Configuring and Troubleshooting FIPS Mode in ra.xml - CA Identity Manager
search cancel

Configuring and Troubleshooting FIPS Mode in ra.xml - CA Identity Manager

book

Article ID: 36577

calendar_today

Updated On:

Products

CA Identity Manager CA Identity Suite

Issue/Introduction

This article clarifies the purpose of the FIPS_Mode parameter in the ra.xml file used by CA Identity Manager to connect to the Policy Server. Incorrect configuration of this parameter often leads to connection failures.

Environment

Identity Manager 14.5 & 15

Cause

The ra.xml file contains connection parameters for the Identity Manager to Policy Server communication. If the FIPS_Mode setting in ra.xml does not match the actual installation mode of the Identity Manager environment, it results in an "Agent API -1" error during connection initialization, as Identity Manager fails to decrypt the stored credentials.

Resolution

Verify Current Configuration

  1. Navigate to the directory where the ra.xml file is deployed on your application server.
  2. Open the file and locate the FIPS_Mode parameter.
  3. Ensure the value ('True' or 'False') matches your environment's installation mode.
  4. If the value is incorrect, update it accordingly.

 

Error Analysis

If a mismatch exists, you may encounter the following error in your logs: javax.resource.spi.EISSystemException: Cannot connect to policy server: Failed to init Agent API: -1

 

Best Practices

  • Changes to the ra.xml file typically require a restart of the application server or the specific resource adapter service to take effect.
  • Always ensure that the FIPS_Mode value reflects the environment’s actual FIPS compliance status.

Additional Information

To speak with a customer representative or a Support Engineer see Contact Support. Scroll to the bottom of the page and click on your respective region.