|Applies To||Keon Key Recovery Module 6.0|
Keon Certificate Authority 6.0
nCipher Hardware Security Module
Sun Solaris 2.8
|Issue||Keon: Installation cannot continue after untarring KKRM files|
Installed KCA 6.0 on Solaris 8 with nCipher HSM - KCA works fine. Then stopped KCA services, untarred KKRM files onto the KCA installation directory, and then started the KCA services. Next, attempted to visit https://server:444/xpkrs/install/ to continue the KKRM installation. However, the browser waits a very long time for the reply; the KCA services seem to be started but not responding.
When creating the Key Recovery CA during KKRM installation, the nCipher Operator Card Set box is empty and cannot continue the installation
|Cause||The KKRM installation files were untarred as "root", or another user, that was different than the user:group that the KCA Web server runs as. Therefore, the files untarred had a different ownership.|
|Resolution||To correct this issue, stop KCA services, change the ownership of the files untarred in the <KCA-Install-Dir>\WebServer\ directory using the "chown" command to the correct user:group. Then, restart the KCA services - the KKRM installation can then be continued through the browser phase.|
NOTE: One of the untarred files is <KCA-Install-Dir>\Xudad\bin\nfProvider.so - this file should have the same ownership as other files in the Xudad directory, and not the same ownership as the Web server files. If ownership of this file is set incorrectly to the Web server user:group, then at the time of creating Key Recovery CA, the drop-down menu of nCipher Operator Card Sets will be empty.
|Legacy Article ID||a9816|