RCM CRL not being generated automatically per crl timer configuration
Originally Published: 2011-02-01
Article Number
Applies To
RSA Certificate Manager 6.8 HA
Microsoft Windows Server 2003 SP2
ADAM High Availability
Certificate Revocation List (CRL)
Issue
From the trace.log, observed the following error in various places:
2011/01/03 13:32:20 ldap 1556 2884 D:\RCM\CERTMGR-3837\strong-sentry\ldap\ldap-3.3-hodges\servers\slapd\crltimer.c:4016 Automatic complete CRL generation Failed.
If RCM is configured with an external LDAP (i.e., only one instance of RCM), crl timers are disabled by default. To use crl timers, please follow the steps in "Using Revocation List Timers with HighAvailability" section on page 212 of RSACertificateManagerAdministratorsGuide.
In "High Availability Configuration - Revocation List Generators" configuration, we can configure values for primary instance and Health check period even if secondary is not configured for HA.
Cause
Resolution
In this situation, using short hostname (i.e., rcm1), instead of the FQDN, as the primary HostName resolved the issue.
Notes
Related Articles
Does RCM handle all special characters in email address allowed per the RFC? 12Number of Views Service Provider hangs at throughput of 5 assertions per second 25Number of Views CRL timer permanently stops when LDAP store under load 11Number of Views Citrix MetaFrame bypassing authentication on a per-session basis 7Number of Views How to Restrict of Active Tokens per User on RSA Authentication Manager. 12Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device How to replace the RSA Authentication Manager self signed console certificate with a signed certificate from Microsoft Act… RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide How to Request Access to the RSA Authentication Manager AMI for AWS via RSA Support
Don't see what you're looking for?