RSA Identity Governance & Lifecycle Role Collector (RDC) fails with ORA-30926 error
Originally Published: 2018-09-18
Article Number
Applies To
RSA Version/Condition: 7.1.0, 7.0.2, 7.0.1
Issue
In addition, in the Admin Errors for Run, the detailed errors for the run may show the following:
EC[212] Context[RunlD-502 RDC(Name=MyRoleCollector, ID=1)] Message[Role Data validation:
Membership Data is Invalid. Specified user(s) not found in associated IDC]
The following log event is logged in the aveksaServer.log file:.
08/24/2018 12:04:42.472 INFO (Exec Task Consumer#9) [com.aveksa.server.db.persistence.PersistenceServiceProvider]
executeCallableStatement giving up after hitting SQLException:
ORA-30926: unable to get a stable set of rows in the source tables
ORA-06512: at "AVUSER.RDC_UPDATE_MASTER_TABLES", line 490
ORA-06512: at "AVUSER.RDC_DATA_COLLECTOR", line 182
ORA-06512: at "AVUSER.RDC_DATA_COLLECTOR", line 297
ORA-06512: at line 1
...
08/24/2018 12:04:42.472 WARN (Exec Task Consumer#9) [org.hibernate.engine.jdbc.spi.SqlExceptionHelper]
SQL Error: 30926, SQLState: 99999
08/24/2018 12:04:42.472 ERROR (Exec Task Consumer#9) [org.hibernate.engine.jdbc.spi.SqlExceptionHelper]
ORA-30926: unable to get a stable set of rows in the source tables
ORA-06512: at "AVUSER.RDC_UPDATE_MASTER_TABLES", line 490
ORA-06512: at "AVUSER.RDC_DATA_COLLECTOR", line 182
ORA-06512: at "AVUSER.RDC_DATA_COLLECTOR", line 297
ORA-06512: at line 1
Cause
This is a known issue in the following versions:
- RSA Identity Governance and Lifecycle 7.0.1
- RSA Identity Governance and Lifecycle 7.0.2
- RSA Identity Governance and Lifecycle 7.1.0
Resolution
- RSA Identity Governance and Lifecycle 7.0.1
If you are using 7.0.1, please upgrade to a current version.
- RSA Identity Governance and Lifecycle 7.0.2 P10
- RSA Identity Governance and Lifecycle 7.1.0 P04
Workaround
You can force the collector to do a Full Refresh for Relationships by making a configuration change (it has to be a major change such as mapping attributes or resolution rules), and then changing the configuration back to the original. You can check to make sure this is set by displaying the list of Roll Collectors with all columns displayed and checking the Requires Full Refresh column.
Related Articles
Unable to save Application Role mapping in Role Collector in RSA Identity Governance & Lifecycle 10Number of Views Partial reject for approvals still provision indirect entitlements for accounts in RSA Governance & Lifecycle 40Number of Views Role collector design changes for RSA Identity Governance & Lifecycle 7.x 40Number of Views Requests Pending Submissions queue accumulating in RSA Identity Governance & Lifecycle 185Number of Views Existing Role memberships later granted through Parent Roles are not revoked when the Role memberships are removed from th… 37Number of Views
Trending Articles
Don't see what you're looking for?