CA Service Management

 View Only
Expand all | Collapse all

Unable to Authorize - Not sure if it is EEM or Catalog

  • 1.  Unable to Authorize - Not sure if it is EEM or Catalog

    Broadcom Employee
    Posted Oct 31, 2019 10:07 AM
    Hi Everyone 

    I have a scenario where Approval is getting stuck with a Level 1 user but the ssoserviceaccount can override this and approve 

    We see this error which points towards EEM and authentication but this was checked on the customer side on verified that there are no issues with account or password: 

    [Authenticate
    Error: Authentication Failed, Artifact Attempted: Operator.T_SLCM_SessionID__]
    com.ca.eiam.SafeException:
    EE_AUTHFAILED Authentication Failed
    at
    com.ca.eiam.SafeContext.authenticateWithArtifact(SafeContext.java:2204)

    I found the following errors I think could be related to why it is failing but I am unsure what is causing this behaviour and need some assistance please: 

    2019/10/22 14.07.38.045 ERROR [localhost-startStop-2] [EventUtil] Error occured while disconnecting from JMS Event messaging framework:Transport disposed.
    2019/10/22 14.07.38.045 ERROR [pool-4-thread-1] [ActiveMQMessageConsumer] ID:W8VCASC01-53672-1571403819477-3:2:3:1 failed to delivered acknowledgements
    javax.jms.JMSException: Transport disposed.

    Regards, 
    Kaveek




  • 2.  RE: Unable to Authorize - Not sure if it is EEM or Catalog

    Broadcom Employee
    Posted Nov 03, 2019 07:22 PM
    1) Products and versions?

    2) Take PAM out of the picture and test with SOAP UI. You might get clearer messages, or rule PAM in/out as a source of the issue.

    Kyle_R.



  • 3.  RE: Unable to Authorize - Not sure if it is EEM or Catalog

    Broadcom Employee
    Posted Nov 04, 2019 05:03 AM

    Hi Kyle 

    Catalog 14.1 + EEM is 12.51.0.4 + CA Process Automation 4.2 SP02

    We are supporting him with 14.1 because they are in the process of upgrading to 17.2 

    Will advise the customer and let you know the outcome. 

    Regards, 

    Kaveek




  • 4.  RE: Unable to Authorize - Not sure if it is EEM or Catalog
    Best Answer

    Broadcom Employee
    Posted Nov 07, 2019 09:16 AM
    Is it the situation that it worked in the past and all of sudden it run into this problem ?  If that is the case ,  you need to give a try with the following :   on catalog node  , 1) stop catalog service  2)  delete all the files under USM_HOME\logs\jms-data\    ( you can take a backup of that folder first )   3)  restart catalog service  .       If there are multiple catalog nodes , you need to do above for all nodes  .

    Thanks, Jing 



  • 5.  RE: Unable to Authorize - Not sure if it is EEM or Catalog

    Broadcom Employee
    Posted Nov 12, 2019 05:19 AM
      |   view attached

    Hi Jing 

    This was done but did not resolve the issue, unfortunately. 

    Logs and screenshot of process attached. 

    Please let me know your thoughts on what else could be wrong here


    Regards,

    Kaveek




  • 6.  RE: Unable to Authorize - Not sure if it is EEM or Catalog

    Posted Nov 12, 2019 04:08 PM
    @Kaveek Jimmy,

    Since PAM is waiting for the synchronous call to complete, I would assume the issue is in Catalog.

    You said ssoserviceaccount is able to override and approve. Does it means that your "approval assigned user" does not have the option to approve in Catalog GUI?

    If yes, I would suggest that you take a look at the Capitalization of your userid/group name that you pass ​to the web service call.

    With the latest set of patch we found that if a group is defined as FinanceApproval in EEM and that we spell it financeapproval in PAM, users do not have the option to approve the request but admin account can override it :)


    Hope this helps,



  • 7.  RE: Unable to Authorize - Not sure if it is EEM or Catalog

    Broadcom Employee
    Posted Nov 12, 2019 10:49 PM
    Kaveek ,

    Do you have their CA_SLCM_<machine name>.HIS file on their catalog server ? how many catalog nodes on that env ? 

    For catalog 14.1 ,  the catalog needs at least on 14.1 CP5 + CP5 rollup1 +  CP5 rollup2 patch level .  

    From the screenshot ,  i realized that catalog was actually able to fire  the PAM process  to run  in PAM , but PAM process stuck/hangs  at assignPendingApproval web service call to catalog .  Is that correct ?    

    I'm wondering if this problem occurs persistently on that env or just occurs intermittently .

    Thanks, Jing 



  • 8.  RE: Unable to Authorize - Not sure if it is EEM or Catalog

    Posted Nov 12, 2019 10:59 PM
    Jing, as per the screenshot, Pam doesn't hang. The purple web service call operator are for synchronous call. It means it'll wait for catalog to complete the pending action before it continues.


  • 9.  RE: Unable to Authorize - Not sure if it is EEM or Catalog

    Broadcom Employee
    Posted Nov 14, 2019 09:22 AM

    Hi Jing 

    Please find .HIS file attached. There is only one instance of Catalog 

    It is a persistent error.  Users who approve are not a part of any special group, they just have be a Catalog user

    Hope this helps bring further clarity. 


    Regards,

    Kaveek 




  • 10.  RE: Unable to Authorize - Not sure if it is EEM or Catalog

    Broadcom Employee
    Posted Nov 14, 2019 09:23 AM
      |   view attached
    .HIS file

    Attachment(s)

    txt
    CA_SLCM_W8VCASC01.txt   374 B 1 version


  • 11.  RE: Unable to Authorize - Not sure if it is EEM or Catalog

    Broadcom Employee
    Posted Nov 12, 2019 11:17 PM
    Hi Kaveek,

    please provide me the case# and CA_SLCM_<machine name>.HIS file on their env .   I seemed to  see this problem somewhere in the past  .

    Thanks, Jing 



  • 12.  RE: Unable to Authorize - Not sure if it is EEM or Catalog

    Posted Nov 13, 2019 09:14 AM
    @Jing Yang, SSQ opened a case about this and I provided the solution a couple of comments above.​