AMIS AM Prime Unable to create/add user account from HDAP portal
Originally Published: 2020-12-18
Article Number
Applies To
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.1.1, 8.x
Platform (Other): AMIS 1.3
Issue
There is some unexpected issue with the server. Status: 504 Please check if the server is accessible.
AMIS logs
===hdap.log===
ERROR com.rsa.pso.lap.springbeans.AMISClientServiceImp - Exception :: AMISClientServiceImp.getIdentitySources() :: /java.lang.NullPointerException
ERROR com.rsa.pso.lap.web.SearchActionBean - Exception while creating user/com.rsa.pso.exception.ServiceException
ERROR com.rsa.pso.lap.web.SearchActionBean - Exception occurred sending status code 500/com.rsa.pso.exception.ServiceException
DEBUG com.rsa.pso.util.LAPUtils - Action /am71/user/createUser is protected by permission user:create
ERROR com.rsa.pso.lap.web.SearchActionBean - Exception occurred sending status code 401/java.lang.Exception
===claimfilter===
ERROR com.emc.rsa.pso.amis.service.claimFilter - unable to validate token 22697441
INFO com.emc.rsa.pso.amis.service.claimFilter - Returning unauthorized.
INFO com.emc.rsa.pso.amis.service.claimFilter - Loading claim set
INFO com.emc.rsa.pso.amis.service.claimFilter - Session token : RSA_AUTHENTICATION_TOKEN was not found in session.
Cause
Sample Response after AMIS May 2020 ChangeList ID 1304761:
<?xml version="1.0" encoding="UTF-8" standalone="no" ?>
<serviceResult result="true">
<driverStatistics maxAllocTime="1857" maxReleastTime="0" maxThreadCount="1" totalAllocTime="1857" totalReleaseTime="0" totalRequests="1" />
</serviceResult>
Resolution
Steps to follow:
- Copy am8.war to Prime SSP servers.
- Stop AMIS service - WinServices Apache AMIS
- cd to ~/primekit/tomcat/tomcat-amis/work/
- From within dir above "rm -rf Catalina" or "rename Catalina"
- cd to ~/primekit/tomcat/tomcat-amis/webapps/
- Rename am8.war to .old_repl_tok extension
- (rename or) "rm -rf auth/ am8/ workflow/ rsa-endpoints/" from webapps repeat for other directories too: auth, am8, and workflow
- Copy the new am8.war to ~/primekit/tomcat/tomcat-amis/webapps/.
- Start AMIS
Should not need to reset permissions script 3_reset_perms.bat in Windows.
Workaround
Notes
Related Articles
RSA Authentication Manager – Unable to Add or Manage Users with Error “The specified ID is already in use” 5.23KNumber of Views Unable to log on to the RSA Access Manager Entitlements Manger (AdminGUI) after upgrade 42Number of Views AM 8.1: Cannot add or manage a user with user ID <UserID>. User IDs must be unique within a deployment. This user ID is al… 320Number of Views Unable to re-use a deleted account name if the account was previously disabled in RSA Identity Governance & Lifecycle 439Number of Views Unable to Resolve User by Login ID and/or Alias or Authenticator Not Assigned to User When Attempting to Authenticate via … 2.15KNumber of Views
Trending Articles
RSA Authentication Manager 8.7 SP2 Setup and Configuration Guide RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide How to Upgrade Internal SHA-1 Certificates to SHA-256 in Authentication Manager Using rsautil RSA Authentication Manager 8.9 Setup and Configuration Guide How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device
Don't see what you're looking for?