Tuesday, August 13, 2013

addNode timeout error

Context : installing Connections, and federating Cognos Node to Dmgr.


The error is :

ADMU0027E: Une erreur s'est produite au cours de la fédération Read timed out ;
           retour à la configuration d'origine.
ADMU0211I: Les détails de l'erreur peuvent être consultés dans le fichier :
           C:\IBM\WebSphere\AppServer\profiles\AppSrv01\logs\addNode.log
ADMU0026I: Une erreur s'est produite au cours de la fédération ; retour à la
           configuration d'origine.
ADMU0113E: Fin du programme avec l'erreur
           com.ibm.websphere.management.exception.AdminException:
           com.ibm.websphere.management.exception.ConnectorException:
           ADMC0009E: Le système n'a pas pu effectuer d'appel RPC SOAP :
           invoke, résultant de [SOAPException: faultCode=SOAP-ENV:Client;
           msg=Read timed out; targetException=java.net.SocketTimeoutException:
           Read timed out]
ADMU1211I: Pour obtenir une trace complète de l'échec, utilisez l'option
           -trace.
ADMU0211I: Les détails de l'erreur peuvent être consultés dans le fichier :
           C:\IBM\WebSphere\AppServer\profiles\AppSrv01\logs\addNode.log

In addNode.log :
[12/08/13 10:04:38:867 CEST] 00000000 ProviderTrack I com.ibm.ffdc.osgi.ProviderTracker AddingService FFDC1007I: Fournisseur FFDC installé : com.ibm.ffdc.util.provider.FfdcOnDirProvider@42f47f5a
[12/08/13 10:04:38:913 CEST] 00000000 Ffdc          I com.ibm.ffdc.util.provider.FfdcOnDirProvider logIncident FFDC1003I: Incident FFDC émis sur C:\IBM\WebSphere\AppServer\profiles\AppSrv01\logs\ffdc\ffdc.1639904841534703718.txt com.ibm.ws.management.connector.soap.SOAPConnectorClient.invokeTemplate 846
[12/08/13 10:04:38:992 CEST] 00000000 AbstractNodeC E   ADMU0040E: Exception sur appel du MBean WebSphere:name=AdminOperations,process=dmgr,platform=proxy,node=SRVCONNECT1CellManager01,version=8.0.0.5,type=AdminOperations,mbeanIdentifier=AdminOperations,cell=SRVCONNECT1Cell01,spec=1.0 mergeConfigDataOnDmgr com.ibm.websphere.management.exception.ConnectorException: ADMC0009E: Le système n'a pas pu effectuer d'appel RPC SOAP : invoke

[12/08/13 10:04:39:195 CEST] 00000000 AdminTool     A   ADMU0026I: Une erreur s''est produite au cours de la fédération ; retour à la configuration d''origine.
[12/08/13 10:04:48:242 CEST] 00000000 AbstractNodeC E   ADMU0040E: Exception sur appel du MBean WebSphere:name=AdminOperations,process=dmgr,platform=proxy,node=SRVCONNECT1CellManager01,version=8.0.0.5,type=AdminOperations,mbeanIdentifier=AdminOperations,cell=SRVCONNECT1Cell01,spec=1.0 doUnMergeConfigDataOnDmgr javax.management.MBeanException: Exception thrown in RequiredModelMBean while trying to invoke operation doUnMergeConfigDataOnDmgr


Here, it is recommanded to increase timeout.

soap.client.props is here : C:\IBM\WebSphere\AppServer\profiles\AppSrv01\properties

Modified timeout to 600.
#------------------------------------------------------------------------------
# SOAP Request Timeout
#
# - timeout (specified in seconds [default 180], 0 implies no timeout)
#
#------------------------------------------------------------------------------
com.ibm.SOAP.requestTimeout=600

In Dmgr, the node has already been created by the addNode.bat command. In order to-- launch the addNode command again, wa have to remove it.

In Dmgr :


However :
  • Removing node from the Dmgr asks the the node agent to be started
  • Starting nodeagent on cognos server returns a fileNotFoundException. Server.xml is not found!
  • It not possible to removeNode using the command line on Cognos server. Error : the node is not federated to a cell.
So it is not usable but not federated. It already exists in Dmgr, but I'm not able to start the nodeagent.

