This section contains the following topics:
java.lang.ClassNotFoundException: com.netegrity.siteminder.sap.webas.jaas.SiteMinderLoginModule.
no JDecrypt in java.library.path
Invalid Entries in the Configuration File
Return code from doManagement Error
Policy server IP address or ports are invalid
SiteMinderSessionID header not found or empty - Aborting...
CA SSO Session Spec Header Not Found or Empty
Resource not protected by CA SSO
CA SSO login module authentication failed. Redirecting to the error page...
Overall login stack authentication failed. Sending error message...
FEDPROFILE Cookie not found - Aborting…
FEDPROFILE cookie set to LOGGEDOFF
Invalid entries for Fed Connector in Config file
Reason:
The CA SSO Agent for SAP could not start.
Action:
Check one or more of the following settings:
Note: The following FIPS/AES encryption modes are not compatible:
Run the configuration wizard again to correct these settings.
Reason:
This message appears in the Web AS default trace file if the Java Agent API file is not present in the system path.
Action:
Check the configuration of your CA SSO Login Module.
Reason:
This message appears in the Web AS default trace file when the smwebas.home property is not set.
Action:
Use the Web AS Configuration Tool to ensure the smwebas.home property is set correctly.
Reason:
The Web AS default trace file contains this message for any of the following reasons:
Action:
Check the deployment of the SiteMinderLoginModule.sca library.
Reason:
The Web AS default trace file contains this message when the JDecrypt.dll is not present in the system path.
Action:
Copy the JDecrypt library
From
<agent_install_drectory>\sapwebas\bin
To:
<sap_home>\<SID>\<instance>\j2ee\os_libs
Reason:
This message appears in the CA SSO Agent for SAP log file if the Java Agent API file is not present in the system path.
Action:
Copy the Java Agent API (smjavaagentapi) library
From
<agent_install_directory>\sapwebas\bin
To:
<sap_home>\<SID>\<instance>\j2ee\os_libs
Reason:
Agent configuration details are missing or are incorrect.
Action:
Run the Agent Configuration Wizard again and correct the errors.
Reason:
This message can occur for any of the following reasons:
Closing accepted connection for session connection idle too long before handshake
Action:
Do the following tasks:
HKEY_LOCAL_MACHINE/Software/Netegrity/SiteMinder/CurrentVersion/PolicyServer/
Reason:
The following items in the Agent configuration differ from those stored on the Policy Server:
Action:
Run the Agent Configuration Wizard again. Ensure that you specify the Policy Server IP address and ports correctly.
Reason:
The following reasons can cause this error:
Action:
Check the WASUSERNAME response in the following realms:
The user attribute passed must match in both realms.
Reason:
One of the following HTTP headers was not available to the CA SSO Login module:
Action:
Check the following items:
Reason:
One of the following HTTP headers was not available to the CA SSO Login module:
Action:
Check the following items:
Reason:
The resource listed in the Agent configuration is not protected in the Policy Server.
Action:
Verify that you have completed all the steps for configuring CA SSO policies.
Reason:
Validation of the Tier 2 CA SSO session can fail when any of the following events occur:
Action:
Check the following items:
Reason:
The user was denied access by the CA SSO login module, and was redirected to the error page.
The user is redirected to the absolute URL of the Error page, which is the ErrorURL parameter that is specified during Agent configuration.
If the URL of the Error page is not displayed and the “Page cannot be displayed” message appears in the browser, check the ErrorURL parameter that is specified during Agent configuration.
If the ErrorURL parameter is not specified during configuration, the log file of this product can issue an additional message:
"CA SSO login module authentication failed. No Error URL configured, sending error message..."
Action:
Verify that the values in the Agent configuration file are correct. If you still get this error, contact CA Technical Support.
Reason:
A login using the CA SSO module succeeded, but another login module in the stack failed.
Action:
Check the other login modules in the stack. Especially those using the following flags:
Reason:
The CA SSO Login Module did not receive the FEDPROFILE cookie from CA Federation.
Action:
Verify the following items:
Reason:
The user completed a single logout (SLO) transaction from CA Federation.
Action:
The FEDPROFILE cookie is not valid. Authentication of the user to the SAP Web AS fails.
Reason:
The following settings are not configured correctly:
Action:
Verify the following items:
|
Copyright © 2015 CA Technologies.
All rights reserved.
|
|