IBM Support

LDAP not available during CRL checking

Question & Answer


Question

Following error returned in WebSEAL message log: DPWIV1210W Function call, gsk_secure_soc_init, failed error: 000001ab GSK_ERROR_LDAP_NOT_AVAILABLE-Could not obtain CRL

Cause

This error is returned in the logs when the Certificate Revocation List server specified in webseal.conf or in the Client Certificate CDP (CRL Distribution Point) cannot be accessed.

Answer

Make sure that the CRL LDAP server is up & running, and that firewall rules allow outbound traffic from the WebSEAL server in case a CDP is defined in the client certificate.

[{"Product":{"code":"SSPREK","label":"Tivoli Access Manager for e-business"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Component":"WebSEAL","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"Version Independent","Edition":"","Line of Business":{"code":"LOB24","label":"Security Software"}},{"Product":{"code":"SSPREK","label":"Tivoli Access Manager for e-business"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Component":"Not Applicable","Platform":[{"code":"","label":""}],"Version":"","Edition":"","Line of Business":{"code":"LOB24","label":"Security Software"}}]

Product Synonym

TAMeB WebSEAL GSKIT

Document Information

Modified date:
16 June 2018

UID

swg21504515