Blog Viewer

Tech Tip : CA Single Sign-On :Policy Server : FSS UI not loading

By Ujwol posted 11-23-2016 12:46 AM



FSS UI stopped loading up recently. It was working before.

No change on the Policy server or OS has been made recently.

Following error message is displayed in IE.


Policy Server : Affected upto 12.52 SP1 CR6 and 12.52 SP2 CR1
Web Server : ANY
Java : 1.7 or 1.8


The FSS UI certificate that is shipped with the above version of Policy server has expired effectively from October 16, 2016.

So, post this date, the Java security wouldn't allow FSS UI to load due to expired certificate.


How to validate the certificate expiry date 

  1. Open Java control panel
  2. Click Security--> Manage Certificates
  3. Double Click the certificate issued to "CA Inc"
  4. Note the Validity date as "October 16 , 2016"

 Alternatively, if you enable the Java tracing from Java control panel,  then you will see the certificate expiry related error as below :


Add the FSS UI site URL as exception in the Java control panel.

  • Open Java control panel.
  • Click Security --> Edit Site List


1. Delete browser history and launch FSSUI

2. Click the check box below to accept the security warning and click Run

3. You will then be shown the FSS UI login page 


CA is working on renewing the expired certificate. If you can't utilise the workaround provided , please open a support case so we can provide you the renewed certificate as a development fix.

1 comment


11-23-2016 01:00 AM