RCM CRL not being generated automatically per crl timer configuration
Originally Published: 2011-02-01
Article Number
Applies To
RSA Certificate Manager 6.8 HA
Microsoft Windows Server 2003 SP2
ADAM High Availability
Certificate Revocation List (CRL)
Issue
From the trace.log, observed the following error in various places:
2011/01/03 13:32:20 ldap 1556 2884 D:\RCM\CERTMGR-3837\strong-sentry\ldap\ldap-3.3-hodges\servers\slapd\crltimer.c:4016 Automatic complete CRL generation Failed.
If RCM is configured with an external LDAP (i.e., only one instance of RCM), crl timers are disabled by default. To use crl timers, please follow the steps in "Using Revocation List Timers with HighAvailability" section on page 212 of RSACertificateManagerAdministratorsGuide.
In "High Availability Configuration - Revocation List Generators" configuration, we can configure values for primary instance and Health check period even if secondary is not configured for HA.
Cause
Resolution
In this situation, using short hostname (i.e., rcm1), instead of the FQDN, as the primary HostName resolved the issue.
Notes
Related Articles
How to Restrict of Active Tokens per User on RSA Authentication Manager. 12Number of Views Citrix MetaFrame bypassing authentication on a per-session basis 7Number of Views Service Provider hangs at throughput of 5 assertions per second 25Number of Views CRL timer permanently stops when LDAP store under load 11Number of Views Does RCM handle all special characters in email address allowed per the RFC? 12Number of Views
Trending Articles
Authentication Manager Supported Hardware and Upgrade Paths Artifacts to gather in RSA Identity Governance & Lifecycle How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Authentication Manager 'Principal Does Not Possess Authenticator' Error for Users with Multiple IDs RSA Authentication Manager 8.8 Setup and Configuration Guide
Don't see what you're looking for?