000031201 - A system activity is reporting an LDAP error code in RSA Authentication Manager 8.1 SP1

Document created by RSA Customer Support Employee on Jun 14, 2016Last modified by RSA Customer Support Employee on Apr 21, 2017
Version 2Show Document
  • View in full screen mode

Article Content

Article Number000031201
Applies ToRSA Product Set: SecurID

RSA Product/Service Type: Authentication Manager

RSA Version/Condition: 8.1 SP1

Platform: SUSE Linux

O/S Version: 11 SP3
IssueThe Directory User (or Windows account used to query the Microsoft Active Directory) used in the identity source configuration had a password change. The Directory Password was updated by an administrator in the identity source configuration.
Users are displayed when querying the identity source using the Security Console however the system activity reports "javax.resource.spi.ResourceAdapterInternalException: Unable to create managed connection [LDAP: error code 49 - 80090308: LdapErr: DSID-0C0903C8, comment: AcceptSecurityContext error, data 775, v23f0 ]."
 
CauseThe authentication manage instance is caching the Directory User ID and Directory Password and the LDAP error being generated is related to the Directory User (or Windows account used to query the Microsoft Active Directory) used in the identity source configuration being locked out.
ResolutionIdentity sources are configured via the Operations Console > Deployment Configuration > Identity Sources > Manage Existing > left-click the Identity Source name and select Edit – under the Connection(s) tab an administrator can change the Directory User ID and/or Directory PasswordThe Directory User ID and Directory Password can be tested with the Test Connection button.
Stopping and starting the authentication manager instance will ensure any cached data is cleared.
  1. Use the rsaadmin account to logon to the operating system of the authentication manager instance.
  2. Navigate to the /opt/rsa/am/server folder using the 'cd' command
  3.  Stop the authentication manager services with ./rsaserv stop all
  4. Start the authentication manager services with ./rsaserv start all
  5. Logout using the command exit
 
NotesURL http://ldapwiki.willeke.com/wiki/Common%20Active%20Directory%20Bind%20Errors allows an administrator to enter the data HEX value i.e. 775 to provide a description/information on the LDAP error code.
Contacting RSA Customer Support
TelephoneFor urgent issues use on of the telephone numbers listed at URL http://www.emc.com/support/rsa/contact/phone-numbers.htm 
EmailFor non-urgent issues email support@rsa.com
Case
   Management
Case Management is found at URL https://knowledge.rsasecurity.com/scolcms/mysupport.aspx
   (requires access to RSA SecurCare Online)

 
 

Attachments

    Outcomes