IBM Support

Error during User Synchronization from Manage to Cognos

Troubleshooting


Problem

Cognos is bundled with Manage and Cognos is configured according to the following links. The Users present in Manage are not synchronized and there is an error in the Manage server bundle Pod log when executing the crontask "CognosUserSyncCronTask"

Configuring Cognos Analytics server:

https://www.ibm.com/docs/en/maximo-manage/continuous-delivery?topic=server-configuring-cognos-analytics   Configuring Maximo Manage user synchronization to Cloud Pak for Data:

https://www.ibm.com/docs/en/maximo-manage/continuous-delivery?topic=ccas-configuring-maximo-manage-user-synchronization-cloud-pak-data

Symptom

The user is not synchronized and the following error occurred in the Manage server bundle Pod log when executing the crontask "CognosUserSyncCronTask".

[ERROR] CWPKI0823E: SSL HANDSHAKE FAILURE: A signer with SubjectDN [CN=*.apps.cluster-02.tdslmas-maint.com] was sent from the host [cpd-ibm-cpd.apps.cluster-02.tdslmas-maint.com:443]. The signer might need to be added to the local truststore [/truststore/trust.p12], located in SSL configuration alias [ssl]. The extended error message from the SSL handshake exception is: [PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find a valid certification path to the requested target].   

[ERROR] CWPKI0828E: The trustDefaultCerts attribute is enabled but trust was not established by using the default truststore. The extended error message from the SSL handshake exception is: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find a valid certification path to the requested target.

Cause

This procedure regarding importing the Certificate is not documented. However, adding the RedHat OpenShift web console certificate to "Imported Certificates" on the activation screen of Manage will result in the successful User synchronization from Manage to Cognos.  

Environment

MAS 8.10.2

Manage 8.6.2  

CP4D 4.6.3  

Cognos Analytics with Watson 11.2.4  

Static Catalogv8-230616-amd64

Diagnosing The Problem

STEPS TO REPRODUCE:

  1. Configure MXCOGNOS End Point properties in Manage.
  2. Add the Users to be linked to the security group "COGNOSUSERS" in Manage.  
  3. Run the crontask "CognosUserSyncCronTask" for Cognos user synchronization.  
  4. This results in the users not being synchronized and an error.

Resolving The Problem

This certificate error does not always happen. If it does happen, the complete certificate chain from CP4D needs to be added to "Imported Certificates" on the activation screen of Manage.

Once this is done, the user will be successfully synchronized.

Where to View and Import the Certificates:

image-20230907091055-1

image-20230907091121-2

Document Location

Worldwide

[{"Type":"MASTER","Line of Business":{"code":"LOB59","label":"Sustainability Software"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSRHPA","label":"IBM Maximo Application Suite"},"ARM Category":[{"code":"a8m50000000CbQxAAK","label":"Reporting-\u003ECognos Integration"}],"ARM Case Number":"TS013784403","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"All Versions"}]

Document Information

Modified date:
11 September 2023

UID

ibm17030899