Hi!
I am working with a customer running a Dynamics 365 On Premises deployment with 2 Full server roles on version 9.0.27.2. We have started a project that includes adding 2 new Backend servers to the deployment (Done without issues) and 1 Frontend server, plan is also to reconfigure the 3 Full servers to run only the Front end role including the deployment parts the supported way running the installation wizard.
I have tried to install the new Front end server and also tried to re-configure an existing Full server getting stuck in the last System Checks step with differrent errors both related to the "Check ServerClaimsEncryptionCertificateValidator"
Install wizard for existing Full server: Error| Check ServerClaimsEncryptionCertificateValidator : Failure: The specified user name and password can not logon.
Install wizard for new Front end server: Error| Check ServerClaimsEncryptionCertificateValidator : Failure: The encryption certificate 'xxxxxx' cannot be accessed by the Dynamics 365 service account.
Some googling around this did not give a lot but some related threads and the only solution i found so far is to deactivate IFD/Claims during installation/re-configuration. I did this for the UAT environment/deployment and it worked fine.
I would like to avoid this in the production environment because it is a complex solution with a lot of integrations going on dependent on IFD/Claims authentication.
Anyone with experience from a scenario like this and maybe come up with a better solution than deactivating IFD/Claims for the deployment?
BR
Roland