Functionality requiring the retrieval of encrypted passwords is failing after a database restore in RSA Identity Governance & Lifecycle
Originally Published: 2017-04-28
Article Number
Applies To
RSA Version/Condition: 7.0.x, 7.1.x, 7.2.x
Issue
- POP3 email is not working because the password is invalid.
- Data collectors fail when attempting to bind to the data source because the passwords for the bind are incorrect.
- Authentication sources no longer work.
- The AFX server does not start because the AFX server Default Truststore Password is encrypted with the wrong key.
- AFX connectors initially fail due to the AFX server failure but once the AFX server starts, the connectors fail when attempting to connect to the endpoints because the passwords to authenticate the connections are incorrect.
04/27/2017 16:06:56.448 ERROR (default task-109) [com.aveksa.server.utils.PasswordTypePropertyHandler] Error in decryption method=ManagePasswordTypeProperties java.lang.IllegalStateException: An issue with handling encryption was encountered
04/27/2017 16:03:10.192 ERROR (ApprovalInboxProcessorServiceProvider) [com.aveksa.server.email.mailboxmonitor.MailboxMonitorThread] Error Processing Email javax.mail.MessagingException: Could not connect to message store for pop3s://iamtest@199.99.9.9:995; nested exception is: javax.mail.AuthenticationFailedException: [AUTH] Authentication failed.
Please see RSA Knowledge Base Article 000030327 -- Artifacts to gather in RSA Identity Governance & Lifecycle to find the location of the log files for your specific deployment.
Cause
- A backup of an RSA Identity Governance & Lifecycle database version 7.0.0 or later is restored using avdbimport without also importing the encryption keys.
- Importing a backup of a database using avdbimport into a different instance of RSA Identity Governance and Lifecycle.
- Importing a backup copy of the database using avdbimport into the same instance of RSA Identity Governance and Lifecycle where an uninstall and a re-install have been performed.
- Importing metadata for data collectors and AFX connectors from a different instance of RSA Identity Governance and Lifecycle.
KEK keys are named arbitrarily using a hashing algorithm to avoid name collisions but are always a combination of three characters including uppercase and lowercase characters and numbers and the filename extension .key. An example KEK filename is F1M.key. KEK keys are searched exhaustively during decryption. As new keys are added, new unique KEK files will be created in the master key storage directory (default /home/oracle/security). When archiving or copying KEK files, be sure to maintain all files in the directory.
Resolution
For resolving the AFX server/connector issues, please see RSA Knowledge Base Article 000034797 -- AFX server remains in a Not Running state with 'An issue with handling encryption was encountered' error on startup in RSA Identity Governance & Lifecycle.
Workaround
Notes
- Ensure that a backup copy of all the Key Encryption Key (KEK) files from the master key storage directory (default /home/oracle/security) are maintained for restoration purposes.
- Ensure that a copy of these files are retained before any uninstall and re-installation of the product.
Related Articles
RSA SecurID WebExpress and ACE/Server QuickAdmin: Protecting JRun functionality from IIS Lockdown Tool 6Number of Views RSA ACE/Server Remote Administration functionality on Windows 2000 7Number of Views Unification is failing at step 8 on "AVUSER.ROLE_MANAGEMENT_PKG", line 2469 in RSA Governance & Lifecycle 446Number of Views Generic REST AFX Connector does not encrypt Additional Parameters when defined as Encrypted in RSA Identity Governance & L… 99Number of Views How to test EFN Functionality 121Number of Views
Trending Articles
Downloading RSA Authentication Manager license files or RSA Software token seed records RSA Release Notes for RSA Authentication Manager 8.8 RSA Authentication Manager 8.9 Release Notes (January 2026) Download RSA SecurID Access Cloud User Event audit logs using Cloud Administration REST API CLU RSA SecurID Software Token 5.0.2 for Windows Desktop displays message after reboot due to roaming profile: No token stor…
Don't see what you're looking for?