RCM CRL not being generated automatically per crl timer configuration
Originally Published: 2011-02-01
Article Number
Applies To
RSA Certificate Manager 6.8 HA
Microsoft Windows Server 2003 SP2
ADAM High Availability
Certificate Revocation List (CRL)
Issue
From the trace.log, observed the following error in various places:
2011/01/03 13:32:20 ldap 1556 2884 D:\RCM\CERTMGR-3837\strong-sentry\ldap\ldap-3.3-hodges\servers\slapd\crltimer.c:4016 Automatic complete CRL generation Failed.
If RCM is configured with an external LDAP (i.e., only one instance of RCM), crl timers are disabled by default. To use crl timers, please follow the steps in "Using Revocation List Timers with HighAvailability" section on page 212 of RSACertificateManagerAdministratorsGuide.
In "High Availability Configuration - Revocation List Generators" configuration, we can configure values for primary instance and Health check period even if secondary is not configured for HA.
Cause
Resolution
In this situation, using short hostname (i.e., rcm1), instead of the FQDN, as the primary HostName resolved the issue.
Notes
Related Articles
How to Restrict of Active Tokens per User on RSA Authentication Manager. 5Number of Views Request from Account Access and Ownership Review stuck in Fulfillment Phase when "Create a job per group, grouping by " us… 89Number of Views RSA Authentication Agent 2.0 for Citrix StoreFront Release Notes (Spanish) 6Number of Views RSA Via Lifecycle and Governance Fulfillment Workflows "Create a job per group, grouping by user" creates a single job for… 15Number of Views Service Provider hangs at throughput of 5 assertions per second 16Number of Views
Trending Articles
Unable to attach a replica instance due to a configuration error when enabling replication for the RADIUS server for RSA A… RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA Authentication Manager 8.7 SP2 Setup and Configuration Guide Troubleshooting RSA MFA Agent for Microsoft Windows How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device
Don't see what you're looking for?