Microsoft SQL Server Collectors can no longer connect to the SQL Server database after upgrade to Microsoft SQL Server 2012 and Microsoft Windows 2012 with RSA Identity Governance & Lifecycle
Originally Published: 2017-07-17
Last Modified: 2026-05-13
Article Number
Applies To
RSA Version/Condition: 6.9+ (JDK 6.0), 7.X+ (JDK 7.0)
Platform (Other): JDBC 4.0, JDBC 4.1
Platform (Other): Microsoft SQL Server 2012
Platform (Other): Microsoft Windows 2012
Issue
The aveksaServer.log has the following error:
06/21/2017 11:20:33.239 ERROR (ApplyChangesRegularThread-136287) [SystemErr]
com.microsoft.sqlserver.jdbc.SQLServerException: The driver could not establish a secure connection to SQL Server by using Secure Sockets Layer (SSL) encryption. Error: "SQL Server did not return a response. The connection has been closed."
com.microsoft.sqlserver.jdbc.SQLServerException: The driver could not establish a secure connection to SQL Server by using Secure Sockets Layer (SSL) encryption. Error: "SQL Server did not return a response. The connection has been closed."
The collector is configured to use the Microsoft SQL Server JDBC driver:
Cause
This is a known issue in the following versions of RSA Identity Governance and Lifecycle which uses the Microsoft JDBC driver 4.0 and 4.1 when connecting to an external Microsoft SQL Server for collections and connectors where DB Type is SQLServer or SQLServer3.
- RSA Identity Governance & Lifecycle 6.9.1
- RSA Identity Governance & Lifecycle 7.0.0
- RSA Identity Governance & Lifecycle 7.0.1
- RSA Identity Governance & Lifecycle 7.0.2
Resolution
- RSA Identity Governance & Lifecycle 7.1.0
- RSA Identity Governance & Lifecycle 7.1.1
Note that Microsoft JDBC driver 4.2 only runs on Java JRE 1.8. This version of the driver cannot be used on older versions of RSA Identity Governance and Lifecycle.
For solutions for older versions see the Workaround section.
Workaround
This is a legacy Knowledge Base Article and only applies to the listed versions which are no longer actively supported.
RSA does not recommend the continued use of the public domain JTDS driver on current versions of the product. RSA recommends customers use the JDBC driver specific for their database.
Use the open-source third-party JTDS JDBC driver. This may be downloaded for free from the web by the customer.
- Upload the driver to:
- Prior to RSA Identity Governance & Lifecycle 7.0 upload to /home/oracle/jboss-4.2.2.GA/server/default/deploy/aveksa.ear/aveksa.war/WEB-INF/LocalAgent/common/lib.
- For RSA Identity Governance & Lifecycle 7.0 and above follow the steps in the relevant RSA Upgrade and Migration guide to customize the ear file using customizeACM.sh.
- RSA Via Lifecycle and Governance Upgrade and Migration Guide 7.0
- RSA Via Lifecycle and Governance Upgrade and Migration Guide 7.0.1
- RSA Via Lifecycle and Governance Upgrade and Migration Guide 7.0.2
- Configure the collector(s) as follows:
Related Articles
Can archived aveksa.ear files stored in $AVEKSA_HOME/archive be deleted in RSA Identity Governance & Lifecycle? 140Number of Views Can a running review be refreshed without losing the completed work in RSA Identity Governance & Lifecycle? 171Number of Views Can the Microsoft Integrated Windows Authentication (IWA) icon be hidden in the RSA SecurID Access Application Portal? 95Number of Views Running script to determine if hardware appliance can successfully upgrade to Authentication Manager 8.7 SP1 466Number of Views How users can generate a temporary emergency access tokencode from RSA Authentication Manager 8.x Self-Service Console 587Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Reporting on RSA Authentication Manager 8.x users with On-Demand Token, a fixed passcode or a hardware/software token assi… How to Download OTP Token Seed Files from myRSA Anomalix idGenius - SAML Relying Party Configuration - RSA Ready Implementation Guide RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide
Don't see what you're looking for?