Do TCP Agent using API ver. 8.5 & 8.6 need a new sdconf.rec file after a new Primary is promoted?
Originally Published: 2021-03-29
Article Number
Applies To
RSA Product/Service Type: Authentication Agent API for Java
RSA Version/Condition: 8.5.0, 8.6.0
Platform: Linux
Platform (Other): Windows
O/S Version: Red Hat Enterprise Linux 6.x
Issue
Definition: TCP agents using API ver. 8.5 & 8.6 to TCP port 5500 (not ReST agents using TCP port 5555, not UDP legacy agents using UDP port 5500) e.g. partner FoxT Boks Server agent.
Tasks
- Add a new replica to your Authentication Manager realm
- Promote new replica to become the new primary
- Remove original primary, either because you promoted for Disaster Recovery, DR, or you promoted for maintenance but eventually decommissioned the original primary that became a replica
Resolution
When you eventually promote this new replica, and as the last step remove the original primary, our Assumptions are as follows:
- Provide newly downloaded copies of the sdconf.rec file to all;
- a. new Boks TCP agents, and
- b. existing TCP agents that did not know of this new primary because they had not authenticated after this new primary had been added as a replica, and therefore did not learn of it through the configuration service
- Technically you would not need a new sdconf.rec file for existing TCP agents that knew of this new primary because they had authenticated after this new primary had been added as a replica. However, a Best Practice would be to maintain consistency with all downloaded sdconf.rec file
Notes
Agent uses the Configuration Service to determine whether or not there is updated configuration information.
Related Articles
Do Web Services need to be enabled if they are not being used in RSA Identity Governance & Lifecycle? 34Number of Views How to run the RSA AMBA utility without the need of input files? 38Number of Views Does RSA Identity Governance and Lifecycle MAX_STRING_SIZE need to be modified from STANDARD to EXTENDED to accommodate st… 19Number of Views When is a wildcard certificate needed in RSA SecurID Access? 112Number of Views Need to wait until updating radius_connector.ini file after AM8.6 upgrades replica side 130Number of Views
Trending Articles
RSA Authentication Manager 8.9 Release Notes (January 2026) Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory How to 'Trust' the RSA Authentication Manager Security Console Self-Signed Root CA certificate and prevent Cert warnings. RSA Authentication Manager Upgrade Process How to delete old or pending certificate signing requests for RSA Authentication Manager console or virtual host replaceme…
Don't see what you're looking for?