CA DRAS - Error:CA DRAS Server is not available for the security check function.
search cancel

CA DRAS - Error:CA DRAS Server is not available for the security check function.

book

Article ID: 216818

calendar_today

Updated On:

Products

Output Management Web Viewer

Issue/Introduction

The customer received the following error during login:

 Error: CA DRAS Server is not available for the security check function."

Things worked fine the previous week.

Understand from mainframe team that encryption certs were updated in their end.

I enabled debug mode in non-prod ca viewer 

Please see attached logs.

Below is the log information I got from my mainframe team,

07.03.28 STC00171 CAS9899E Task 0001 Error: SSL function rc = 420 ->
07.03.28 STC00171 CAS9899E Task 0001 Error: Socket closed by remote partner
07.03.28 STC00171 CAS9899E Task 0001 Error: SSL I/O ErrNo = 121 ->
07.03.28 STC00171 CAS9899E Task 0001 Error: EDC5121I Invalid argument.
07.03.28 STC00171 CAS9861I Task 0001 closing (xx.xxx.xx.xxx)/ppppp.
07.03.28 STC00171 CAS9861I Task 0001 delivered 1 packets, 123 bytes.
07.03.55 STC00171 CAS9855I Task 0002 has connection from (xx.xxx.xx.xxx)/pppp
07.03.55 STC00171 CAS9899E Task 0002 Error: SSL function gsk_secure_socket_init
07.03.55 STC00171 CAS9899E Task 0002 Error: SSL function rc = 420 ->

 

 

Environment

Release : 12.1

Component : OUTPUT MANAGEMENT WEB VIEWER FOR ALL PLATFORMS

Resolution

The error occurred due to a failing on the SSL handshake:

DEBUG 04 Jun 2021 00:46:04,445 [https-openssl-nio-443-exec-1] omgmt.drascci.cci.OmCCIInterface.CCIInit: CCI.Init fails with result code: REQUEST_CCI_INIT_FAILURE - Error creating SSL socket for server:XXXX.xxx.com port:pppp. SSL Handshake Exception during initial handshake - General SSLEngine problem, failure caught during CCI Init Interface for :DRASCLIENT
com.ca.ccs.cciclient.exceptions.CCIException: CCI.Init fails with result code: REQUEST_CCI_INIT_FAILURE - Error creating SSL socket for server:XXXX.xxx.com port:pppp. SSL Handshake Exception during initial handshake - General SSLEngine problem

------------------------------------------------------

This was the certificate, for CCI, on the Windows side.

C:\Program Files\CA\CA_OM_Web_Viewer\config\cci.jks

---------------------------------------------------------

The client was asked to contact their security people, to let them know that matters fail on the handshake, and that they had to have that keystore on their side.