C:\IBM\WebSphere\AppServer\profiles\AppSrv01\bin>startNode.bat
ADMU0116I: Les informations sur les outils sont journalisées dans le fichier
           C:\IBM\WebSphere\AppServer\profiles\AppSrv01\logs\nodeagent\startServ
er.log
ADMU0128I: Démarrage de l'outil avec le profil AppSrv01
ADMU3100I: Lecture de la configuration du serveur : nodeagent
ADMU0111E: Fin du programme avec l'erreur : java.io.FileNotFoundException:
           C:\IBM\WebSphere\AppServer\profiles\AppSrv01\config\cells\SRVCONNECT2
Node01Cell\nodes\SRVCONNECT2Node01\servers\nodeagent\server.xml
           (Le chemin d?accès spécifié est introuvable.)
ADMU1211I: Pour obtenir une trace complète de l'échec, utilisez l'option
           -trace.
ADMU0211I: Les détails de l'erreur peuvent être consultés dans le fichier :
           C:\IBM\WebSphere\AppServer\profiles\AppSrv01\logs\nodeagent\startServ
er.log
C:\IBM\WebSphere\AppServer\profiles\AppSrv01\bin>syncNode.bat srvconnect1.alteca
.fr 8879
ADMU0116I: Les informations sur les outils sont journalisées dans le fichier
           C:\IBM\WebSphere\AppServer\profiles\AppSrv01\logs\syncNode.log
ADMU0128I: Démarrage de l'outil avec le profil AppSrv01
ADMU2026E: Le noeud SRVCONNECT2Node01 n'est pas intégré à une cellule.
C:\IBM\WebSphere\AppServer\profiles\AppSrv01\bin>removeNode.bat
ADMU0116I: Les informations sur les outils sont journalisées dans le fichier
           C:\IBM\WebSphere\AppServer\profiles\AppSrv01\logs\removeNode.log
ADMU0128I: Démarrage de l'outil avec le profil AppSrv01
ADMU2001I: Début du retrait du noeud : SRVCONNECT2Node01.
ADMU2026E: Le noeud SRVCONNECT2Node01 n'est pas intégré à une cellule.
ADMU0211I: Les détails de l'erreur peuvent être consultés dans le fichier :
           C:\IBM\WebSphere\AppServer\profiles\AppSrv01\logs\removeNode.log

But if you simply force delete the Node in the Dmgr, addnode can run. 

Also uninstall the Cognos application, so you start clean. Without this you won't be able to access Cognos.

Success



Friday, August 9, 2013

-classpath is not recognized as an internal or external command operable program or batch file

During Connections 4.5 installation, at the point of launching cognos-setup.bat, I get this error :


Success to verify the JDBC connection to Cognos Content Store database.
'-classpath' n'est pas reconnu en tant que commande interne
ou externe, un programme exécutable ou un fichier de commandes.
Failed to verify the JDBC connection to Metrics database. Please check the error
 message.
Validation failed, unable to continue setup
Which in English is :
-classpath is not recognized as an internal or external command operable program or batch file
 May this be because of parenthesis in my password ?

-> No I changed every related password on this server and no amelioration.

What annoys me is that it's not even an error message ! That's a bug and that bug was already on version 4. I opened a PMR then but finally abandonned.

Finally solved by modifying the cognos-setup.bat!

  1. JDBC Connection for Cognos Content Manager works but not JDBC Connection for Metrics.
  2. I bypass the verifying of the JDBC Connection for Cognos Content Manager and now JDBC Connection for Metrics works ok!
That means that everything is good in my file but the ".bat" is not constructed correctly ??
I have some difficulty believing that this batch was not tested... So what is the difference between my environment and everyone else's ?

