RSA Authentication Manager services failed to start after activating a new console certificate
Originally Published: 2019-10-15
Article Number
Applies To
Authentication Manager 8.2, 8.2 SP1, 8.3, 8.4
Issue
- After importing and activating a new console certificate, some Authentication Manager failed to start the RSA RADIUS Server Operations Console and RSA Runtime Server services
- Errors in /opt/rsa/am/server/logs/radiusoc.log include:
2d1290f2ee76-00000001> <1561034153225> <[severity-value: 8] [rid: 0] [partition-id: 0] [partition-name: DOMAIN] > <BEA-090870> <The realm "rsa" failed to be loaded: weblogic.security.service.SecurityServiceException: com.bea.common.engine.ServiceInitializationException: weblogic.security.spi.ProviderInitializationException: A failure occurred attempting to load LDIF for provider RoleMapper from file /opt/rsa/am/server/security/XACMLRoleMapperInit.ldift.. weblogic.security.service.SecurityServiceException: com.bea.common.engine.ServiceInitializationException: weblogic.security.spi.ProviderInitializationException: A failure occurred attempting to load LDIF for provider RoleMapper from file /opt/rsa/am/server/security/XACMLRoleMapperInit.ldift. at weblogic.security.service.CommonSecurityServiceManagerDelegateImpl.postInitializeRealm(CommonSecurityServiceManagerDelegateImpl.java:536) at weblogic.security.service.CommonSecurityServiceManagerDelegateImpl.postLoadRealm(CommonSecurityServiceManagerDelegateImpl.java:861) at weblogic.security.service.CommonSecurityServiceManagerDelegateImpl.postInitializeRealms(CommonSecurityServiceManagerDelegateImpl.java:982) at weblogic.security.service.CommonSecurityServiceManagerDelegateImpl.postInitialize(CommonSecurityServiceManagerDelegateImpl.java:1250) at weblogic.security.service.SecurityServiceManager.postInitialize(SecurityServiceManager.java:586) at weblogic.security.SecurityService.start(SecurityService.java:130) at weblogic.server.AbstractServerService.postConstruct(AbstractServerService.java:76) at sun.reflect.GeneratedMethodAccessor7.invoke(Unknown Source)
Cause
The console certificate signature algorithm is sha256ECDSA, which is not supported by RSA. This crashes the server and causes the RSA RADIUS Server service and the Operations Console service to fail to start.
Resolution
To resolve the issue,
- Change the Signature Algorithm on the CA side to SHA256RSA.
- Generate new CSR from the RSA Operations Console.
- Sign the CSR from the CA.
- Import and activate the certificate on the Operations Console.
- After the reboot, SSH to the Authentication Manager server to confirm that the status of the Authentication Manager services and to verify that they are all running.
/opt/rsa/am/server/rsaserv status all
To make sure that services are up and running until signing the certificate, SSH to the Authentication Manager server and run the following commands to revert back to the default self-signed certificate
/opt/rsa/am/utils/rsautil reset-server-cert
When prompted, enter the Operations Console username and password. When done, restart the Authentication Manager services:
/opt/rsa/am/server/rsaserv restart all
Related Articles
Adding a new Fortinet RADIUS dictionary to RSA RADIUS for RSA Authentication Manager 1.3KNumber of Views RSA Authentication Manager 8.x services do not start after activating a new console certificate 1.03KNumber of Views Activate a New SSL Console Certificate 124Number of Views Migrating an RSA Authentication Manager 8.x deployment to a new location with different network settings 288Number of Views How to create a new ActiveMQ KahaDB for use with AFX in RSA Identity Governance & Lifecycle 357Number of Views
Trending Articles
RSA Authentication Manager Patch Updates RSA SecurID Software Token 4.1.2 and 4.2.1 for Mac OS X displays: No token storage device was detected. Verify that the de… How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device RSA SecurID software token .sdtid file fails to import into RSA SecurID Software Token 5.0 for Windows Configuring a Checkpoint firewall to work with SecurID
Don't see what you're looking for?