Segmentation fault running SiteMinder Web Agent 12.52 SP1 CR11 with many virtual hosts
search cancel

Segmentation fault running SiteMinder Web Agent 12.52 SP1 CR11 with many virtual hosts

book

Article ID: 401163

calendar_today

Updated On: 06-16-2025

Products

SITEMINDER

Issue/Introduction

Trying to run many virtual hosts in an Apache Web server results in a Segmentation Fault whenever there is a request to the Web Agent. There is a single instance of the agent on the server and the diferent virtual hosts are configured via different ACO and Web Agents.

The number of virtual servers up from which this has been observed is 859 but other numbers might be possible

Environment

SiteMinder Web  Agent 12.52 SP1 CR11 

Redhat 7.9

Likely the issue is OS-agnostic as will be discussed below

Cause

The crash is occurring within the CAPKI component. The version of CAPKI integrated into the 1252Sp1CR11 web agent release is outdated, specifically identified as ETPKI/5.1.0-00. 

CAPKI internal Uses openssl. the OpenSSL 1.0.2g has an issue in generating random bytes, which was fixed in later release OpenSSL 1.0.2ze, which is as part of CAPKI 5.2.9.

CAPKI 5.1 is built on OpenSSL 1.0.2g, whereas CAPKI 5.2.9 uses OpenSSL 1.0.2ze.

 

Resolution

Sustaing Engineering provided a CAPKI containing the 5.2.9 version to replace the CAPKI which is available when required. This parch will allow up to more than 8000 virtual hosts to be managed

Kindly open a case with Broadcom Support if you are experiencing this issue for them to provide the replacement package