Here is the modification of cognos-setup.bat (basically I just added a bunch of "REM") :


REM Validate the JDBC connection.
SET was=%was.install.path%
SET java="%was%\java\bin\java.exe"
SET JAR_HOME=%cognosSetupScriptPath_%BI-Customization\JDBC\*
PUSHD %cognosSetupScriptPath_%lib
SET cp=.;"%CD%\*";"%JAR_HOME%"
POPD
REM Validate the JDBC connection to Cognos Content Store database
REM SETLOCAL ENABLEDELAYEDEXPANSION
REM    set "java_PATH=!java!"
REM FOR /F "tokens=*" %%j IN ('"!java_PATH! -classpath %cp% com.ibm.connections.metrics.cognos.install.CognosDBJDBCConnectionVerifer %cognos.db.type% %cognos.db.host% %cognos.db.name% %cognos.db.user% %cognos.db.password%"') DO (
REM ENDLOCAL
REM IF "%%j" == "JDBC Connection Success" SET cognosjdbcconnection=true
REM CALL :log %%j
REM )
REM IF NOT "%cognosjdbcconnection%" == "true" (
REM CALL :log Failed to verify the JDBC connection to Cognos Content Store database. Please check the error message.
REM EXIT /b 1
REM )
REM CALL :log Success to verify the JDBC connection to Cognos Content Store database.
REM Validate the JDBC connection to Metrics database
SETLOCAL ENABLEDELAYEDEXPANSION
    set "java_PATH=!java!"
FOR /F "tokens=*" %%j IN ('"!java_PATH! -classpath %cp% com.ibm.connections.metrics.cognos.install.MetricsDBJDBCConnectionVerifer %metrics.db.type% %metrics.db.host% %metrics.db.name% %metrics.db.user% %metrics.db.password%"') DO (
ECHO %%j
ENDLOCAL
IF "%%j" == "JDBC Connection Success" SET metricsjdbcconnection=true
CALL :log %%j
)
IF NOT "%metricsjdbcconnection%" == "true" (
CALL :log Failed to verify the JDBC connection to Metrics database. Please check the error message.
EXIT /b 1
)
CALL :log Success to verify the JDBC connection to Metrics database.
CALL :log ... performing validation check completed
ENDLOCAL
GOTO :EOF

During cognos-configure.bat, same problem of course. This time I took a different approached. I duplicated a paragraph which is used to set parameters. This one :

REM Validate the JDBC connection.
SET was=%was.install.path%
SET java="%was%\java\bin\java.exe"
SET JAR_HOME=%cognosSetupScriptPath_%BI-Customization\JDBC\*
PUSHD %cognosSetupScriptPath_%lib
SET cp=.;"%CD%\*";"%JAR_HOME%"
POPD

Here is the final result for cognos-configure.bat :

REM Validate the JDBC connection.
SET was=%was.install.path%
SET java="%was%\java\bin\java.exe"
SET JAR_HOME=%cognosSetupScriptPath_%BI-Customization\JDBC\*
PUSHD %cognosSetupScriptPath_%lib
SET cp=.;"%CD%\*";"%JAR_HOME%"
POPD
REM Validate the JDBC connection to Cognos Content Store database
SETLOCAL ENABLEDELAYEDEXPANSION
    set "java_PATH=!java!"
FOR /F "tokens=*" %%j IN ('"!java_PATH! -classpath %cp% com.ibm.connections.metrics.cognos.install.CognosDBJDBCConnectionVerifer %cognos.db.type% %cognos.db.host% %cognos.db.name% %cognos.db.user% %cognos.db.password%"') DO (
ENDLOCAL
IF "%%j" == "JDBC Connection Success" SET cognosjdbcconnection=true
CALL :log %%j
)
IF NOT "%cognosjdbcconnection%" == "true" (
CALL :log Failed to verify the JDBC connection to Cognos Content Store database. Please check the error message.
EXIT /b 1
)
CALL :log Success to verify the JDBC connection to Cognos Content Store database.
REM Validate the JDBC connection.
SET was=%was.install.path%
SET java="%was%\java\bin\java.exe"
SET JAR_HOME=%cognosSetupScriptPath_%BI-Customization\JDBC\*
PUSHD %cognosSetupScriptPath_%lib
SET cp=.;"%CD%\*";"%JAR_HOME%"
POPD
REM Validate the JDBC connection to Metrics database
SETLOCAL ENABLEDELAYEDEXPANSION
    set "java_PATH=!java!"
FOR /F "tokens=*" %%j IN ('"!java_PATH! -classpath %cp% com.ibm.connections.metrics.cognos.install.MetricsDBJDBCConnectionVerifer %metrics.db.type% %metrics.db.host% %metrics.db.name% %metrics.db.user% %metrics.db.password%"') DO (
ENDLOCAL
IF "%%j" == "JDBC Connection Success" SET metricsjdbcconnection=true
CALL :log %%j
)
IF NOT "%metricsjdbcconnection%" == "true" (
CALL :log Failed to verify the JDBC connection to Metrics database. Please check the error message.
EXIT /b 1
)
CALL :log Success to verify the JDBC connection to Metrics database.
CALL :log ... performing validation check completed
ENDLOCAL
GOTO :EOF

