;/THEAD&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;A class="jive-link-external-small" href="https://community.esri.com/external-link.jspa?url=https%3A%2F%2Fags-web-dev.mydomain.org%2Fserver" rel="nofollow" target="_blank"&gt;https://ags-web-dev.mydomain.org/server&lt;/A&gt;&lt;/TD&gt;&lt;TD&gt;Web Adaptor pointing to the ArcGIS Server&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;A class="jive-link-external-small" href="https://community.esri.com/external-link.jspa?url=https%3A%2F%2Fags-web.mydomain.org%2Fportal" rel="nofollow" target="_blank"&gt;https://ags-web.mydomain.org/portal&lt;/A&gt;&lt;/TD&gt;&lt;TD&gt;Web Adaptor pointing to the Portal for ArcGIS Site&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;A class="jive-link-external-small" href="https://community.esri.com/external-link.jspa?url=https%3A%2F%2Fags-dev.mydomain.org%3A6443%2Farcgis" rel="nofollow" target="_blank"&gt;https://ags-dev.mydomain.org:6443/arcgis&lt;/A&gt;&lt;/TD&gt;&lt;TD&gt;Direct URL to the ArcGIS Server machine&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;A class="jive-link-external-small" href="https://community.esri.com/external-link.jspa?url=https%3A%2F%2Fags-portal.mydomain.org%3A7443%2Farcgis" rel="nofollow" target="_blank"&gt;https://ags-portal.mydomain.org:7443/arcgis&lt;/A&gt;&lt;/TD&gt;&lt;TD&gt;Direct URL to the Portal for ArcGIS&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;/TD&gt;&lt;TD&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Almost everything appears to work correctly. &amp;nbsp;For example&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;I can log into Portal using the primary site administrator account&lt;/LI&gt;&lt;LI&gt;I can log into Portal using my Domain account&lt;/LI&gt;&lt;LI&gt;After Federating, all of the ArcGIS Server services appeared as Portal items, as expected&lt;/LI&gt;&lt;LI&gt;I can log into the ArcGIS Server Administrative service directory using the ArcGIS Server site administrator credentials, or by manually generating a Portal token.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only issue if that attempting to open ArcGIS Server Manager fail. &amp;nbsp;The interface hangs on the "Please wait..." progress bar and the network traffic shows repeated failures to POST to the portal generateToken page via the ArcGIS Server proxy&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://ags-dev.openspace.org:6443/arcgis/manager/proxy?_proxyUrl=https%3A%2F%2Fags-web.openspace.org%2Fportal%2Fsharing%2FgenerateToken" title="https://ags-dev.openspace.org:6443/arcgis/manager/proxy?_proxyUrl=https%3A%2F%2Fags-web.openspace.org%2Fportal%2Fsharing%2FgenerateToken"&gt;https://ags-dev.mydomain.org:6443/arcgis/manager/proxy?_proxyUrl=https%3A%2F%2Fags-web.mydomain.org%2Fportal%2Fsharing…&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The network inspector shows that ArcGIS Server returned a 500 server error caused by a "Connection closed" (see screenshot).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are there any good ways to go about diagnosing the root cause of an issue like this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Update&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Installing Fiddler and enabling HTTPS traffic snooping shows that request is being sent from the ArcGIS Server machine to the Portal Web Adaptor.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This may be a side-effect of enabling Fiddler as a MITM proxy, but the Portal logs show this WARNING:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14.4px;"&gt;&lt;SPAN&gt;ArcGIS Server services URL '&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://community.esri.com/external-link.jspa?url=https%3A%2F%2Fags-web-dev.mydomain.org%2Fserver" rel="nofollow" target="_blank"&gt;https://ags-web-dev.mydomain.org/server&lt;/A&gt;&lt;SPAN&gt;' cannot be validated against '&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://community.esri.com/external-link.jspa?url=https%3A%2F%2Fags-web-dev.mydomain.org%2Fserver%2Frest%2Finfo" rel="nofollow" target="_blank"&gt;https://ags-web-dev.mydomain.org/server/rest/info&lt;/A&gt;&lt;SPAN&gt;'. If the service URL is a proxy URL verify it is accessible to clients.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14.4px;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14.4px;"&gt;The JSON at the /info endpoint is&lt;/SPAN&gt;&lt;/P&gt;&lt;PRE&gt;{&amp;nbsp; "currentVersion": 10.5,&amp;nbsp; "fullVersion": "10.5.0",&amp;nbsp; "soapUrl": "https://ags-web-dev.mydomain.org/server/services",&amp;nbsp; "secureSoapUrl": null,&amp;nbsp; "owningSystemUrl": "https://ags-web.mydomain.org/portal",&amp;nbsp; "authInfo": {&amp;nbsp;&amp;nbsp; "isTokenBasedSecurity": true,&amp;nbsp;&amp;nbsp; "tokenServicesUrl": "https://ags-web.mydomain.org/portal/sharing/generateToken"&amp;nbsp; } }&lt;/PRE&gt;&lt;P&gt;What information is being used to attempt this 'validation'?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Jun 2017 20:40:07 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/unable-to-log-into-arcgis-server-manager-after/m-p/567959#M7755</guid>
      <dc:creator>LucasScharenbroich</dc:creator>
