Sametime authServerURL in embedded Sametime Client: Why do some servers work and others don't?

When trying to migrate to a new Sametime 12.0.1 server we found out that not all Mail-/Home Servers of the users are able to deliver an SSO Token to login to Sametime successfully.

This has nothing to do with the new Sametime server and happens with the old one as well.

Currently we have a Domino Based Sametime 11.0.1 Server. With this server you do not need a authServerURL as the sametime server itself can deliver the token. The configuration looks like this:

Authentication server is empty: Everything works.

Now we have two locations, Germany and Suisse, both with a Domino Cluster:

Germany cluster:

DominoDE_1/Company, dominode_1.de.company.com
DominoDE_2/Company, dominode_2.de.company.com

Suisse cluster:

DominoCH_1/Company, dominoch_1.ch.company.com
DominoCH_2/Company, dominoch_2.ch.company.com

The clusterpartners are configured identically: Both using "Internet Sites", both configured to use the same LtpaToken with the same DNS domain.

But only half of the servers work when put into "Authentication server":

Authentication ServerLogin to Sametime embedded client works
DominoDE_1/CompanyYes
dominode_1.de.company.comYes
DominoDE_2/CompanyNo
dominode_2.de.company.comNo
DominoCH_1/CompanyNo
dominoch_1.ch.company.comNo
DominoCH_2/CompanyYes
dominoch_2.ch.company.comYes

This seems like random and I can't find any difference between the servers and a reason why two work and the others don't...

So: What can I check to find out, why some Domino Servers do not work as authentication server while others (in the same cluster / same network) do...

Have you checked if the servers that do not work are listed in the Websso Document

that you imported the ltpa.keys