RSA Federated Identity Manager CTConnection Plugin Enhanced for Firewalls and Reliable Connectivity.
Originally Published: 2015-08-27
Last Modified: 2023-10-06
Article Number
000049051
Applies To
RSA Product Set: Federated Identity Manager
RSA Product/Service Type: Federated Identity Management Module
RSA Version/Condition: 4.2
Platform: All
 
Issue
.FIM Plugin needs the aserver connectivity fixed to allow pool refresh like the AxM agents do.

With firewalls or aserver .socket.timout set (acting like a firewall) The torn down connections will never be reset if the user doesn't configure the retry equal to the number of aservers.

The connections would never be torn down if pool refresh could be configured like the agent is with pool refresh pinging the connections in a configurable amount of time

Resolution
Released in FIM 4.2 SP1  several new parameters were added to CTConnection plugin control connections to AxM better.  Especially when firewalls are concerned.

These parameters were added.
PoolRefreshTime - The Pool Interval time in minutes the Runtime API will attempt to refresh the pool,
RefreshPersistTime - The minimum amount of time in seconds the Runtime API will wait before attempting one more refresh when all connections are invalid,
MinRefreshInterval - The minimum amount of time in seconds that has to pass after the last pool refresh before the Runtime API will allow a new attempt


 
Notes
The following are the default values set for the parameters in the CTConnection plugin.
 
PoolRefreshTime – 60 Seconds
RefreshPersistTime – 30 Seconds
MinRefreshInterval- 5 Seconds
 
This default setting can be viewed and modified in the <FIM_INSALL location>\ rsa-fim-config\plugins\CTConnection\plugin.xml.