RSA Product/Service Type: SecurID Access Prime (Linux)
When trying to start RSA PrimeKit services or run scripts , the following error displays:
../../java/latest/bin/java: error while loading shared libraries: libjli.so: cannot open shared object file; no such file or directory.
The <primekit>/java/latest/bin/java executable is in the proper folder.
Even though <primekit>/java/latest/bin/java is in the correct directory, the system is unable to access it. The most common causes for this are:
- fapolicyd
- SELinux
- Trellix
- Tanium
- Another application that prevents code from executing
SecurID Access Prime (aka PrimeKit) is its own environment. It contains all the Java and Apache Tomcat code required to do its job. Everything that PrimeKit needs to run is contained in /opt/rsa/primekit (or C:\rsa\primekit in Windows).
Ensure that nothing on the system is blocking any code from running under /opt/rsa/primekit or any of its subdirectories. The actual whitelisting of /opt/rsa/primekit is beyond the scope of this document; instead, whoever is responsible for hardening the system in the first place should be consulted on how to remove restrictions from /opt/rsa/primekit.
The same is true for Windows installations of Primekit; that is, ensure that there is nothing interfering with the execution of anything under C:\rsa\primekit (or wherever PrimeKit was installed).
Related Articles
Alternative to running RSA ACE/Server 5.1 patch installer for installation issues on hardened systems 4Number of Views Announcing the March Release of SecurID 20Number of Views Patch/upgrade fails with 'java: No such file or directory' error in RSA Identity Governance & Lifecycle 168Number of Views Self-Service 5Number of Views Error "No such file or directory while trying to open /dev/disk/by-id/scsi-XXXX-part1" and services do not start on RSA Se… 62Number of Views