Document created by RSA Customer Support Employee on Oct 1, 2018
Article Number000036555
Applies ToRSA Product Set: Adaptive Authentication (OnPrem)
RSA Version/Condition: 7.3.x.x
Platform: JBoss 6.4
IssueAfter deploying BackOffcie in JBoss application server version 6.4, although customer was able to access BackOffice URL they were not able to make any changes to the configuration and the following errors were seen in (rsa\logs\backoffice.log)


ERROR [http-/] [] []
[com.rsa.csd.config.AAOPGenConfigProxyImpl] - com.rsa.csd.config.IGenConfigService$GenConfigException:
java.lang.SecurityException: unable to generate key for seed:ECdGVxWxFVDgzHsEbajA0AHvDcT/r/aE at com.rsa.csd.config.GenConfigCommandBase.decryptParamValues
(GenConfigCommandBase.java:430) at com.rsa.csd.config.GenConfigViewStagingCommand.
execute(GenConfigViewStagingCommand.java:59) at com.rsa.csd.config.AAOPGenConfigProxyImpl.
invoke(AAOPGenConfigProxyImpl.java:119) at com.rsa.csd.config.AAOPGenConfigProxyImpl$$FastClassByCGLIB$$12b87dd4.invoke()
at net.sf.cglib.proxy.MethodProxy.invoke(MethodProxy.java:191)

CauseBecause of an issue with JBoss application server 6.4 (bug JBAS-7882), the WS credentials for AdaptiveAuthentication and AdaptiveAuthenticationAdmin cannot be saved for the Administration Console application. The error “Failed to initialize the context: unable to generate key for seed:” is logged.
WorkaroundRun the server with the jboss.vfs.forceVfsJar property set to true. For more information, see the issue JBAS-7882, “Wrong provider code base for security provider included in packed ear” on the JBoss website.

If that workaround does not work, please do the following:

1. Stop the server.
2. Copy cryptoj-6.1.3.jar from the backoffice\WEB-INF\lib directory to the <jre directory>/lib/ext in JBoss installation directory.
3. Start the server.