RSA Authentication Manager stuck at startup after configuring Embedded IDR
Article Number
Applies To
RSA Product/Service Type: RSA Authentication Manager
RSA Version/Condition: 8.7 SP2, 8.7 SP2 P1
Issue
Cause
Resolution
- Reboot the system.
- Have console and keyboard access on boot.
- On boot, observe the system startup and look for a short GRUB message.
- Right after the GRUB message you now see a blank screen with two lines.
- Press the E key. You will be presented with an editor and the content of the selected boot entry.
- A text box will open, allowing you to edit the startup lines.
- Navigate down to the line that starts with linux and at the end of that line that already contains text, add systemd.mask=validate-interfaces.service to the end of the line, as shown:
- Boot the system by pressing F10.
- Once the server is booted. Apply the "Preventive Action" as mentioned in the Workaround section below - This is important to avoid re-occurrence of the problem.
Workaround
After RSA Authentication Manager is installed with full kit of 8.7 SP2 and / upgraded to 8.7 SP2 P1. When an Embedded IDR is installed. Following steps needs to be performed as a "Preventive Action" , before rebooting the server.
Note: This "Preventive Action" needs to be applied before rebooting the server.
-
Launch the SSH client and connect to the RSA appliance using the IP address or fully qualified hostname.
-
When prompted, type the operating system User ID, rsaadmin, and press ENTER.
-
When prompted, type the password for the rsaadmin operating system account, and press ENTER.
- Change to the root user by running the command sudo su - root and providing the rsaadmin password..
login as: rsaadmin Using keyboard-interactive authentication. Password: <enter OS user password> Last login: Thu May 23 21:46:18 2024 from 192.168.26.100 RSA Authentication Manager Installation Directory: /opt/rsa/am rsaadmin@am87-2:~> sudo su - [sudo] password for rsaadmin: <enter OS user password> am87-2:~ #5. Run the below command.
sed -i 's/After=network.target lvm2-monitor.service firewalld.service/Wants=iptables.service timesync.service wicked.service\nBefore=rsaservmgr.service snmpd.service systemd-logind.service\nAfter=network.target lvm2-monitor.service firewalld.service memorycontrol.service/g' /usr/lib/systemd/system/docker.service
- Run the below command.
systemctl daemon-reload
- Reboot the Appliance from the operation console.
Notes
Related Articles
Name or service not known error when connecting Identity Router (IDR) to RSA Authentication Manager 251Number of Views How to upgrade an RSA SecurID Access IDR 329Number of Views Clarification on RSA Identity Router (IDR) Upgrade Notification (12.22.0.0.37) 135Number of Views Failed to deploy RSA IDR - VMware "Error updating httpd.conf" 105Number of Views What to expect during an RSA SecurID Access Identity Router (IDR)/Cluster software update 591Number of Views
Trending Articles
RSA SecurID Software Token 5.0.2 for Windows Desktop displays message after reboot due to roaming profile: No token stor… RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA Release Notes for RSA Authentication Manager 8.8 RSA Authentication Manager 8.9 Release Notes (January 2026) Troubleshooting RSA SecurID Access Application Portal unsuccessful logon message due to a bad identity source bind
Don't see what you're looking for?