Getting an error while importing Federation SSO domain from RHEL 6(R12.7) to RHEL 8 (R12.8)
search cancel

Getting an error while importing Federation SSO domain from RHEL 6(R12.7) to RHEL 8 (R12.8)

book

Article ID: 233071

calendar_today

Updated On:

Products

SITEMINDER

Issue/Introduction

We have exported a Federation SSO client policy from RHEL 6 policy server( running on Siteminder 12.7 version) to  RHEL 8 policy server (running on Siteminder on R12.8  version), when we are trying to import the policy the domain got failed. Please refer the below import error. Authentication scheme imported successfully. 


dc2sdelssmu010-(/opt/vgi/siteminder)->/opt/vgi/siteminder/smps/r12.8/bin/XPSImport FIE_DOMAIN_00741_qa01.xps -validateonly -npass
[XPSImport - XPS Version 12.8.0500.2546]
Log output: /opt/vgi/siteminder/smps/r12.8/log/XPSImport.2022-01-20_160156.log
Initializing XPS, please wait...
Log Time Phase/Section #Objects %age Elapsed
-------- ------------------------ --------------- ----------- -----------------
16:02:04 Initializing
16:02:04 Reading 00:00:00
16:02:04 Reading 00:00:00 00:00:00
16:02:04 Analyzing 0/20 00:00:00
(ERROR) : [sm-xpsxps-01830] An object with XID "CA.SM::AuthScheme@0d-0006a6a0-791c-1171-b914-38420aad0000" as specified in the object reference with Reference ID "Ref00004" in the XML file does not exist in the policy store. (Line:unavailable, XID not found)
16:02:04 Analyzing/Reference 2/20 10% 00:00:00 00:00:00
16:02:04 Analyzing/Reference 4/20 20% 00:00:00 00:00:00
(FATAL) : [sm-xpsxps-05810] Import failed.

Environment

Release : 12.8

Component :

Cause

Customer was importing two sets of auth scheme/domain.  They got the order right in the first operation, but ran into this on the second one because they were trying to validate the domain import before importing the auth scheme.  The xml for the domain import referenced the auth scheme, thus the auth scheme needed to be imported before the validation of the domain import would succeed.

Resolution

Since the domain referenced the auth scheme, the auth scheme needed to be imported first.  Done in this order, the validations/imports succeeded with no errors.