AMIS AM Prime Unable to create/add user account from HDAP portal
Originally Published: 2020-12-18
Article Number
Applies To
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.1.1, 8.x
Platform (Other): AMIS 1.3
Issue
There is some unexpected issue with the server. Status: 504 Please check if the server is accessible.
AMIS logs
===hdap.log===
ERROR com.rsa.pso.lap.springbeans.AMISClientServiceImp - Exception :: AMISClientServiceImp.getIdentitySources() :: /java.lang.NullPointerException
ERROR com.rsa.pso.lap.web.SearchActionBean - Exception while creating user/com.rsa.pso.exception.ServiceException
ERROR com.rsa.pso.lap.web.SearchActionBean - Exception occurred sending status code 500/com.rsa.pso.exception.ServiceException
DEBUG com.rsa.pso.util.LAPUtils - Action /am71/user/createUser is protected by permission user:create
ERROR com.rsa.pso.lap.web.SearchActionBean - Exception occurred sending status code 401/java.lang.Exception
===claimfilter===
ERROR com.emc.rsa.pso.amis.service.claimFilter - unable to validate token 22697441
INFO com.emc.rsa.pso.amis.service.claimFilter - Returning unauthorized.
INFO com.emc.rsa.pso.amis.service.claimFilter - Loading claim set
INFO com.emc.rsa.pso.amis.service.claimFilter - Session token : RSA_AUTHENTICATION_TOKEN was not found in session.
Cause
Sample Response after AMIS May 2020 ChangeList ID 1304761:
<?xml version="1.0" encoding="UTF-8" standalone="no" ?>
<serviceResult result="true">
<driverStatistics maxAllocTime="1857" maxReleastTime="0" maxThreadCount="1" totalAllocTime="1857" totalReleaseTime="0" totalRequests="1" />
</serviceResult>
Resolution
Steps to follow:
- Copy am8.war to Prime SSP servers.
- Stop AMIS service - WinServices Apache AMIS
- cd to ~/primekit/tomcat/tomcat-amis/work/
- From within dir above "rm -rf Catalina" or "rename Catalina"
- cd to ~/primekit/tomcat/tomcat-amis/webapps/
- Rename am8.war to .old_repl_tok extension
- (rename or) "rm -rf auth/ am8/ workflow/ rsa-endpoints/" from webapps repeat for other directories too: auth, am8, and workflow
- Copy the new am8.war to ~/primekit/tomcat/tomcat-amis/webapps/.
- Start AMIS
Should not need to reset permissions script 3_reset_perms.bat in Windows.
Workaround
Notes
Related Articles
RSA Authentication Manager – Unable to Add or Manage Users with Error “The specified ID is already in use” 5.24KNumber of Views Unable to load bean named CTKIPServerService when importing a token via CTKIP to RSA SecurID Software Token 697Number of Views Unable to log on to the RSA Access Manager Entitlements Manger (AdminGUI) after upgrade 42Number of Views Unable to re-use a deleted account name if the account was previously disabled in RSA Identity Governance & Lifecycle 441Number of Views Unable to Resolve User by Login ID and/or Alias or Authenticator Not Assigned to User When Attempting to Authenticate via … 2.15KNumber of Views
Don't see what you're looking for?