IBM Support

Policy Server fails to start with LDAP SSL configured

Troubleshooting


Problem

The Policy Server is configured to use SSL to an external LDAP server and Policy server fails to start with an "SSL Initialization call failed" error.

Symptom

The error appears in the msg__pdmgrd_utf8.log file as

2014-11-20-12:12:10.720+00:00I----- 0x16B480C9 pdmgrd ERROR rgy ira ira_handle.c 859 0x7f0eb29f5720 HPDRG0201E Error code 0x71 was received from the LDAP server. Error text: "SSL initialization call failed".
2014-11-20-12:12:10.720+00:00I----- 0x1354A0B6 pdmgrd ERROR ivc general azn_maint.cpp 2773 0x7f0eb29f5720 HPDCO0182E LDAP initialization failed: ira_rgy_init("ldapsvrname", 636,"cn=ivmgrd/master,cn=SecurityDaemons,secAuthority=Default", ***)= 113,408.

Cause

One cause of this error is if there is a ssl-keyfile-pwd specified in the ivmgrd.conf file.

Resolving The Problem

Open the LMI.  Edit the ivmgrd.conf file and remove the following line if found:
ssl-keyfile-pwd = **obfuscated**

[{"Product":{"code":"SSPREK","label":"Tivoli Access Manager for e-business"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Component":"General Information","Platform":[{"code":"PF004","label":"Appliance"}],"Version":"8.0;8.0.0.2;8.0.0.4;8.0.0.5;8.0.1;8.0.1.2;8.0.1.3;8.0.1.4;8.0.1.5;8.0.1.6;9.0;9.0.0.1;9.0.1;9.0.2;9.0.2.1;9.0.3","Edition":"","Line of Business":{"code":"LOB24","label":"Security Software"}}]

Document Information

Modified date:
31 December 2021

UID

swg21694364