PAM Server Refusing Connection Two-Node Cluster - Recovery and Best Practices
search cancel

PAM Server Refusing Connection Two-Node Cluster - Recovery and Best Practices

book

Article ID: 407500

calendar_today

Updated On:

Products

CA Privileged Access Manager (PAM)

Issue/Introduction

This article details the troubleshooting and resolution steps for a two-node development in cluster where the secondary node was refusing connection. The cluster experienced a "[PAM] PAM-UI-1428: Bootstrap node for the primary site is unavailable." error (Quorum-Loss Mode) after a reboot, preventing normal operation.

Environment

CA Privileged Access Manager (PAM) 4.x

Cause

The "PAM-UI-1428" error and Quorum-Loss Mode typically occur in a two-node cluster when one node becomes unavailable. In this case, a reboot of Node 1 left Node 2 in an inactive state, leading to the quorum loss.

Resolution

The two-node cluster was successfully recovered through the following steps:

- Initial State Assessment:
   - Node 1 was rebooted cluster was on.
   - Node 2 remained inactive and displayed a "PAM-UI-1428" error (Quorum-Loss Mode), preventing full login or normal cluster operation.

- Node Isolation and Configuration Reset:

   - Both Node 1 and Node 2 were temporarily removed from the cluster.
   - Their cluster configurations were reset to allow individual logins as a "super" user, confirming the ability to access all menus and resolve the "PAM-UI-1428" error on each node individually.

- Cluster Reconfiguration:

   - After verifying the stability and independent operation of both nodes, the cluster was reconfigured.
   - A new configuration key was generated from Node 1.
   - The settings were synchronized across both nodes.

- Verification:

   - Monitored synchronization between the nodes, ensuring both were operational and responding correctly.
   - PAM client connection tests were performed to confirm the stability of the reconfigured cluster.

- Outcome:

The cluster is now fully operational and stable.