      <dc:date>2017-06-02T20:40:07Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to log into ArcGIS Server Manager after Federating</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/unable-to-log-into-arcgis-server-manager-after/m-p/567960#M7756</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hm, so I think that when either Server or Portal use their respective proxies, the request is actually made from the software itself as the user running the software's service. &amp;nbsp;I'm more certain this is the case for the Portal going through the sharing proxy, so I'm guessing that it's the same for Server. &amp;nbsp;So, if we assume that's correct, what you can try to do is reach the Sharing API through the Portal web adaptor on the Server machine when you're logged in as the account running the ArcGIS Server Windows service. &amp;nbsp;That will tell you if the URL it's proxying to can be reached by the Server as the account running the service. &amp;nbsp;Another thing you can try is to sign into the Portal website and then bring up Server Manager, as that'll automatically sign you in with the cookies already present in the browser.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Jun 2017 21:28:54 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/unable-to-log-into-arcgis-server-manager-after/m-p/567960#M7756</guid>
      <dc:creator>JonathanQuinn</dc:creator>
      <dc:date>2017-06-02T21:28:54Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to log into ArcGIS Server Manager after Federating</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/unable-to-log-into-arcgis-server-manager-after/m-p/567961#M7757</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'll try logging in as the ArcGIS Service account and see if that makes a difference.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regarding logging into Portal first, that is actually how I discovered the issue. &amp;nbsp;I had just Federated the server and clicked on the server link in the Portal Server setting page, which pointed to the server manager page.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I may not have verified that I was logged into Portal on subsequent tests, so I'll double-check that being logged into Portal does not change the behavior.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the suggestions.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 04 Jun 2017 13:36:33 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/unable-to-log-into-arcgis-server-manager-after/m-p/567961#M7757</guid>
      <dc:creator>LucasScharenbroich</dc:creator>
      <dc:date>2017-06-04T13:36:33Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to log into ArcGIS Server Manager after Federating</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/unable-to-log-into-arcgis-server-manager-after/m-p/567962#M7758</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have seen&amp;nbsp;the "Please wait..." message hang, too. I believe it to be an issue with the browser. Do you get the "Not secure" message at the top of your browser? I'm using Chrome, and sometimes when I get that message I get the "Your connection is not private" message, then I go on to 'Advanced' and 'Proceed', then I get to Server Manager. When the browser hangs at "Please wait", I think it is due to that error message, except that it isn't presented to me to proceed around it.&amp;nbsp;If I go back or refresh I'll usually get the privacy error, then I can move on.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Jun 2017 15:53:05 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/unable-to-log-into-arcgis-server-manager-after/m-p/567962#M7758</guid>
      <dc:creator>CarolSousa</dc:creator>
      <dc:date>2017-06-05T15:53:05Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to log into ArcGIS Server Manager after Federating</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/unable-to-log-into-arcgis-server-manager-after/m-p/567963#M7759</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you're using &amp;nbsp;the default self-signed certificate on 6443, that is actually related to Chrome losing the exception you've made for the self signed certificate. &amp;nbsp;What happens is the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) &amp;nbsp;You try to reach Manager over 6443. &amp;nbsp;Chrome sees that this is a self-signed certificate so you're asked if you want to proceed or not. &amp;nbsp;You select Proceed.&lt;/P&gt;&lt;P&gt;2) &amp;nbsp;Since you're trying to reach a federated Server, you're redirected to the Portal sign in page. &amp;nbsp;This is where the initial exception for the self signed certificate is lost.&lt;/P&gt;&lt;P&gt;3) &amp;nbsp;Once provide your credentials, you're redirected back to Server Manager. &amp;nbsp;Since the initial exception has been lost, and for whatever reason Chrome doesn't prompt you to proceed again, the rest of the requests to Server Manager don't go through. &amp;nbsp;You should see INSECURE_RESPONSE errors or something similar in the dev tools in Chrome.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is reproducible outside of Server Manager and Portal as well. &amp;nbsp;IE and Firefox don't have this problem.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Jun 2017 16:00:48 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/unable-to-log-into-arcgis-server-manager-after/m-p/567963#M7759</guid>
      <dc:creator>JonathanQuinn</dc:creator>
