Unable to install RSA Certificate Manager on a migrated nCipher Security World
Originally Published: 2008-05-19
Article Number
Applies To
Win 2003 Server
nCipher HSM, where the security works is pre-exisiting Security World, with existing pkcs11 keys.
Issue
C:\nfast\bin>nfkmcheck nfkmcheck: information: World is in strict FIPS 140-2 mode (see manual) nfkmcheck: information: Module #1 Slot #0 Operator Cardset `OCS1' #1 nfkmcheck: information: Key mscapi container-xxxxxxx arbitrary data object (not a key) nfkmcheck: information: Key mscapi container-xxxxxxxarbitrary data object (not a key) nfkmcheck: information: Key mscapi container-xxxxxxx arbitrary data object (not a key) nfkmcheck: information: Key mscapi container-xxxxxxx arbitrary data object (not a key) 11:41:36 ERROR: Key file bearing AppName pkcs11, Ident uxxxxxx contains different key pkcs11 uxxxxxxx nfkmcheck: fatal error: NFKM_findkey failed: HostDataInvalid nfkmcheck: fatal error occurred - not all checks carried out !
Unable to install RCM on a migrated nCipher Security World
When installing RCM 6.7 the following message appears when trying to configure the Install Directory Server;
Configuration of Install Directory Server (e:\RSA_CM\ids\bin\xudad.exe -setup -d2 -f ids.log ids.conf) failed tieht return code [17]. Please refer to the log file [e:\RSA_CM\ids\bin\ids.log] for more information, and contact technical support if the cause of the problem remains unclear.
The ids.log contains the following:
Reading configuration parameters. Reading configuration from file [ids.conf]
Checking network.
Confirming existence of target directories:
e:\RSA_CM\ids\conf
e:\RSA_CM\ids\ssl\private
e:\RSA_CM\ids\ssl\certs
e:\RSA_CM\ids\db
Bootstrapping XUDA from schema file:
e:\RSA_CM\ids\dist\schema.conf
*** Unable to load crypto provider : pkcs11v2,c:\nfast\toolkits\pkcs11\cknfast.dll *** [XrcUNABLE: unspecified failure] *** Operation failed. *** [XrcUNABLE: unspecified failure] configuration parameter is undefined [installMode]
Cause
Resolution
This can also happen if the hardserver process on solaris is not running.
Related Articles
How to reseed identity columns in SQL Server? 18Number of Views Authentication Manager database services do not to start after power outage 179Number of Views A single user has large spacing in the Users display in RSA Identity Governance & Lifecycle 26Number of Views Key Manager Server migration appears to hang after logging 'Migrating AUTH_INTERNAL...' in migrate.log 22Number of Views After a power outage ACE/Server is not authenticating nor will it start properly 22Number of Views
Trending Articles
Passwordless Authentication in Windows MFA Agent for Active Directory – Quick Setup Guide RSA Authentication Manager Upgrade Process RSA Authentication Manager 8.9 Release Notes (January 2026) An example of SSO using SAML and ADFS with RSA Identity Management and Governance 6.9.x RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide
Don't see what you're looking for?