OpsanBlog

Michael Coates - Microsoft Pragmatic Evangelist

Posted with:
 Windows Live Writer
 Download Live Writer

My Windows Live Local Collections:
 Las Vegas
 Los Angeles
 San Jose
 Seattle
 Washington, DC
 My Walks

Article Categories

Archives

Post Categories

Bloggers

Promote a group member to master secret server

If your MSS should fail, here are the steps to promote a member server to the MSS:

  • Change the master secret server name from the original to the new using ssomanage: “ssomanage -updatedb”.
  • Stop the ENTSSO service on the new master secret server.
  • Start the ENTSSO service on the new master secret server. It will recognize that it is the master secret server and that it has no secrets.
  • On the new master secret server, restore the backed up master secret file using ssoconfig: “ssoconfig -restoresecret BackupFile” 

The new server is now the master of the group. 

posted on Sunday, September 26, 2004 5:00 PM

Feedback

# re: Promote a group member to master secret server 3/6/2006 12:47 AM Péterfalvi Attila

We have done this steps, but it did not work.
We have done the following steps and it works:
1. SSOmanage -updatedb <xml file>
2. SSOmanage -serverall <new master secret server>
3. In the BTS Admin conzol (BTS 2004 properties - SSO server name: the new master secret server)
4. SSOmanage -displaydb (to verify the information in the SSO db)
5. Restrat ENTSSO service on the new master secret server
6. SSOconfig -restoresecret <master secret key backup>
7. Verify the change:
+ In BTS admin conzol refresh Receive Locations (it must work)
+ In VS BTS Explorer change by one of the receive location or port same properties
+ Verify the messages in the server event viewer

# re: Promote a group member to master secret server 7/14/2008 11:30 PM techmio

i encouter the information may be diffirenct but most the same. in cluster, the cluster network name should be the gate for network acess. when i try tp change the MSS(master secrete server) from node1 to NetworkName(cluster) using ssomanage -updatedb xml
ssomanage -serverall networkname(cluster)
and then restart SSO
a waring in evenlog appear that SSO can't receive the secret value.
but infact the networkname map tonode1 when node1 is active
why?

Failed to retrieve master secrets. Verify that the master secret server name is correct and that it is available.
Secret Server Name: btscluster.atomsg.com
Error Code: 0x800706D9, There are no more endpoints available from the endpoint mapper.
Got the previous secret from the master secret server.
Secret Server Name: btsnd2.atomsg.com
MSID: a080e0bf-a8ed-414e-93ce-a670e1bea9c6
btsnd2.atomsg.com = btscluster.atomsg.com

Title  
Name  
Url
Comments   

The opinions expressed herein are my own and are not intended to represent those of my employer.