      <dc:date>2017-06-05T16:00:48Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to log into ArcGIS Server Manager after Federating</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/unable-to-log-into-arcgis-server-manager-after/m-p/567964#M7760</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've got domain certificates on all the Enterprise machines. But I should use IE or Firefox. Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Jun 2017 16:12:19 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/unable-to-log-into-arcgis-server-manager-after/m-p/567964#M7760</guid>
      <dc:creator>CarolSousa</dc:creator>
      <dc:date>2017-06-05T16:12:19Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to log into ArcGIS Server Manager after Federating</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/unable-to-log-into-arcgis-server-manager-after/m-p/567965#M7761</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have seen the behavior you describe caused by self-signed or incorrect SSL certificate, however in this case we do have proper certificates installed on both the ArcGIS Server, Portal and Web Adaptors in IIS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have added a screenshot of the browser when connected to the Manager page with the SSL credentials shown. &amp;nbsp;Please let me know if you see anything amiss in this settings.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The issue seems to be pretty clearly caused by a network connection being terminated when the ArcGIS Server proxy page attempts to connect to the Portal generateToken page via the Portal Web Adaptor. &amp;nbsp;This behavior is confirmed by the ArcGIS Server error page that was captured from the Web Server network inspector, and by monitoring the traffic between the ArcGIS Server and Web Adaptors via Fiddler.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am waiting on IT to grant remote login privileges to the ArcGIS Server domain account in order to test Johnathan Quinn's suggestion of verifying that the ArcGIS Server process identity is not being blocked due to external policy considerations.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Jun 2017 16:17:33 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/unable-to-log-into-arcgis-server-manager-after/m-p/567965#M7761</guid>
      <dc:creator>LucasScharenbroich</dc:creator>
      <dc:date>2017-06-05T16:17:33Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to log into ArcGIS Server Manager after Federating</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/unable-to-log-into-arcgis-server-manager-after/m-p/567966#M7762</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;New information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Logging in as the ArcGIS Server service account made no difference.&lt;/LI&gt;&lt;LI&gt;I created two python scripts on the ArcGIS Server, one that POSTs to the /proxy page and one that POST directly to the generateToken URL that is trying to be proxied. Each has appropriate headers and body content. &amp;nbsp;The first script returns the same ArcGIS Server error page as shown in the network panel screenshot and the second succeed and returns a token from Portal.&lt;/LI&gt;&lt;LI&gt;For a few hours today things started working and I was able to log into ArcGIS Server Manager. &amp;nbsp;The IT staff I'm in contact with stated that they had not made any changes. &amp;nbsp;A few hours later and the error returned. Very strange.&lt;/LI&gt;&lt;LI&gt;Turning on DEBUG level logging in the ArcGIS Server doesn't show anything specific, but there are these entries that appear to be somewhat related to the issue at hand,&lt;OL&gt;&lt;LI&gt;&lt;SPAN style="color: #000000; background-color: #f1e1e1; font-weight: bold; font-size: 14.4px;"&gt;&lt;SPAN&gt;Token is not a valid Admin token. Trying portal token next. Token = 8_AptoTJ86nrEVK5hBnnfD-9C7LzVwrcQNoFgnLNkMh1PkFTV8ssh4EyaDOknlAYQmygXFCykSiYl2_xnp178FKqk2tNBc0tvQ8JpV05r5dFXvElHufzydxeMsIfImSk3QNklmn1obIstorWPo2s_U8GFhk4gq3LLUpu8KcClOo8f7vAhgta4C3d2Fl09OA0, referrer = &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://community.esri.com/external-link.jspa?url=https%3A%2F%2Fags-dev.mydomain.org%3A6443%2Farcgis%2Fmanager%2FCould" rel="nofollow" target="_blank"&gt;https://ags-dev.mydomain.org:6443/arcgis/manager/Could&lt;/A&gt;&lt;SPAN&gt; not decrypt token. Token may not be valid.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-weight: bold; font-size: 14.4px;"&gt;ARCGIS_PORTAL_TOKEN Authentication, Token is not available in the request, request is treated as anonymous&lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Jun 2017 04:06:45 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/unable-to-log-into-arcgis-server-manager-after/m-p/567966#M7762</guid>
      <dc:creator>LucasScharenbroich</dc:creator>
