When the URL for an RSA endpoint is modified, attempts to update the configuration within the Provisioning Manager may fail with connection errors. This occurs because the eTDYNPassword and eTDYN-str-multi-ca-04 attributes are encrypted based on the original URL. To successfully update the endpoint, these attributes must be cleared and re-initialized.
Identity Manager
The error occurs because the RSA endpoint's connection URL has changed, causing a decryption failure for the eTDYNPassword and eTDYN-str-multi-ca-04 attributes. These attributes are cryptographically linked to the previous URL, necessitating a reset when the URL is modified.
To update the RSA endpoint URL, follow these steps:
Update the URL in JXplorer:
etadb > im > RSASecurID 7 > MyRSAEndpointClear Required Attributes:
eTDYNPasswordeTDYN-str-multi-ca-04Update Attributes via etautil:
etautil command on the Provisioning Server to re-encrypt and update the attributes:Verification:
eTDYNPassword and eTDYN-str-multi-ca-04 are now populated.
Note: If you do not update both attributes simultaneously as shown above, you will encounter the following decryption error: DYN Endpoint [Name] read failed: Error decrypting attribute: Attribute eTDYNConnectionURL has been modified since this attribute was encrypted. Please reset the encrypted attribute.
For additional context, refer to: