RSA Identity Governance & Lifecycle 6.8.x and above remote Access Fulfilment Express (AFX) server fails to start with the error "SSL peer shut down incorrectly" in the logs
Originally Published: 2016-08-10
Article Number
Applies To
RSA Product/Service Type: Access Fulfilment Express
RSA Version/Condition: 6.8.x and above
Platform: WebSphere
Issue
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ + New app '10_AFX-INIT' + ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ ERROR 2014-12-26 01:58:52,810 [WrapperListener_start_runner] org.mule.module.launcher.DeploymentService: ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ + Failed to deploy app '10_AFX-INIT', see below + ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ org.mule.module.launcher.DeploymentInitException: EOFException: SSL peer shut down incorrectly at org.mule.module.launcher.application.DefaultMuleApplication.init(DefaultMuleApplication.java:221) at org.mule.module.launcher.application.ApplicationWrapper.init(ApplicationWrapper.java:64) at org.mule.module.launcher.DefaultMuleDeployer.deploy(DefaultMuleDeployer.java:46) at org.mule.module.launcher.DeploymentService.guardedDeploy(DeploymentService.java:398) at org.mule.module.launcher.DeploymentService.start(DeploymentService.java:181) at org.mule.module.launcher.MuleContainer.start(MuleContainer.java:157) at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method) at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:57) at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43) at java.lang.reflect.Method.invoke(Method.java:622) at org.mule.module.reboot.MuleContainerWrapper.start(MuleContainerWrapper.java:56) at org.tanukisoftware.wrapper.WrapperManager$12.run(WrapperManager.java:3925) Caused by: org.mule.api.config.ConfigurationException: Error creating bean with name 'serverInitialization' defined in URL [file:/home/oracle/AFX/mule/apps/10_AFX-INIT/mule-config.xml]: Instantiation of bean failed; nested exception is org.springframework.beans.BeanInstantiationException: Could not instantiate bean class [com.aveksa.afx.server.init.ServerInitializationComponent]: Constructor threw exception; nested exception is org.mule.api.lifecycle.InitialisationException: Server initialization failed! Please correct the issue and restart AFX. (org.mule.api.lifecycle.InitialisationException) (org.mule.api.config.ConfigurationException) ... 15 more
Cause
- The SSL configuration on WebSphere is not configured correctly. For example, the wrong path configured to the server.keystore or the wrong keystore password.
- The server.keystore on the application server file system is corrupt or outdated. For example, a new server.keystore has been generated from the UI, but not updated on the WebSphere application server file system.
Resolution
Follow the WebSphere SSL configuration steps found in the WebSphere installation guide relative to your version.
For 6.8.1
Follow the relevant steps under "Working with Keystores and Certificates" in Chapter 7 of the Identity Management & Governance 6.8.1 Installation Guide
- Getting the RSA IAM Platform Server Keystore File (page 32).
- Associating the RSA IAM Platform server.keystore File with Your WebSphere Server (page 33).
- Configuring the WebSphere Server SSL (page 33).
- Configuring SSL Port Assignment (page 34).
For 6.9.x
Follow the relevant steps under "Securing Internal Communication Between RSA IMG Components" in Chapter 3 of the Identity Management & Governance 6.9.1 Installation on WebSphere Guide:
- Download the RSA IMG Server Keystore File (page 33).
- Create a keystore in the WebSphere Server using the RSA IMG server.keystore File (page 33).
- Create an SSL Configuration in WebSphere using the RSA IMG Keystore (page 34).
- Configuring the SSL Port (page 34).
For 7.0.0
Follow the relevant steps under "Securing Internal Communication Between RSA IMG Components" in Appendix A of the RSA Via L&G 7.0 Installation Guide:
- Download the RSA Via L&G Server Keystore File (page 88).
- Create a keystore in the WebSphere Server using the RSA Via L&G server.keystore File (page 89).
- Create an SSL Configuration in WebSphere using the RSA Via L&G Keystore (page 89).
- Complete these additional steps if Access Fulfillment Express (AFX) is deployed along with RSA Via L&G (page 90).
- Configuring the SSL Port (page 90).
Related Articles
WebLogic process hosting RSA FIM becomes unresponsive and must be killed to restart. 13Number of Views "java.lang.RuntimeException: java.lang.OutOfMemoryError: Java heap space" errors occur frequently in versions 6.x of RSA I… 73Number of Views Deadlock Detected While Extending Schema for Role in RSA Identity Governance & Lifecycle 24Number of Views RSA Governance & Lifecycle Integration: Generic SSH and SSH-Keypair Summary 14Number of Views AFX Server is in a 'Not running' State in the user interface but 'afx status' indicates AFX is running in RSA Identity Gov… 375Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Authentication Manager Security Console and Operations Console Inaccessible After Certificate Update RSA Authentication Manager 8.9 Patches and Hotfixes Readme RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide "No decryption codes were found in the zip file" error when decrypting RSA SecurID tokens
Don't see what you're looking for?