      <dc:date>2017-06-07T04:06:45Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to log into ArcGIS Server Manager after Federating</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/unable-to-log-into-arcgis-server-manager-after/m-p/567967#M7763</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;More information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;I’ve attached a network trace of the traffic captured between our ArcGIS Server and the Web Server that hosts the Web Adaptor for Portal.&amp;nbsp; It appears that the Web Server (192.168.103.50) is sending a TCP Reset packet in response to the CLIENT HELLO send by the ArcGIS Server.&amp;nbsp; This process repeats a few times and then, apparently, the ArcGIS Server side gives up.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;We actually have three ArcGIS Servers set up right now (1 dev, 2 production) and the same error is happening in all cases, so it appears to be something systemic and specific to how the proxy page and/or tomcat/geronimo/Java is handling it's networking.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;Might be time to write a test client in Java and see if that behaves the same as ArcGIS Sever....&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Jun 2017 13:23:44 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/unable-to-log-into-arcgis-server-manager-after/m-p/567967#M7763</guid>
      <dc:creator>LucasScharenbroich</dc:creator>
      <dc:date>2017-06-09T13:23:44Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to log into ArcGIS Server Manager after Federating</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/unable-to-log-into-arcgis-server-manager-after/m-p/567968#M7764</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Getting closer to a resolution. &amp;nbsp;It appears that this is likely an IIS/SSL issue related to certificate negotiation. &amp;nbsp;The IIS Web Server we are using has an ECC certificate installed (versus the more common RSA signed certificate) and that appears to be problematic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We had an issue when installing ECC certificates on ArcGIS Server, as well. &amp;nbsp;Chrome and other broswers reported that they could not negotiate a common cipher and the connection failed. We ended up using RSA certificates instead. The same type of issue appears to be in play here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some relevant stackexchange posts on this issue&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;&lt;A href="https://security.stackexchange.com/questions/96804/server-sends-rst-after-receiving-client-hello-when-binding-certain-certificate"&gt;https://security.stackexchange.com/questions/96804/server-sends-rst-after-receiving-client-hello-when-binding-certain-certificate&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;&lt;A href="https://serverfault.com/questions/774826/tls-1-2-client-hello-triggers-tcp-reset-from-2012-r2"&gt;https://serverfault.com/questions/774826/tls-1-2-client-hello-triggers-tcp-reset-from-2012-r2&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Jun 2017 14:34:12 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/unable-to-log-into-arcgis-server-manager-after/m-p/567968#M7764</guid>
      <dc:creator>LucasScharenbroich</dc:creator>
      <dc:date>2017-06-09T14:34:12Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to log into ArcGIS Server Manager after Federating</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/unable-to-log-into-arcgis-server-manager-after/m-p/567969#M7765</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ah, ok, I have a basic understanding of certificates, not to the degree to know the difference between ECC and RSA. &amp;nbsp;You may want to reach out to Technical Support so they can investigate whether there's a problem with a certain certificate type in the software.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Jun 2017 17:43:08 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/unable-to-log-into-arcgis-server-manager-after/m-p/567969#M7765</guid>
      <dc:creator>JonathanQuinn</dc:creator>
      <dc:date>2017-06-09T17:43:08Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to log into ArcGIS Server Manager after Federating</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/unable-to-log-into-arcgis-server-manager-after/m-p/567970#M7766</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have had an open support case concurrent with this thread and have cross-referenced customer support to this topic as well. &amp;nbsp;Hopefully the specific failure mechanism will be found soon...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Jun 2017 15:36:04 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/unable-to-log-into-arcgis-server-manager-after/m-p/567970#M7766</guid>
      <dc:creator>LucasScharenbroich</dc:creator>
      <dc:date>2017-06-12T15:36:04Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to log into ArcGIS Server Manager after Federating</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/unable-to-log-into-arcgis-server-manager-after/m-p/567971#M7767</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Portal and server support ECDHE (Elliptic-curve Diffie Hellman) key exchanges. Is your listed here:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://server.arcgis.com/en/server/latest/administer/windows/restrict-arcgis-server-ssl-protocols-and-cipher-suites.htm"&gt;https://server.arcgis.com/en/server/latest/administer/windows/restrict-arcgis-server-ssl-protocols-and-cipher-suites.htm&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Jun 2017 17:25:15 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/unable-to-log-into-arcgis-server-manager-after/m-p/567971#M7767</guid>
