NetIQ Access Manager Gateway configuration change pending for 10 to 15min

  • 7023662
  • 23-Jan-2019
  • 23-Jan-2019

Environment

  • NetIQ Access Manager 4.4.3
  • NetIQ Access Gateway Service
  • NetIQ Access Gateway Appliance

Situation

  • NetIQ Access Manager Gateway configuration change pending for 10 to 15min

  • Catalina.out of the Embedded Service Provider reports:
208411-<amLogEntry> 2018-12-27T18:09:33Z DEBUG NIDS Application:
208470-Method: JNDILogEventListener.accept
208506-Thread: JNDIReplicaRestart-255443e8-d6d2-4bc7-901e-a01a415d14f2
208570:Replica ldap://10.0.28.2 restart failed! Will try again after 60000 milliseconds! </amLogEntry>
208668-
208669-<amLogEntry> 2018-12-27T18:09:33Z DEBUG NIDS Application:
208728-Method: JNDILogEventListener.accept
--
208947-<amLogEntry> 2018-12-27T18:09:33Z DEBUG NIDS Application:
209006-Method: JNDILogEventListener.accept
209042-Thread: JNDIReplicaRestart-b4575c64-a3de-4372-b9f5-bff73e41298f
209106:Replica ldap://10.0.28.2restart failed! Will try again after 60000 milliseconds! </amLogEntry>
209204-
209205-<amLogEntry> 2018-12-27T18:09:34Z DEBUG NIDS Application:
209264-Method: JNDILogEventListener.accept
--
212437-<amLogEntry> 2018-12-27T18:09:34Z DEBUG NIDS Application:
212496-Method: JNDILogEventListener.accept
212532-Thread: JNDIReplicaRestart-d0a23ab6-a21d-4a3b-a506-00a8885a2b16
212596:Replica ldap://10.0.28.2restart failed! Will try again after 60000 milliseconds! </amLogEntry>

Resolution

  • This issue has been addressed to engineering
  • As a workaround make sure the Access Gateway has access to configured LDAP data sources

Cause

  • The Access Gateway Embedded Service Provider (ESP) is trying to connect to LDAP datasource(s) configured for virtual attribute access. This process causes a delay on any configuration change or restart of the embedded service provider

Additional Information

Troubleshooting
  • run a LAN trace on the Access Gateway to:
    • review any communication with the Access Manager Console for possible failured
    • any kind of connection attempt failure (in this case it turned out that the ESP tried accessing LDAP servers)

  •  Enable File Logging:
       Echo To Console,
       Component File logger Levels:
          Application, Liberty: debug