RSA Authentication Manager 8.2 reports 'Unexpected error during command com.rsa.admin.GetPrincipalNestedGroupsCommand execution'
Originally Published: 2016-08-29
Article Number
Applies To
RSA Product/Service Type: RSA Authentication Manager
RSA Version/Condition: 8.2
Issue
There was a problem processing your request. Unexpected error during command com.rsa.admin.GetPrincipalNestedGroupsCommand execution
- First, ensure that verbose logging is turned on in the Security Console. To do this,
- Click Setup > System Settings > Logging.
- Select the primary server and click Next.
- Set Trace Log value to Verbose in the Log Levels section.
- Scroll down and check the option to apply the above settings to the replica instance(s) upon save.
- Click Save.
- If verbose logging was not enabled, redo the process above to generate error. Skip to step 3 if it was enabled.
- Review the /opt/rsa/am/server/logs/imsTrace.log for an error such as:
2016-08-26 08:50:58,071, [[ACTIVE] ExecuteThread: '0' for queue: 'weblogic.kernel.Default (self-tuning)'], (CommandServerEngine.java:897), trace.com.rsa.command.CommandServerEngine, DEBUG, {AM-hostname},,,,Command : class com.rsa.admin.GetPrincipalNestedGroupsCommand Execution Exception: com.rsa.common.UnexpectedDataStoreException: exception during group search: (&(objectClass=group)(member={group DN})): Unable to find the requested data from the directory server com.rsa.common.UnexpectedDataStoreException: exception during group search: (&(objectClass=group)(member={group DN})): Unable to find the requested data from the directory server
at com.rsa.ims.admin.dal.ldap.GroupAccessLDAP.getMemberOfGroups(GroupAccessLDAP.java:1426)
atcom.rsa.ims.admin.impl.GroupAdministrationImpl.getMemberOfGroupsForGroup(GroupAdministrationImpl.java:3255) at com.rsa.ims.admin.impl.GroupAdministrationImpl.getAllSuperGroups(GroupAdministrationImpl.java:3179)
at com.rsa.ims.admin.impl.GroupAdministrationImpl.getAllGroupsPrincipalBelongsTo(GroupAdministrationImpl.java:3222) at com.rsa.admin.GetPrincipalNestedGroupsCommand.performExecute(GetPrincipalNestedGroupsCommand.java:138) at com.rsa.command.LocalTarget.executeCommand(LocalTarget.java:119)
at com.rsa.ims.command.LocalTransactionalCommandTarget.access$0(LocalTransactionalCommandTarget.java:1)
at com.rsa.ims.command.LocalTransactionalCommandTarget$2.doInTransaction(LocalTransactionalCommandTarget.java:268)
atcom.rsa.ims.command.LocalTransactionalCommandTarget$2.doInTransaction(LocalTransactionalCommandTarget.java:1) at org.springframework.transaction.support.TransactionTemplate.execute(TransactionTemplate.java:131)
at com.rsa.ims.command.LocalTransactionalCommandTarget.executeCommand(LocalTransactionalCommandTarget.java:260) at com.rsa.command.CommandServerEngine$CommandExecutor.run(CommandServerEngine.java:933)
at com.rsa.command.CommandServerEngine$CommandExecutor.run(CommandServerEngine.java:1)
at com.rsa.ims.security.spi.SimpleSecurityContextImpl.doAs(SimpleSecurityContextImpl.java:113)
at com.rsa.security.SecurityContext.doAs(SecurityContext.java:439)
at com.rsa.command.CommandServerEngine.executeCommand(CommandServerEngine.java:445)
at com.rsa.command.CommandServerEngine.executeCommand(CommandServerEngine.java:373)
at com.rsa.command.CommandServerBean.executeCommand(CommandServerBean.java:89)
at com.rsa.command.CommandServerEjb30_vraifm_CommandServerEjb30Impl.__WL_invoke(Unknown Source)
at weblogic.ejb.container.internal.SessionRemoteMethodInvoker.invoke(SessionRemoteMethodInvoker.java:34)
at com.rsa.command.CommandServerEjb30_vraifm_CommandServerEjb30Impl.executeCommand(Unknown Source)
at com.rsa.command.CommandServerEjb30_vraifm_CommandServerEjb30Impl_WLSkel.invoke(Unknown Source)
at weblogic.rmi.internal.BasicServerRef.invoke(BasicServerRef.java:701)
at weblogic.rmi.cluster.ClusterableServerRef.invoke(ClusterableServerRef.java:231)
at weblogic.rmi.internal.BasicServerRef$1.run(BasicServerRef.java:527)
at weblogic.security.acl.internal.AuthenticatedSubject.doAs(AuthenticatedSubject.java:363)
at weblogic.security.service.SecurityManager.runAs(SecurityManager.java:146)
at weblogic.rmi.internal.BasicServerRef.handleRequest(BasicServerRef.java:523)
at weblogic.rmi.internal.wls.WLSExecuteRequest.run(WLSExecuteRequest.java:118)
at weblogic.work.ExecuteThread.execute(ExecuteThread.java:311)
at weblogic.work.ExecuteThread.run(ExecuteThread.java:263)Cause
Resolution
- Log into the Operations Console.
- Select Deployment Configuration > Identity Sources > Manage Existing.
- Left click the appropriate identity source and select Edit.
- Ensure you are in the Connections tab and update the Directory URL(s) to include the required port number.
- The example below illustrates using the default non-secure Global Catalog port of 3268:
Notes
Related Articles
Unexpected error during command com.rsa.ucm.request.AddSelfServiceRequestCommand execution when requesting token via-Authe… 210Number of Views Unexpected error during command com.rsa.ucm.request.CompleteWorkflowRequestActionsCommand execution when approving token r… 182Number of Views Unexpected error during command com.rsa.authmgr.admin.radius.AddRadiusClientCommand execution when adding new RADIUS clien… 267Number of Views Unexpected error during command com.rsa.authmgr.admin.tokenmgt.UnlinkTokensFromPrincipalsCommand execution when unassignin… 100Number of Views Modification of the LDAP identity source failed with an Error "Unexpected error during command com.rsa.admin.UpdateIdentit… 141Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device How to implement SAML SSO Authentication with Microsoft Azure Active Directory and RSA Identity Governance & Lifecycle How to download full kits, service packs, and patches from RSA Link for RSA Identity Governance & Lifecycle Authentication Manager Security Console and Operations Console Inaccessible After Certificate Update RSA announces the availability of the RSA SecurID Hardware Appliance 350 based on the Dell PowerEdge R640 Server
Don't see what you're looking for?