      <dc:creator>RandallWilliams</dc:creator>
      <dc:date>2017-06-12T17:25:15Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to log into ArcGIS Server Manager after Federating</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/unable-to-log-into-arcgis-server-manager-after/m-p/567972#M7768</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The original certificates that were installed on IIS were ECDHE_ECDSE &amp;nbsp;which were not on the list. After discovering that discrepancy, IT installed new certificates that are ECDHE_RSA with P384.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My understanding is that the block cipher and message authentication are negotiated and, according to the Chrome Security toolbar, it can connect with AES_256_CBC_SHA1 (AES_256_CBC with HMAC_SHA1, specifically). That would appear to match the TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA entry in the list of supported ArcGIS Server ciphers, so our expectation was that ArcGIS Server would (at least) be able to use that cipher as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unfortunately, the&amp;nbsp;new certificate did not resolved the issue.&amp;nbsp; So we are looking more closely at the details of the certificates and network traces to try and figure out where the TLS handshake breaks down. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am certainly not a certificate/TLS/Networking expert by any means, so I may be misunderstanding the specifics of how this is supposed to work and any quirks of the Java networking stack when talking to Windows/IIS web servers.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Jun 2017 17:42:57 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/unable-to-log-into-arcgis-server-manager-after/m-p/567972#M7768</guid>
      <dc:creator>LucasScharenbroich</dc:creator>
      <dc:date>2017-06-12T17:42:57Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to log into ArcGIS Server Manager after Federating</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/unable-to-log-into-arcgis-server-manager-after/m-p/567973#M7769</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A workaround!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The actual issue appears to be a lack of support for SNI in the ArcGIS Server proxy. &amp;nbsp;Our web server was set up with multiple sites, each bound to a FQDN. &amp;nbsp;On a hunch, I added a default HTTPS binding to the site that contains the Portal Web Adaptor and things began working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At one point I did have a default binding on the site in order to configure the Web Adaptor (so I could use &lt;A href="https://localhost/"&gt;https://localhost/&lt;/A&gt;&amp;nbsp;to get at the configuration page), which is why it worked for a while and then "stopped". &amp;nbsp;At the time, I didn't associate removing the default binding with the loading failures.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is an Esri &lt;A href="http://support.esri.com/bugs/nimbus/QlVHLTAwMDA5MzgyNw=="&gt;BUG-000093827&lt;/A&gt; that discusses an issue with the Portal proxy and SNI support that was fixed in 10.4.1, but nothing I could find that discussed the state of SNI support in the ArcGIS Server proxy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm hoping to get a resolution from Esri support that either&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Confirms this as a bug in the AGS proxy, or&lt;/LI&gt;&lt;LI&gt;Provides some details on how to enable SNI support&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For now, moving on from this issue....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;TLS Extension List sent from ArcGIS Server&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;extensions [extension_type: elliptic_curves,extension_type: ec_point_formats,extension_type: signature_algorithms]&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;TLS Extension List sent from Chrome Browser&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;extensions [extension_type: 31354,extension_type: renegotiation_info,&lt;STRONG&gt;extension_type: server_name&lt;/STRONG&gt;,extension_type: extended_master_secret,extension_type: SessionTicket_TLS,extension_type: signature_algorithms,extension_type: status_request,extension_type: 18,extension_type: application_layer_protocol_negotiation,extension_type: 30032,extension_type: ec_point_formats,extension_type: elliptic_curves,extension_type: 10794]&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Jun 2017 17:02:45 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/unable-to-log-into-arcgis-server-manager-after/m-p/567973#M7769</guid>
      <dc:creator>LucasScharenbroich</dc:creator>
