Article Content
Article Number | 000037409 |
Applies To | RSA Product Set: RSA Identity Governance & Lifecycle RSA Version/Condition: 7.1.0, 7.1.1 |
Issue | Remote collection agents fail with the latest Java Runtime Environments (JREs) and/or Java Development Kits (JDKs) starting with versions 1.7.0_191 (or above) or 1.8.0_181 (or above). The aveksaAgent.log file (/home/{remoteagentuser}/AveksaAgent/logs/aveksaAgent.log) contains the following errors:
Other errors that have been seen in the aveksaAgent.log file (/home/{remoteagentuser}/AveksaAgent/logs/aveksaAgent.log) associated with this issue are:
and/or
|
Cause | Later versions of Java have added more validations when verifying certificates.This problem occurs when validating the RSA Identity Governance & Lifecycle internal server and client certificates that do not meet the new criteria. This change can also affect collections where certificate validation of the end point certificates is done. Please see RSA Knowledge Base Article 000036712 - LDAP Collector reports "No subject alternative names matching IP address n.n.n.n found" in RSA Identity Governance & Lifecycle for more information. |
Resolution | The following RSA Identity Governance & Lifecycle versions and patches generate certificates that meet the new criteria for JRE and JDK environments.
After installing one of the above patches, the next step is to generate and download new RSA Identity Governance & Lifecycle server and client internal certificates. Because of the patch, these newly generated certificates will be of the correct format expected by the latest JRE and JDK versions. * Note that new installations of RSA Identity Governance & Lifecycle 7.2.0 are not susceptible to this issue. Customers upgrading to 7.2.0 from a previous version are affected and will have to follow the steps in the following section. Steps:
Notes: The server certificate resides on the RSA Identity Governance & Lifecycle server. The client certificate resides on the remote agent server. The client certificate needs to be copied to each remote agent system. IMPORTANT: If you use AFX, the AFX Server client keystore will also need to be updated as explained in the above-referenced RSA Knowledge Base Article. |
Workaround | Use a 1.7 Java Runtime Environment (JRE) and/or 1.7 Java Development Kit (JDK) prior to 1.7.0_191. Do not use version 1.8. |