Unable to install RSA Certificate Manager on a migrated nCipher Security World
Originally Published: 2008-05-19
Article Number
Applies To
Win 2003 Server
nCipher HSM, where the security works is pre-exisiting Security World, with existing pkcs11 keys.
Issue
C:\nfast\bin>nfkmcheck nfkmcheck: information: World is in strict FIPS 140-2 mode (see manual) nfkmcheck: information: Module #1 Slot #0 Operator Cardset `OCS1' #1 nfkmcheck: information: Key mscapi container-xxxxxxx arbitrary data object (not a key) nfkmcheck: information: Key mscapi container-xxxxxxxarbitrary data object (not a key) nfkmcheck: information: Key mscapi container-xxxxxxx arbitrary data object (not a key) nfkmcheck: information: Key mscapi container-xxxxxxx arbitrary data object (not a key) 11:41:36 ERROR: Key file bearing AppName pkcs11, Ident uxxxxxx contains different key pkcs11 uxxxxxxx nfkmcheck: fatal error: NFKM_findkey failed: HostDataInvalid nfkmcheck: fatal error occurred - not all checks carried out !
Unable to install RCM on a migrated nCipher Security World
When installing RCM 6.7 the following message appears when trying to configure the Install Directory Server;
Configuration of Install Directory Server (e:\RSA_CM\ids\bin\xudad.exe -setup -d2 -f ids.log ids.conf) failed tieht return code [17]. Please refer to the log file [e:\RSA_CM\ids\bin\ids.log] for more information, and contact technical support if the cause of the problem remains unclear.
The ids.log contains the following:
Reading configuration parameters. Reading configuration from file [ids.conf]
Checking network.
Confirming existence of target directories:
e:\RSA_CM\ids\conf
e:\RSA_CM\ids\ssl\private
e:\RSA_CM\ids\ssl\certs
e:\RSA_CM\ids\db
Bootstrapping XUDA from schema file:
e:\RSA_CM\ids\dist\schema.conf
*** Unable to load crypto provider : pkcs11v2,c:\nfast\toolkits\pkcs11\cknfast.dll *** [XrcUNABLE: unspecified failure] *** Operation failed. *** [XrcUNABLE: unspecified failure] configuration parameter is undefined [installMode]
Cause
Resolution
This can also happen if the hardserver process on solaris is not running.
Related Articles
How to reseed identity columns in SQL Server? 18Number of Views A single user has large spacing in the Users display in RSA Identity Governance & Lifecycle 29Number of Views Authentication Manager database services do not to start after power outage 181Number of Views Key Manager Server migration appears to hang after logging 'Migrating AUTH_INTERNAL...' in migrate.log 26Number of Views After upgrading to 8.0.0, migrated AFX Connectors show as "Not Deployed" in RSA Governance & Lifecycle 121Number of Views
Trending Articles
RSA Release Notes: Cloud Access Service and RSA Authenticators RSA Authentication Manager Patch Updates Deploying RSA Authenticator 6.2.2 for Windows Using DISM RSA Authenticator for iOS and Android Administrator Guide - Mobile Lock RSA SecurID software token .sdtid file fails to import into RSA SecurID Software Token 5.0 for Windows
Don't see what you're looking for?