      <dc:date>2017-06-13T17:02:45Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to log into ArcGIS Server Manager after Federating</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/unable-to-log-into-arcgis-server-manager-after/m-p/567974#M7770</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK, yes. That makes sense.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There's a second issue that's fixed in 10.5 - [#&lt;SPAN style="margin: 0px; color: #000000; font-size: 11pt; font-family: 'Calibri',sans-serif;"&gt;BUG-000099854&lt;/SPAN&gt;&lt;SPAN&gt; A proxy call within Portal for ArcGIS does not support Server Name Indication (SNI): GET /arcgis/sharing/proxy?&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://community.esri.com/external-link.jspa?url=https%3A%2F%2Fserver.domain.com%2Farcgis%2Frest%2Fservices%2FHosted%2FMyService%2FFeatureServer%2F0%3Ff%3Djson" rel="nofollow" target="_blank"&gt;https://server.domain.com/arcgis/rest/services/Hosted/MyService/FeatureServer/0?f=json&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;}&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Jun 2017 17:07:39 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/unable-to-log-into-arcgis-server-manager-after/m-p/567974#M7770</guid>
      <dc:creator>RandallWilliams</dc:creator>
      <dc:date>2017-06-13T17:07:39Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to log into ArcGIS Server Manager after Federating</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/unable-to-log-into-arcgis-server-manager-after/m-p/567975#M7771</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for this workaround! I had the same issue but never thought that the default https binding could be the cause. I tried many things and contacted support without success, we have a similar setup with multiple sites each bound to a FQDN. Editing the default https binding with an EV SSL certificate solved this issue.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Oct 2017 09:29:00 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/unable-to-log-into-arcgis-server-manager-after/m-p/567975#M7771</guid>
      <dc:creator>MatthiasFries</dc:creator>
      <dc:date>2017-10-18T09:29:00Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to log into ArcGIS Server Manager after Federating</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/unable-to-log-into-arcgis-server-manager-after/m-p/567976#M7772</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Lucas&lt;/P&gt;&lt;P&gt;Thank you for your post.&amp;nbsp; Its the only thing I have found that comes close to solving my problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am getting the exact same problem of not being able to access server manager after federation.&amp;nbsp; I even get a log message which includes "&lt;SPAN style="color: #000000; background-color: #ffffff;"&gt;If the service URL is a proxy URL verify it is accessible to clients".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff;"&gt;I am having a frustrating time trying to solve this.&amp;nbsp; Have you had a response from ESRI regarding your 2 points?&amp;nbsp; We have two portals joined together in primary/secondary failover mode.&amp;nbsp; Web adapters are on both servers but arcgis is the only site on these servers (so I assume that would make it default anyway).&amp;nbsp; However we do have a f5 load balancer which directs traffic to the primary server if it is up or the secondary server if it is down.&amp;nbsp; I am trying to work out if you fix applies to the load balancer or the servers with the web adapters?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff;"&gt;Thanks again, Rob&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Nov 2017 10:45:17 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/unable-to-log-into-arcgis-server-manager-after/m-p/567976#M7772</guid>
      <dc:creator>RobertDriessen2</dc:creator>
      <dc:date>2017-11-23T10:45:17Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to log into ArcGIS Server Manager after Federating</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/unable-to-log-into-arcgis-server-manager-after/m-p/567977#M7773</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't have an answer for the SNI problem, but&amp;nbsp;just wanted to chime in and mention it's unnecessary to only send traffic to the primary server.&amp;nbsp; The Web Adaptors are aware of the health of the portal machines and will balance requests to each machine.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Nov 2017 18:41:49 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/unable-to-log-into-arcgis-server-manager-after/m-p/567977#M7773</guid>
      <dc:creator>JonathanQuinn</dc:creator>
      <dc:date>2017-11-28T18:41:49Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to log into ArcGIS Server Manager after Federating</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/unable-to-log-into-arcgis-server-manager-after/m-p/567978#M7774</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Rob,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Esri support did confirm the lack of SNI support in the ArcGIS Server proxy and filed&amp;nbsp;&lt;SPAN style="font-size: 11.0pt;"&gt;BUG-000106097.&amp;nbsp; It is listed as fixed in 10.6.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;&lt;A class="link-titled" href="http://support.esri.com/en/bugs/nimbus/QlVHLTAwMDEwNjA5Nw==" title="http://support.esri.com/en/bugs/nimbus/QlVHLTAwMDEwNjA5Nw=="&gt;BUG-000106097: A proxy call within ArcGIS GIS Server does not suppo..&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Dec 2017 15:38:32 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/unable-to-log-into-arcgis-server-manager-after/m-p/567978#M7774</guid>
      <dc:creator>LucasScharenbroich</dc:creator>
      <dc:date>2017-12-11T15:38:32Z</dc:date>
    </item>
  </channel>
</rss>

