Unable to install RSA Certificate Manager on a migrated nCipher Security World
Originally Published: 2008-05-19
Last Modified: 2023-10-06
Article Number
Applies To
Win 2003 Server
nCipher HSM, where the security works is pre-exisiting Security World, with existing pkcs11 keys.
Issue
C:\nfast\bin>nfkmcheck nfkmcheck: information: World is in strict FIPS 140-2 mode (see manual) nfkmcheck: information: Module #1 Slot #0 Operator Cardset `OCS1' #1 nfkmcheck: information: Key mscapi container-xxxxxxx arbitrary data object (not a key) nfkmcheck: information: Key mscapi container-xxxxxxxarbitrary data object (not a key) nfkmcheck: information: Key mscapi container-xxxxxxx arbitrary data object (not a key) nfkmcheck: information: Key mscapi container-xxxxxxx arbitrary data object (not a key) 11:41:36 ERROR: Key file bearing AppName pkcs11, Ident uxxxxxx contains different key pkcs11 uxxxxxxx nfkmcheck: fatal error: NFKM_findkey failed: HostDataInvalid nfkmcheck: fatal error occurred - not all checks carried out !
Unable to install RCM on a migrated nCipher Security World
When installing RCM 6.7 the following message appears when trying to configure the Install Directory Server;
Configuration of Install Directory Server (e:\RSA_CM\ids\bin\xudad.exe -setup -d2 -f ids.log ids.conf) failed tieht return code [17]. Please refer to the log file [e:\RSA_CM\ids\bin\ids.log] for more information, and contact technical support if the cause of the problem remains unclear.
The ids.log contains the following:
Reading configuration parameters. Reading configuration from file [ids.conf]
Checking network.
Confirming existence of target directories:
e:\RSA_CM\ids\conf
e:\RSA_CM\ids\ssl\private
e:\RSA_CM\ids\ssl\certs
e:\RSA_CM\ids\db
Bootstrapping XUDA from schema file:
e:\RSA_CM\ids\dist\schema.conf
*** Unable to load crypto provider : pkcs11v2,c:\nfast\toolkits\pkcs11\cknfast.dll *** [XrcUNABLE: unspecified failure] *** Operation failed. *** [XrcUNABLE: unspecified failure] configuration parameter is undefined [installMode]
Cause
Resolution
This can also happen if the hardserver process on solaris is not running.
Related Articles
How to reseed identity columns in SQL Server? 18Number of Views Error on migrating to 7.1.1: IO Error: Connection reset by peer 60Number of Views RSA Authentication Manager 8.6 Hardware Appliance Getting Started 21Number of Views Key Manager Server migration appears to hang after logging 'Migrating AUTH_INTERNAL...' in migrate.log 26Number of Views RSA Authentication Manager 8.1 replica attachment fails with error with migrated primary 257Number of Views
Trending Articles
Artifacts to gather in RSA Identity Governance & Lifecycle How to Update the Root (Server) and Client Certificates in RSA Identity Governance & Lifecycle How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Troubleshooting AFX Connector issues in RSA Identity Governance & Lifecycle How to Download and Reinstall the AFX Server Archive in RSA Governance & Lifecycle
Don't see what you're looking for?