RSA Version/Condition: 7.0.1, 7.0.2
RSA documents a method for converting a Wildfly deployment "in place" from standalone to clustered. See:
- v7.0.1: RSA Identity Governance and Lifecycle 7.0.1 - Configuring WildFly Clustering
- v7.0.2: RSA Identity Governance and Lifecycle 7.0.2 - Configuring WildFly Clustering
RSA particularly refers you to the "Supported Configurations" section of both above documents.
To simplify fallback plans, you may consider setting up a new clustered environment, rather than converting the existing standalone deployment "in place". A method for doing so is, at a high level:
- Build a new standalone environment.
- Put the old standalone environment into maintenance mode, to stop all activities on it.
- Export the old standalone's database
- Shutdown the old standalone environment as it will only be needed as a fallback option should the clustering attempt fail
- Import the old standalone database into the new standalone environment
- Convert the new standalone environment to clustered, as described in the above published RSA documentation for your version
- If the clustering fails, you can fallback to the standalone environment. Meanwhile, keep the clustered environment "as is" for troubleshooting.
- At the end of each of the above Configure Wildfly Clustering documents is a "Troubleshooting" section. If you are having difficulty converting to a clustered architecture, see if that section helps. Of course, contact RSA Support if you need assistance.
This method requires an outage while the export, import and clustering is done (steps 2 to 6). Clustering (step 6) may be time-consuming and as it involves many tasks, may be prone to error.
RSA will support importing the database from your standalone deployment to the new cluster deployment. This allows for a procedure that still requires outage time during import and export, but as the clustering step can be done while production is running, the clustering portion of the outage is eliminated. It also minimizes risk as the clustered deployment can be prepared earlier and tested, whilst the fallback procedure is still quick and simple:
- Build a new standalone environment.
- Convert the new standalone environment to clustered, as described in the documents in the Issue section above, and confirm it is generally operative with an "empty" database.
- Put the old standalone environment into maintenance mode, to stop all activities on it.
- Export the old standalone's database
- Import the old standalone database into the new clustered environment: Follow the instructions in the Database Setup and Management Guide for your version, chapter 3, section "Importing AVUSER Schema/Data for a Customer-Supplied Database Restoration/Load". Make sure you do the "Validate Compatibility of the Database Import" steps. The Guides are:
- v7.0.1: RSA Identity Governance and Lifecycle V7.0.1 Database Setup and Management Guide
- v7.0.2: RSA Identity Governance and Lifecycle 7.0.2 Database Setup and Management Guide
- After importing, the following environment information will need to be adjusted. To fix that:
- Delete * from T_SERVER_NODES and the new nodes will register themselves.
- Create new AFX and remote agent server certificates as required. Ensure AFX and remote agents are configured to communicate with the new cluster.
- When all is working in the clustered environment, shutdown the old standalone environment.
- If the clustering fails, you can fallback to the standalone environment. Meanwhile, keep the clustered environment "as is" for troubleshooting.
- Contact RSA Support if you need assistance to troubleshoot.
Information about clustering in Weblogic and Websphere environments is in the Installation Guide for your version. Refer section "Clustered Application Server and Oracle RAC Implementation Environments" within the Weblogic and Websphere chapters.
- v7.0.1: RSA Identity Governance and Lifecycle V7.0.1 Installation Guide
- v7.0.2: RSA Identity Governance and Lifecycle 7.0.2 Installation Guide
Related Articles
Authentication Manager database services do not to start after power outage 185Number of Views After a power outage ACE/Server is not authenticating nor will it start properly 24Number of Views FIM - user (s) experiencing difficulty with SSO - Expired Certificate 11Number of Views Oracle AFX connector message "DH Parameters without subprime Q are not FIPS 140 approved" in RSA Governance & Lifecycle 116Number of Views RSA Via Lifecycle and Governance WildFly cluster not connecting as expected 131Number of Views
Trending Articles
RSA Authentication Manager 8.9 Setup and Configuration Guide RSA Authentication Manager 8.9 Release Notes (January 2026) RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide How to 'Trust' the RSA Authentication Manager Security Console Self-Signed Root CA certificate and prevent Cert warnings. RSA Authentication Manager Upgrade Process