IBM Support

Agent not able to connect to LMT server (CODAG011E)

Troubleshooting


Problem

Attempts to connect agents to LMT server fails with CODAG011E. Security set to 1 on both the server and the agents. GSK_ERROR_SOCKET_CLOSED appearing in the log files.

Symptom

Attempting to connect to [http://<server_ip>:9988/msghandler/service] via a web browser should return:

"This method of communication with the server is unsupported."

whereas connecting to :

[https://<server_ip>:9999/msghandler/service]

returns an error.

[9988 and 9999 are the default ports used for agent-to-server communication, if you modified these settings, please use the 'Server Port' and 'Secure Port without client authentication' from tlmagent.ini accordingly]

----------------------------------------------------------------------------------------------------------------------------------

The following messages visible in the agent log files (<IBM\tivoli>\common\COD\logs\agent\trace\)

7.2.*.* (traceX.log)

<LogText><![CDATA[Error during gsk_sec_soc_init function - rc=GSK_ERROR_SOCKET_CLOSED]]></LogText>

<LogText><![CDATA[Get input stream failure, http message=Http: Connect error]]></LogText>

<LogText><![CDATA[ctrlCommService - Service 1-Ping connection error (1)]]></LogText>

7.2.2 (error.log)

Error during gsk_sec_soc_init function - rc=GSK_ERROR_SOCKET_CLOSED

----------------------------------------------------------------------------------------------------------------------------------


The following can be found in <WAS>/profiles/AppSrv01/logs/server1/SystemOut.log:

WSX509KeyMana E CWPKI0024E: The certificate alias "lmt server" specified by the property com.ibm.ssl.keyStoreServerAlias is not found in KeyStore "<IBM>/LMT/admin/keystore/key.p12".

Cause

The aliases defined in:
[ISC > Security> SSL certificate and key management > SSL configurations > ILMTsecure]

and
[ISC > Security> SSL certificate and key management > Key stores and certificates > ILMTkeystore > Personal certificates]

differ.

The default aliases defined in [ISC > Security> SSL certificate and key management > SSL configurations > ILMTsecure] not saved to the master configuration.

Resolving The Problem

Navigate to [ISC > Security>SSL certificate and key management > SSL configurations > ILMTsecure],
click on 'Get certificate aliases' and make sure that
'Default server certificate alias' and
'Default client certificate alias' are equal to the alias specified in [ISC > Security> SSL certificate and key management > Key stores and certificates > ILMTkeystore > Personal certificates]

Please remember to 'Save directly to the master configuration. '

After this operation [https://<server_ip>:9999/msghandler/service] should return "This method of communication with the server is unsupported."

In some cases repeating the 'Get certificate aliases' action, and clicking on 'OK' then saving it to the master configuration is required (for example after replacing the default lmt_server alias).

[{"Product":{"code":"SS8JFY","label":"IBM License Metric Tool"},"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Component":"--","Platform":[{"code":"PF002","label":"AIX"},{"code":"PF027","label":"Solaris"},{"code":"PF033","label":"Windows"},{"code":"PF012","label":"IBM i"},{"code":"PF016","label":"Linux"},{"code":"PF010","label":"HP-UX"}],"Version":"Version Independent","Edition":"","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
26 April 2021

UID

swg21497936