This worked also, but I don't like having to modify the batch. I could have opened a PMR but that would take me 3 weeks again and a lot of work


Wednesday, August 7, 2013

SSO not complete

SSO is only working one way! I login to Connections, then go to webmail, SSO takes care of authentication. But the opposite, when I first login to webmail, it does not log me in to Connections automatically.


Several steps I didn't take, according to Zero To Hero Integration Guide

  1. Editing Wimconfig in order to exernalName instead of uniqueName for userUniqueIdMapping
  2. importing SSL certificate from Websphere

WIM


By the way, what is WIM ? (from What's new in version 6.1? ) :
WebSphere Application Server V6.1 also includes WebSphere Identity Manager (WIM) (also included in WebSphere Portal, which provides basic identity, profile, and user information that can be used by JAAS). Figure 8 illustrates the WIM framework.
So it in linked to authentication.



The wimconfig.xml procedure is explained (because I have to always know why I do what I do!) : here at Kenio blog 

Here is the paragraph I'm referring to :

Please note - if you make subsequent changes to the Global Security Federated Repository area using the ISC - Step 3 may need to be redone as changes may be lost.

What this does -

Step 1.) Insures that the username in the LTPA token created from Domino map to an existing repository in WAS - If there is no match, you get the "user not in defined realm" error in the logs.

Step 2.) Insures that Domino Flat groups can be found for policies

Step 3.) Insures that the username in the LTPA token that WAS generates is resolvable by the Sametime Community Server. In general, Domino does not validate the usernames contained within the LTPA token, it grants the user "default" level access to the database based on the validity of the token.

That seems important! However from that source : http://www-01.ibm.com/support/docview.wss?uid=swg1PM33575 it seems that it is included in 8.0.0.5 having externalName or uniqueName is both fine.

Path of wimconfig.xml : C:\IBM\WebSphere\AppServer\profiles\Dmgr01\config\cells\connectionsCell01\wim\config

However


Wiki : Troubleshooting


In Connections Wiki documentation, they also provide with an action to take on wimconfig file for troubleshooting SSO in the context of using flat group in Domino LDAP.

I applied, and that didn't make any change.


SSO D'bugging


From this Interesting document about SSO in the ICS world (sametime in that case)

D'buggin – It's more an art than science -
● Process of elimination – where is the problem originating?
─ Confirm that basic authentication (username/password) works first
─ Confirm with basic browser based tests before attacking Sametime itself
─ From a browser
– access http://<domino>/names.nsf then go directly to http://<was>/stmeetings
– access http://<was>/stmeetings (login) then go directly to http://<domino>/names.nsf
─ Do both tests – what does this tell you?
– First test – Domino created the LTPA token, Second test WAS created it
– If both tests pass – then continue on to Sametime issues
– If both tests fail – 99% of the time, the LTPA keys are not in synch
– If test(s) fail in one direction only – keys are in synch, but something else is off
– Most common reason for failing from Domino to WAS is “user not in defined realm”

And this point also to "ExternalName" and "UniqueName" modification.

Also (Step 3 = Modifying wimconfig.xml) :
Please note: If you make subsequent changes to the Global Security Federated Repository area using the Integrated Solutions Console (ISC), then Step 3 might need to be redone as changes may be lost.
This is really unfortunate, to have to redo wimconfig modification each time federated repository are changed.

