Regenerate aek.key - Could not connect to docbase using IDQL
I've regenerated the aek.key, re-encrypted the dbpasswd.txt and started the docbase back up. All looks fine in the docbase log, however none of the users are able to login using IAPI/IDQL. I recieve the following error when trying to login to IDQL using the install owner:
Could not connect
[DM_SESSION_E_CLIENT_AUTHENTICATION_FAILURE]error: "Failed to authenticate client. Please check server log for more detail."
I've followed the steps in KB0720457 (
) which involve:- Stop Docbase, rename aek.key file
- Run SQL commands to clear out crypto key
- Run dm_crypto_create to generate new aek.key (using default password AES_256_CBC algorithm)
- Run dm_encrypt_password to re-encrpt the database password within dbpasswd.txt
Any ideas?
Best Answer
-
The details for this message are:
CLIENT_AUTHENTICATION_FAILURE "Failed to authenticate client. Please check server log for more detail."
; CAUSE: The client installation sent a certificate that uniquely identifies
; the client instance. The Content Server was unable to successfully
; verify this certificate.
; ACTION: Check the reason listed in the error message as to why the certificate
; failed to verify.
;I think that this refers to the dfc.keystore used by your client. If you are using iapi or idql, it's probably $DOCUMENTUM/config/dfc.keystore. Try to delete this file and try again (dfc.keystore will be recreated). If it works, you should probably delete all dfc.keystore files you can find. As long as you don't use any privileged client (e.g. Records Client or D2), you should be fine. Otherwise, you will need to grant each client privileges again.
0
Answers
-
The details for this message are:
CLIENT_AUTHENTICATION_FAILURE "Failed to authenticate client. Please check server log for more detail."
; CAUSE: The client installation sent a certificate that uniquely identifies
; the client instance. The Content Server was unable to successfully
; verify this certificate.
; ACTION: Check the reason listed in the error message as to why the certificate
; failed to verify.
;I think that this refers to the dfc.keystore used by your client. If you are using iapi or idql, it's probably $DOCUMENTUM/config/dfc.keystore. Try to delete this file and try again (dfc.keystore will be recreated). If it works, you should probably delete all dfc.keystore files you can find. As long as you don't use any privileged client (e.g. Records Client or D2), you should be fine. Otherwise, you will need to grant each client privileges again.
0
Categories
- All Categories
- 123 Developer Announcements
- 54 Articles
- 150 General Questions
- 148 Thrust Services
- 57 OpenText Hackathon
- 37 Developer Tools
- 20.6K Analytics
- 4.2K AppWorks
- 9K Extended ECM
- 918 Core Messaging
- 84 Digital Asset Management
- 9.4K Documentum
- 32 eDOCS
- 186 Exstream
- 39.8K TeamSite
- 1.7K Web Experience Management
- 8 XM Fax
- Follow Categories