IGA v14.5 Deployment Failure on Oracle Cloud Infrastructure (OCI) with "Invalid credentials" (Error 49)
search cancel

IGA v14.5 Deployment Failure on Oracle Cloud Infrastructure (OCI) with "Invalid credentials" (Error 49)

book

Article ID: 407386

calendar_today

Updated On:

Products

CA Identity Suite

Issue/Introduction

When attempting to deploy Identity Governance and Administration (IGA) v14.5 services to servers in an Oracle Cloud Infrastructure (OCI) environment, the im_jcs service fails to initialize with error code 49, "Invalid credentials." This occurs because the ldapmodify command is unable to change the admin user's password, even when attempting to use a fallback password. The primary cause of this issue is that OCI is not a supported platform for IGA v14.5, as per the product's compatibility matrix. The customer intends to migrate all services to OCI, leading to a high-impact situation due to the unsupported platform.

Error Messages/Symptoms:

  • [ERROR] 49 Failed running services O/S configuration scripts on [IP Address]: (error code: 49):
  • [ERROR] The "ldapmodify" command returned error 49
  • [ERROR] Initialization script for im_jcs exited with error status 49
  • [ERROR] The service im_jcs failed to initialize (error code 49). Please inspect the log file: /opt/CA/VirtualAppliance/logs/ca_vapp_main.log
  • ldap_bind: Invalid credentials (49)
  • additional info: code 49 (INVALID_CREDENTIALS): Bind failed: uid=admin,ou=system: org.apache.directory.shared.ldap.exception.LdapAuthenticationException: null

Environment

  • Identity Governance and Administration (IGA) v14.5.1
  • Operating System: CentOS Stream 8 and CentOS Stream 9
  • Deployment Platform: Oracle Cloud Infrastructure (OCI)

Cause

Oracle Cloud Infrastructure (OCI) is not a certified or officially supported platform for IGA v14.5. The ldapmodify command's failure to change the admin password during service initialization is a symptom of deploying the IGA Virtual Appliance on an unsupported infrastructure.

Resolution

  1. Deploy on a Certified Platform: The recommended resolution is to deploy IGA v14.5 services on a platform officially certified for proper functionality, stability, and support.

  2. Consider IGA v15 (Best Effort Support for OCI):
    • IGA v15 is expected to be generally available soon and will no longer include the vApp. This version is the recommended path for potential OCI compatibility.
    • Important Note: OCI is also not officially certified for IGA v15. However, support for IGA v15 deployments on OCI will be provided on a best-effort basis. Customers should be aware that full support and guaranteed functionality cannot be assured on an uncertified platform.

  3. Migration Planning: Customers planning to migrate to OCI should be advised to thoroughly review the certified platforms for IGA v14.5, and consider the best-effort support model for IGA v15 on OCI when planning their migration strategy.

Additional Information

  • The product's compatibility matrix clearly lists supported virtualization and cloud platforms.
  • AWS support for the IGA vApp was deprecated as of June 30, 2025.For IGA v15, certified cloud platforms include Google Cloud Platform (GCP), Amazon Web Services (AWS), and Microsoft Azure. Oracle Cloud Infrastructure (OCI) was not listed as officially supported until the date of publishing this document in August/2025.