000022758 - How to prevent RSA ACE/Server Quick Admin from hanging when trying to contact ACE/Server

Document created by RSA Customer Support Employee on Jun 16, 2016Last modified by RSA Customer Support Employee on Apr 21, 2017
Version 2Show Document
  • View in full screen mode

Article Content

Article Number000022758
Applies ToRSA ACE/Server 5.2
RSA ACE/Server Quick Admin
IssueHow to prevent RSA ACE/Server Quick Admin from hanging when trying to contact ACE/Server
RSA ACE/Server Quick Admin is unresponsive when browsing to its URL
RSA ACE/Server Quick Admin tracing shows SSL client hello in progress and nothing more:

14:47:52  ACE Admin version QA1.00 started.
...     
      ACP:Creating SSLSocket.
      Connecting to ds209.na.rsa.net/192.168.130.209
      STATE: Sending Client Hello
      [CLIENT HELLO]:
      SSLV3
      [CLIENT HELLO / random / gmtUnixTime]:
      30 59 CB 0E
      [CLIENT HELLO / random / Random bytes]:
      DB 82 75 4F 64 91 DE 28 D3 2A B7 55
      CE B4 48 09 82 B6 DC 12 CA 8C 53 A5 CB FF 71 A6

[CLIENT HELLO / Session ID]

[CLIENT HELLO / Client Cipher Suite]:
00 05 00 04 00 0A 00 00 00 09 00 00 00 00
[CLIENT HELLO/ Compression Method]:
00
CauseThe SSL setup code in RSA ACE/Server 5.2 Quick Admin uses an infinite timeout waiting to receive the ACE/Server's response to SSL handshake initiation. While the ACE/Server should never be unresponsive to the SSL connection initiation, ACE/Server 5.2 can occasionally exhibit this behavior. ACE/Server 5.2 patch 1 corrects this ACE/Server behavior.
ResolutionIn addition to RSA ACE/Server 5.2 patch 1, a Quick Admin hot fix is available that uses a configurable timeout (1-minute default) for the SSL connection setup to ACE/Server. Contact RSA Security Customer Support to request hot fix 23613 for Quick Admin.
Legacy Article IDa30174

Attachments

    Outcomes