RSA Authentication Manager 8.2 SP1 system log shows error message: Message Key manager limit reached when using the RSA Authentication Agent API
Originally Published: 2018-07-26
Article Number
Applies To
RSA Product/Service Type: Authentication Agent API
RSA Version/Condition: 8.5.1
Platform: Linux
Platform (Other): FoxT BoKs
O/S Version: SUSE Linux
Issue
ERROR All available agent keys are in use. The Agent Message Key Manager service cannot add new keys until some current keys expire or are deleted. Result: Message Key manager limit reached Activity Key: Agent Message Key Manager Key Limit
Cause
Resolution
If your deployment sees this error after the work-around, possibly because you have hundreds or thousands of TCP agents, you may also need to check if the BoKS agent or other TCP agent is re-using keys or discarding them. If it is not re-using them, you can change the key lifetime to a much shorter period. Please contact RSA customer support for the details on this key lifetime change or contact the TCP agent partner vendor or developer about key re-use options.
Workaround
- Open an SSH session to the primary Authentication Manager server.
- Login with the rsaadmin operating system account and password.
- Run the command ./rsautil store -a config_all auth_manager.messagekey.max_message_keys 30000, as shown:
login as: rsaadmin Using keyboard-interactive authentication. Password: <enter operating system password> Last login: Wed Jun 20 05:24:51 2018 from jumphost.vcloud.local RSA Authentication Manager Installation Directory: /opt/rsa/am rsaadmin@am82p:~> cd /opt/rsa/am/utils rsaadmin@am82p:/opt/rsa/am/utils> ./rsautil store -a config_all auth_manager.messagekey.max_message_keys 30000 Please enter OC Administrator username: <enter Operations Console administrator user name> Please enter OC Administrator password: <enter Operations Console administrator password> pgsql.bin:/tmp/2273f1ca-a9c4-40ce-8173-6780a85f8f902222344216645874570.sql:149: NOTIOCE: Changed the value of configuration parameter 'auth_manager.messagekey.max_message_keys' from '10000' to '30000' for all instances config_all ------------ (1 row)
Notes
Related Articles
Incompatibility with Encoding of Private Key causes various issues on an RSA SecurID Access Identity Router running SLES12… 200Number of Views Manually applying the definition files to ClamAV for RSA Authentication Manager 8.x 603Number of Views Skyhigh End User Remediation Flow - SAML Relying Party Configuration - RSA Ready Implementation Guide 17Number of Views RSA Identity Governance and Lifecycle RESTful web service response: java.lang.IllegalStateException 276Number of Views Windows Agent failing to authenticate local Group Membership with 30 Secs timeout 118Number of Views
Trending Articles
Troubleshooting RSA SecurID Access Identity Router to RSA Authentication Manager test connection failures RSA SecurID Software Token 5.0.2 Downloads for Microsoft Windows RSA Authentication Manager 8.9 Release Notes (January 2026) RSA Governance & Lifecycle 8.0.0 Administrators Guide Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory
Don't see what you're looking for?