After upgrading an endpoint from PIM 12.81 to PAM SC 14.0 UNAB stopped receiving policies
search cancel

After upgrading an endpoint from PIM 12.81 to PAM SC 14.0 UNAB stopped receiving policies

book

Article ID: 234699

calendar_today

Updated On:

Products

CA Privileged Identity Management Endpoint (PIM)

Issue/Introduction

There is no direct upgrade for an endpoint from PIM 12.81 to PAM SC 14, so the usual procedure implies removing the RPM for PIM 12.8 endpoing and then, upgrading UNAB to 14.1 and installing again the new PAM SC 14.1 endpoint.

This procedure works and it looks good in the endpoint. UNAB is equally capable of communicating with Active Directory, but the server does not receive UNAB polices (even though policies for PAM Server Control look OK). Besides that, in the Worldview, UNAB information is either missing or incorrect (still showing the old version)

Environment

 CA PAM 14.1, all flavours

Cause

In PAM SC 14.1 the communication to the message queue is established to port 61616 in the distribution server, as compared to port 7243 in the case of PIM 12.81. This results from the change of message queue system from TIBCO to ActiveMQueue.

If the message queue has not been updated in file accommon.ini, the endpoint, and notably UNAB as well, will try to reach to the old queue and it will fail to retrieve or sent data. This will be reflected in the unab debug logs.

Resolution

Make sure that in accommon.ini the Distribution_Server option is set to the name or ip of that server and that port specified is 61616

e.g.

ssl://test.example.com:61616
 
Default:
 None

and restart PAM SC and unab after the change