CA Identity Suite Virtual Appliance: cannot start the IM connector when web services are enabled
search cancel

CA Identity Suite Virtual Appliance: cannot start the IM connector when web services are enabled

book

Article ID: 47116

calendar_today

Updated On:

Products

CA Identity Manager CA Identity Governance CA Identity Portal

Issue/Introduction

On Virtual Appliance, when trying to configure web-services in the connector from IP to IM and (re)starting the connector, the connector fails to start with the following error message displayed:

Request Failed

Sorry, something went wrong

Error Testing connectivity and configuration

<html><head><title>Error</title></head><body>Unauthorized</body></html>

Portal ws failed to initialize

Reload connector failed

Reload connector failed

 

Also, the following messages appear in the Identity Portal server log:
ERROR [com.idmlogic.sigma.connector.ca.CaimAdapter] (default task-41) Reload connector failed : ErrorCode: 20056, ErrorFamily: GENERAL, Message: com.idmlogic.sigma.backend.InitConnectorException: Portal ws failed to initialize

Caused by: ErrorCode: 0, ErrorFamily: GENERAL, Message: com.idmlogic.sigma.backend.BackendException: Error Testing connectivity and configuration

BackendMessages:

<html><head><title>Error</title></head><body>Unauthorized</body></html>

 

 



Cause: 
Due to the Wildfly 8.2 Application Server security mechanism, the application server attempts to authorize the request and denies it since the superAdmin credentials provided in the request are not valid as application server credentials.

Cause2:

If have existing IM and IP in cluster mode and need add more one IM to connect to existing Portal may have this issue too with new IM machine.

Environment

CA Identity Suite Virtual Appliance 14.x
CA Identity Suite Virtual Appliance 12.6 SP8 CR1

 

Resolution

1.    Log into the  Virtual Appliance that have the IM deployed with the shell as user 'config'.
2.    Run the command
    sudo /opt/CA/wildfly-idm/bin/add-user.sh
3.    Add the SuperAdmin account (for 12.6.8 cr1) or imadmin account (for 14.0.1 GA) as an Application User with no groups to belong to and no Remoting connection for server to server EJB calls.
 

Additional Information

This scenario is also valid when Identity Manager is installed on Wildfly 8.2.0 outside the Virtual Appliance