Permanent pending changes in the Cloud Administration Console
3 years ago
Article Number
000068072
Applies To
RSA Product Set: SecurID Access
RSA Product/Service Type: Cloud Authentication Service

 
Issue
The Cloud Administration Console shows Changes Pending but after clicking the Publish Changes button, the status changes to Publishing, but then reverts back to Changes Pending.

The error that appeared in the IDR logs under /var/log/symplified/symplified.log

ERROR com.symplified.service.shared.appliance.system.UnixServiceUtil[95] - Failed to restart httpd with command: /usr/sbin/start_apache2 -DSYSTEMD -k restart , exit code: 1, stdout/err: [Wed Oct 26 02:45:19.088092 2022] [so:warn] [pid 16333:tid 140283118901440] AH01574: module setenvif_module is already loaded, skipping
ClusterCacheStoreService returned a null cache. This likely means that Infinispan is not properly configured or did not start.


image.png


 
Cause
The cluster has an Embedded Identity Router (IDR) with RADIUS and SSO enabled which is not supported. Thus, when publishing takes place, it still can not be reflected on the Embedded Identity Router.
Resolution
Disabling SSO and RADIUS in the Cluster that has the Embedded IDR in it.

1. From the Cloud Administration Console: Platform > Clusters > Edit the needed Cluster >
Uncheck Enable the SSO service on all identity routers in the cluster and Enable the RADIUS service on all identity routers in the Cluster.

2. Save the changes and publish again.
Workaround
N/A
Notes
N/A