After an upgrade to RSA Authentication Manager 8.4 patch 6 and upgrading the Java version on the Authentication Manager Integration Service (AMIS) server from JRE 1.7.0 to JRE 1.8.0_221, the Self-Service Portal (SSP) failed to generate the QR code for the token request/replacement.
The QR code image keeps spinning without generating the QR code.
The CTF conversion utility uses the Java random function which results in a massive delay in minutes. Oracle has noted this performance issue regarding using the random function to generate cryptographically strong random number generator (RNG), and the resolution is below in the resolution section.
As per the logs:
The header request API call sent from the AMIS server to the Authentication Manager server is not correct. It is stating that the distribution type of the token is CTF, however it should be CTKIP.
Below is the API call generated from the SSP request, found in the ssp_daily.log file, with theissuehoghlighted in red:
As per the Prime AMIS Developer's Guide, the request for CTKIP should look like the snippet shown below. The header below does not contain the distribution type CTF which is the error in the above request.