RSA Product Set: SecurID
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.7 and lower
Critical Event Notifications
Attention! The following critical system event occurred: Not able to sync time. Either the NTP service is not running or unable to sync time from the NTP server.
System Activity Report
System Time Synchronization Configuration Check,"Checking configuration for System Time Synchronization. Warning,All NTP Servers are unavailble - potential for significant system time drift,SYSTEM,,,,,ALL_NTP_SERVERS_UNVAILABLE
The following article provides some Linux commands to verify the status of the NTP sync function.
This article is to assist customers and support personnels to find where the NTP related problem lies and to direct troubleshooting effort to the right areas.
- Login the Authentication Manager primary via an SSH session or direct connection.
- Starting with ntpq commands, the primary server returns offsets value of 105426 ms, which is about two minutes off.
See knowledge article Unable to check NTP status using ntpq -p command on RSA Authentication Manager 8.x.
How to allow to run ntpq command
- Run ntpq -n to enable a DNS lookup of the NTP server:
[am83p ~]# ntpq -n ntpq> as ntpq> pe
- The command ntpdc identifies the problem with the time source(s):
[am83p ~]# ntpdc -c kerninfo
pll offset: 0 s
pll frequency: 27.220 ppm
maximum error: 0.884516 s
estimated error: 1.6e-05 s
status: 2040 unsync nano
pll time constant: 0
precision: 1e-09 s
frequency tolerance: 500 ppm
- And the ntptime command agrees with the ntpdc command output:
[am83p ~]# ntptime
ntp_gettime() returns code 5 (ERROR)
time d260f02f.d3c9039c Wed, May 2 2018 14:17:17.573, (.571058557),
maximum error 927516 us, estimated error 16 us, TAI offset 0
ntp_adjtime() returns code 5 (ERROR)
modes 0x0 (),
offset 0.000 us, frequency 27.220 ppm, interval 1 s,
maximum error 927516 us, estimated error 16 us,
status 0x2040 (UNSYNC,NANO),
time constant 0, precision 0.001 us, tolerance 500 ppm,
RSA Support may assist in finding a problem with NTP in an environment; however, it is not RSA Support's scope to troubleshoot its errors. It is the customer's responsibility to provide reliable time sources and their paths to the RSA Authentication Manager server(s). System Administrators may look into their firewall rules or fetch another reliable time source to resolve the issue.
Related Articles
On-demand token delivery is not working after upgrading to RSA Authentication Manager 8.4 232Number of Views SNMP queries and traps not working after configuring Authentication/Privacy passwords on RSA Authentication Manager 8.x 366Number of Views Replica fail over is not working on PAM agent version v7.1.0.149.01 for RSA Authentication Manager 70Number of Views RSA SecurID Access Automatic Integrated Windows Authentication (IWA) not working 299Number of Views Alias host name redirect to consoles is not working after upgrade to RSA Authentication Manager 8.3 patch 1 476Number of Views
Trending Articles
RSA SecurID software token .sdtid file fails to import into RSA SecurID Software Token 5.0 for Windows RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA Authentication Manager Patch Updates Unable to login to RSA Authentication Manager Security Console as super admin RSA Authentication Manager Upgrade Process