However, I have already ExternalName, so this must be ok.


Getting information


Another source is this paper. What is good about this one, is that, even though this is Websphere portal and not application server, it goes in the direction of getting more information. Debugging by checking parameters is ok at the beginning. But when you checked all the basics, and if you are going in-depth for the first time, my opinion is that you have to know how to get information. I cannot go blind for long.

In fact, this paper is part of a serie on SSO which can be useful if you are interested to have more knowledge on ibm LTPAToken SSO.



Which LTPA

Specifically in my environment, I have :
- several domino in the same domain, SSO ok.
- Connections, SSO works only one way
- Sametime System Console with Proxy Server, SSO ok with domino, and one way with Connections
So basically, Connections side is not OK.
However, is it possible that by adding SSO for Sametime System Console, I erased the LTPA Token for Connections ? How is it possible to check which LTPA Token is in place in domino ?

I reimported the LTPA key from Connections to Domino (restart task HTTP) and Sametime, and now SSO works.

Note: when testing Connections SSO, do not use https://connections.server.com/homepage/login
The "login" at the end puts you at the login page even though SSO will log you if you access https://connections.server.com/homepage

Friday, August 2, 2013

LDAP Bind account and disappearing groups in Sametime

On a production environment, the LDAP Bind account is in LocalDomainAdmins group. That's historical but poses a threat to security. However, when removed, LDAP groups appeared as empty for users in Sametime!

Solving


Testing access to LDAP you have :
- ldapsearch which is delivered with lotus notes
- Ldap Browser from Softerra which i use a lot, and it's free

Clic there to access the free tool

With LDAP testing I found that some groups had the problem and other not. This is LDAP related.


Finally

Some groups had reader field and I had not made aware of them. I guess you never know what's in a production environment until you break your head on it!
I just added the LDAP Bind account to reader access, restarted LDAP task and it rolled.

Thursday, July 18, 2013

Embedded experience to the clients (policies)

This is the following of embedded experience quest.
Fisrt part of this quest is here.

Sources


  1. Domino Policies FAQ
  2. IBM Domino 9.0 Social Edition OpenSocial Component Deployment Cookbook
  3. Troubleshooting policies
  4. Make your business Open and Social using IBM Notes Social Edition 9.0 

CLPEE5021E

CLPEE5021E: The Gadget Server URL is not configured.
CLPEE6026E: The Gadget Server URL is not configured or not valid and the gadget cannot be used.

I put the URL of my shindig server into the desktop policy and that worked. Apparently there no other than to use a policy. In a test phase I would imagine putting the setting directly into the notes client but this seems not to be possible.


CLPEE2012E


The errors disappeared but not I have :

CLPEE2012E: An error occurred obtaining a security token to access the server.
java.io.IOException: Server returned HTTP response code: 401 for URL: XXXXXXX/fiesta/container/stgen?u=XXXXXXX/fiesta&m=0&c=default&d=remote&i=XXXXXXXX at sun.reflect.NativeConstructorAccessorImpl.newInstance0(Native Method) at sun.reflect.NativeConstructorAccessorImpl.newInstance(Unknown Source) at sun.reflect.DelegatingConstructorAccessorImpl.newInstance(Unknown Source) at java.lang.reflect.Constructor.newInstance(Unknown Source) at sun.net.www.protocol.http.HttpURLConnection$6.run(Unknown Source) at java.security.AccessController.doPrivileged(Unknown Source) at sun.net.www.protocol.http.HttpURLConnection.getChainedException(Unknown Source) at sun.net.www.protocol.http.HttpURLConnection.getInputStream(Unknown Source) at com.ibm.rcp.net.http.internal.protocol.HttpURLConnection.getInputStream(Unknown Source) at java.net.URL.openStream(Unknown Source) at com.ibm.fiesta.notes.security.ContainerSecurityTokenProvider$2.run(Unknown Source) at org.eclipse.core.internal.jobs.Worker.run(Unknown Source) Caused by: java.io.IOException: Server returned HTTP response code: 401 for URL: XXXXX/fiesta/container/stgen?u=XXXXXX at sun.net.www.protocol.http.HttpURLConnection.getInputStream(Unknown Source) at java.net.HttpURLConnection.getResponseCode(Unknown Source) at com.ibm.rcp.net.http.internal.protocol.HttpURLConnection.reAuthenticate(Unknown Source) ... 4 more
CLPEE5015W: The error JSON does not contain the property code.
CLPEE6017W: Error preloading the gadget at

