Error when signing a certificate request using RCM in HA with Thales HSM
4 years ago
Originally Published: 2014-11-27
Article Number
000049710
Applies To
RSA Product Set: Digital Certificate Solutions
RSA Product/Service Type: Certificate Manager
RSA Version/Condition: 6.9
Thales / nCipher HSM
Issue
Trying to approve a certificate request from RCM setup in High Availability (HA) mode and using Thales/nCipher HSM give the following error:
req-authorize.xuda: line 664: [XrcNOTFOUND] Unable to locate requested member or object. 

After enabling tracing the following is logged in trace.log:
2014/11/27 13:40:12 signing  29210  60418928 signerSignCertificate.c:1887 Return code = XrcNOTFOUND (11).
 
 
Cause
Security World / RFS not in sync on the second RCM instance
Resolution
Sync the RFS using the following command:
rfs-sync -update

Without restarting any service you should be able to issue the certificate