000033007 - RSA Authentication Manager 8.1 failed to backup RADIUS audit files

Document created by RSA Customer Support Employee on Jun 14, 2016Last modified by RSA Customer Support Employee on Apr 21, 2017
Version 4Show Document
  • View in full screen mode

Article Content

Article Number000033007
Applies ToRSA Product Set : SecurID
RSA Product/Service Type : RSA Authentication Manager
RSA Version/Condition: 8.1 SP1
IssueWhile performing a backup using the Authentication mManager Operations Console, an error is reported:
 
Failed to backup RADIUS audit log files. IOException occurred.

Taken from the Advanced Status View:
Start export of systemfields.properties...
Completed export of systemfields.properties.
Starting RADIUS backup..
Backing up RADIUS data to /opt/rsa/am/backup/staging/radius-data/RADIUS_DATA_BACKUP
Start the RADIUS Backup
RADIUS Backup succeed, and the dump files is located at /opt/rsa/am/backup/staging/radius-data/RADIUS_DATA_BACKUP
Backing up RADIUS dictionary...
Successfully backed up RADIUS dictionary to /opt/rsa/am/backup/staging/radius-dict
Backing up RADIUS configuration files...
Backing up RADIUS configuration file /opt/rsa/am/utils/etc/../..//radius/securid
Backing up RADIUS configuration file /opt/rsa/am/utils/etc/../..//radius/sdconf.rec
Backing up RADIUS configuration file /opt/rsa/am/utils/etc/../..//radius/vendor.ini
Backing up RADIUS configuration file /opt/rsa/am/utils/etc/../..//radius/ttlsauth.aut
Backing up RADIUS configuration file /opt/rsa/am/utils/etc/../..//radius/spi.ini
Backing up RADIUS configuration file /opt/rsa/am/utils/etc/../..//radius/securid.ini
Backing up RADIUS configuration file /opt/rsa/am/utils/etc/../..//radius/sbrd.conf
Backing up RADIUS configuration file /opt/rsa/am/utils/etc/../..//radius/radius.ini
Backing up RADIUS configuration file /opt/rsa/am/utils/etc/../..//radius/peapauth.aut
Backing up RADIUS configuration file /opt/rsa/am/utils/etc/../..//radius/events.ini
Backing up RADIUS configuration file /opt/rsa/am/utils/etc/../..//radius/eap.ini
Backing up RADIUS configuration file /opt/rsa/am/utils/etc/../..//radius/classmap.ini
Backing up RADIUS configuration file /opt/rsa/am/utils/etc/../..//radius/account.ini
Successfully backed up RADIUS configuration files.
RADIUS log location: /opt/rsa/am/radius
RADIUS report location: /opt/rsa/am/radius/authReports
Backing up RADIUS audit logs...
Command timeout error: null
Failed to backup RADIUS audit log files. IOException occurred.
An error occurred while backing up the system:
Failed to backup RADIUS.
CauseThe RSA RADIUS server log file records RADIUS events, such as server startup or shutdown or user authentication or rejection, as a series of messages in an ASCII text file. The log filenames are date stamped as YYYYMMDD to identity when they were created (e. g., 20160901.log). The backup process includes these RSA RADIUS server log files and the error occurred because the number and size of these log files reached a growth that the backup timeout trying to preserve them.
Resolution
  1. Confirm whether trace and/or debug level have been altered in the radius.ini file.  To do this, login to the Operations Console and select Deployment Configuration > RADIUS > Manage RADIUS Server Files.  
  2. Click on the radius.ini file and select Edit.
  3. Ensure the LogLevel and TraceLevel values are set to 0, unless otherwise advised by RSA Customer Support for troubleshooting an RSA RADIUS issue.
[Configuration]
StartupTimeout=600
StartupTimeout=600
LogLevel                        = 0
TraceLevel                      = 0

LogfilePermissions              = rsaadmin:rsaadmin 600
Apply-Login-Limits              = yes
;PrivateDir                     = <file system location>
FramedIPAddressHint             = no
CheckMessageAuthenticator       = 0
LogAccept                       = 1
LogReject                       = 1
AddSourceIPAddressAttrToRequest = 0

  1. Next, an administrator may want to tidy up the RSA RADIUS log and associated accounting files in the /opt/rsa/am/radius folder. 
    1. Logon to the command line with the rsaadmin account.
    2. Navigate to/opt/rsa/am/radius.
    3. Create a tar.gz file for the RSA RADIUS log and account files based on year or year and month. Examples below:
    • To tar the logs for all of 2015

tar cvzf /tmp/RADIUSlogact2015.tar.gz /opt/rsa/am/radius/2015*.*


  • To tar the logs for June 2015

tar cvzf /tmp/RADIUSlogact201506.tar.gz /opt/rsa/am/radius/201506*.*


  1. After preserving the RSA RADIUS log and account files they can then be removed from the RSA RADIUS folder. Example below:
  • To tar the logs for all of 2015

rm -rf /opt/rsa/am/radius/2015*.*


  • To tar the logs for June 2015

rm -rf /opt/rsa/am/radius/201506*.*


  1. Now perform the backup again via the Operations Console (Maintenance > Backup and Restore > Back Up Now.  
  2. Enter a Backup Password and enter the Confirm Backup Password.
  3. Click Backup.

Attachments

    Outcomes