Issue:
Policy Manager Server temporarily loses contact to the Active Directory (AD) Server. This causes the AD user accounts to be at some times unable to log in to Policy Manager Console.
User gets error: com.fsecure.fsa.SessionStartException: Cannot connect to the server: authorization failed because the specified user credentials are invalid.
Resolution:
-
Verify Connection and Address:
- Ensure proper network connectivity exists between the Policy Manager Server and the Active Directory server.
- Double-check the LDAPS address configured in the Policy Manager Server. The address in the error message ("LDAPS://EXAMPLEADDRESS.COM") should match the actual server address.
-
Update Active Directory Address Using H2 Console (if address mismatch):
Important: Back up your registry before making any changes. Refer to the F-Secure Policy Manager documentation for instructions on registry backup: https://www.withsecure.com/userguides/product.html#business/policy-manager/16.00/en/task_F3496EC8C79842E1B5A479E8D195E8A5-16.00-en
Enable H2 Console:
- Close the Policy Manager Console (if open).
- Stop the Policy Manager Server service.
- Open the Registry Editor (regedit).
- Locate the appropriate registry key based on your Policy Manager version:
- For Policy Manager 15:
HKEY_LOCAL_MACHINE\SOFTWARE(Wow6432Node)\Data Fellows\F-Secure\Management Server 5\additional_java_args - For Policy Manager 16:
HKLM\SOFTWARE\WithSecure\Policy Manager\Policy Manager Server\additional_java_args
- Edit the "additional_java_args" value.
- Add the following parameter:
-Dh2ConsoleEnabled=true - Close the Registry Editor and start the F-Secure Policy Manager Server service.
Open H2 Console:
-
Open a web browser (Internet Explorer or Firefox).
-
Navigate to https://<PolicyManagerServerIP>:<AdminPort>.
- Replace
<PolicyManagerServerIP> with the actual IP address of the Policy Manager Server. - Replace
<AdminPort> with the configured administration port (default: 8080). You can use localhost if accessing from the Policy Manager Server itself.
-
Select the domain.
-
Execute the following SQL statement:
SQL
SELECT * FROM ACTIVE_DIRECTORY_SERVERS;
-
Click the edit button (pen icon) for the relevant entry.
-
Update the "LDAPS Address" field with the correct address.
-
Save the changes.
The Policy Manager Server should automatically start using the updated LDAPS address after saving the changes in the H2 Console.
Additional Notes:
- This article provides a general guideline. Refer to the F-Secure Policy Manager documentation for detailed instructions specific to your version.
- If the issue persists after following these steps, contact F-Secure Support for further assistance.