What is the originator info?
Originally Published: 2010-10-21
Last Modified: 2023-10-06
Article Number
Applies To
Issue
What is the originator info (or ORIGINATOR_INFO, or originator ID)
Resolution
Originator information is stored in the application registration file. It is a way to uniquely identify the source where encryption was done.
A new Originator ID is requested to RKM server automatically when the RKM client detects a client environment or configuration change such as:
- Operation user account name has changed. (Operating system login user)
- IP address has changed
- Host name has changed
- Credentials have changed. (Client Identity certificate changed)
RKM 2.7 introduced the concept of originator information.
Originator information is a related to client registration. This is described starting on page 43 of the 2.7.1 C# Client Developer's Guide. The following information appears on page 45:
"If the Key Manager C# Client application is registered with a Key Manager Server, or if the Key Manager C# Client detects an environment change (such as a change of IP address), it automatically requests the information from the Key Manager Server and stores it in the registration file to renew the originator information. If the Key Manager Server is unavailable, or transport is disabled for local cache operations and environment data has been changed, encryption operations will normally fail because the Key Manager C# Client cannot renew the originator information. However, if high availability encryption is required, add the following parameter to the registration file:
client.origin_info.optional_in_ciphertext=true
When this option is set to true, the originator information renewal error is ignored and the Key Manager C# Client does not add the originator identifier in the cipher text."
So, if there has been an environment change (such as IP address) on the RKM client, the client will try to retrieve updated originator info from the RKM server. If the RKM client cannot contact the RKM Server, encryption operations will fail unless the following is set in the C or C# client registration file (not the configuration file):
client.origin_info.optional_in_ciphertext=true
The Java client implements this differently. It has a different variable that needs to be set in the configuration file:
high.availability=true
Regardless of whether you're running in high availability mode, when the client can't contact the server, you may see non-fatal errors in the client logs such as: "Error reading origin info from RKM server, ret: 10003".
Related Articles
.\src\service_provider\https_svc_impl.c:488 - ret = 10022. HTTP error in Key Reponse: 302 18Number of Views How to Start/Stop/Access Oracle Enterprise Manager (OEM) in RSA Governance & Lifecycle 188Number of Views Unable to open a Form from Change Requests after making changes to a text in a Static Text Control Type in a form 17Number of Views AFX Connectors remain in a Deployed state and 'Could not locate data file kahadb/db-XXX.log' error in RSA Identity Governa… 461Number of Views How to identify which operating system is installed on an RSA Identity Governance & Lifecycle Appliance 244Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Reporting on RSA Authentication Manager 8.x users with On-Demand Token, a fixed passcode or a hardware/software token assi… How to Download OTP Token Seed Files from myRSA Anomalix idGenius - SAML Relying Party Configuration - RSA Ready Implementation Guide RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide
Don't see what you're looking for?