Access Manager servers are slow to start up.
Originally Published: 2012-11-22
Article Number
Applies To
Red Hat Linux Enterprise
VMWare ESX Server
RSA Access Manager is configured for ANON or AUTH SSL.
Issue
The RSA Access Manager servers are slow to start up. There are no error messages logged. The problem appears to be intermittent and the time to startup is sometimes a minute, sometimes as long as 10 minutes. The pause seems to occur during creation of the servers listen port.
If the servers is started with -DDEBUG_FULL you can see that there is a pause during the SSL initialization.
2012/11/21 15:15:12:206 [ssl] [main (sirrus.util.net.SSLSocketFactory.setEnabledCipherSuites)] - Available Ciphers:
2012/11/21 15:47:30:593 [ssl] [main (sirrus.util.net.SSLSocketFactory.printCiphers)] - Cipher[0]: SSL_RSA_WITH_RC4_128_MD5
Cause
The following articles provide more information:
6521844 : SecureRandom hangs on Linux Systems
Resolution
An alternative is to direct the crypto libraries to use an alternate source for the randomness. Linux has an alternate file called urandom that can be used for this purpose. Note that potentially using a random source with less entropy could reduce the robustness of some crypto features.
You can either modify the global java security.properties file and add the following line:
securerandom.source=file:/dev/./urandom
Or you modify the server startup batch files to pass the following parameter to each instance of the JVM that is started.
-Djava.security.egd=file:/dev/./urandom
Note that the security.properties file may already have a line that says "securerandom.source=file:/dev/urandom" which is similar to the example above but with a path that does not contain a dot. Due to the way file handles are passed to JAVA by some operating systems this setting is ignored in this format. You must include a "." (dot) in the path for the setting to be effective.
Related Articles
RSA Identity Management and Governance 6.9.1 installation fails while installing JDK with error "tar: /tmp/aveksa/packages… 79Number of Views AirWatch ADC Collector test connection fails with "This API has reached end-of-life" error in RSA Identity Governance & Li… 77Number of Views Emails from workflow approval/fulfillment nodes are not generated and sent due to error "Illegal hex characters in escape … 78Number of Views View RADIUS Servers 83Number of Views Troubleshooting tips on testing and configuring NTP for time synchronization on RSA Identity Governance & Lifecycle servers 525Number of Views
Trending Articles
Passwordless Authentication in Windows MFA Agent for Active Directory – Quick Setup Guide RSA Authentication Manager 8.9 Release Notes (January 2026) RSA Authentication Manager Upgrade Process RSA Authentication Manager 8.7 SP2 Setup and Configuration Guide An example of SSO using SAML and ADFS with RSA Identity Management and Governance 6.9.x
Don't see what you're looking for?