Attempts to enable appliances fail in RSA Security Analytics 10.4 due to time differences
Issue
One or more appliances show a red Enable button on the Administration -> Appliances screen within the Security Analytics UI.Attempting to click on the button to retry the operation will also fail, displaying the following message: enable failed, click to retry.
Issuing the puppet agent -t command after removing and re-purposing the appliance reports an error similar to the example below.
[2015-01-26T13:47:07.070214 #6373] WARN -- : runner.rb:179:in `receiver_thread' message ae14abdabf8d5c398b40e53642aa3b7e from cert=mcollective_client_public@RSA-AS-MD7 created at 1422279537 is 490 seconds old, TTL is 60
Cause
This issue occurs due to a time difference between the appliance and the SA server.
Resolution
In order to resolve the issue, check the timestamp on both of the appliances by running the date command, as shown below.
[root@SA-Server ~]# date
Tue Jan 27 07:38:16 UTC 2015
Tue Jan 27 07:38:16 UTC 2015
Take note of the difference between them. The appliances should be synchronized to the same NTP server, or manually have the same time.
Notes
CAUTION: Be aware that changing the time on the SA server could cause the rest of appliances to fail.Therefore, it is recommended that all servers be synced to NTP during installation and, if a time change is necessary, to update all of the appliances.
Product Details
RSA Product Set: Security AnalyticsRSA Product/Service Type: Security Analytics UI, Core Appliances
RSA Version/Condition: 10.4.0.2
Platform: CentOS
O/S Version: EL6
Approval Reviewer Queue
ASOC Approval Group