This error can be found in the troubleshooting guide. SSO is not configured.
Here again I tried to configure locally for testing purpose by configuring the "account" directly into my Notes client. By entering it into the policy (see Source 4. page 47), rebooting my client a few times, the error disappeared.


No error but still not working


This time I have no error left in the client's trace. However the embedded experience widget is still not working right. In order to have more information, I use Wireshark

In wireshark I have :

He cannot find the way to my locked domain it seems. Opened a request to open DNS for

  • unlocked.server.domain.com
  • *-locked.server.domain.com

To server.domain.com's IP

More next time!

Tuesday, July 16, 2013

Node Synchronization problem


2 Websphere 8.0.0.5 servers :
1 Dmgr + appserver
1 appserver that I federated to the Dmgr
This last one won't synchronize

I have 2 errors in the nodeagent log : ADMS0005E and ADMS0036E

[15/07/13 15:51:49:235 CEST] 0000001e NodeSyncTask  A   ADMS0036E: La synchronisation de la configuration n'a pas abouti.
[15/07/13 15:51:51:595 CEST] 0000001f NodeSync      E   ADMS0005E: Le système ne peut pas générer de demande de synchronisation : javax.management.JMRuntimeException: ADMN0022E: L'accès est refusé pour l'opération getRepositoryEpoch sur le MBean ConfigRepository en raison de justificatifs insuffisants ou vides.
at com.ibm.ws.management.connector.soap.SOAPConnectorClient.handleAdminFault(SOAPConnectorClient.java:948)
at com.ibm.ws.management.connector.soap.SOAPConnectorClient.invokeTemplateOnce(SOAPConnectorClient.java:916)
at com.ibm.ws.management.connector.soap.SOAPConnectorClient.invokeTemplate(SOAPConnectorClient.java:682)
at com.ibm.ws.management.connector.soap.SOAPConnectorClient.invokeTemplate(SOAPConnectorClient.java:672)
at com.ibm.ws.management.connector.soap.SOAPConnectorClient.invoke(SOAPConnectorClient.java:658)
at com.ibm.ws.management.connector.soap.SOAPConnectorClient.invoke(SOAPConnectorClient.java:480)
at $Proxy2.invoke(Unknown Source)
at com.ibm.ws.management.AdminClientImpl.invoke(AdminClientImpl.java:224)
at com.ibm.ws.management.sync.NodeSync.getCellRepositoryEpoch(NodeSync.java:410)
at com.ibm.ws.management.sync.NodeSyncTask.doSync(NodeSyncTask.java:248)
at com.ibm.ws.management.sync.NodeSyncTask.run(NodeSyncTask.java:157)
at java.lang.Thread.run(Thread.java:772)

And in the Dmgr log I have : SECJ0305I

[15/07/13 16:13:16:384 CEST] 000002bc RoleBasedAuth A   SECJ0305I: Echec du contrôle d'autorisation basée sur le rôle pour admin-authz opérations StatusCache : placeReport:com.ibm.ws.management.status.StatusReport.  L'utilisateur UNAUTHENTICATED (ID unique : unauthenticated) n'a pas reçu un des rôles requis suivants : operator, administrator.

But I am not unauthenticated, I am wasadmin.

FFDC in Dmgr's SystemOut.log :
[15/07/13 17:53:50:217 CEST] 0000002f FfdcProvider W com.ibm.ws.ffdc.impl.FfdcProvider logIncident FFDC1003I: Incident FFDC émis sur C:\IBM\WebSphere\AppServer\profiles\Dmgr01\logs\ffdc\dmgr_67421e5f_13.07.15_17.53.50.2011205009599192654889.txt com.ibm.ws.security.token.WSCredentialTokenMapper.createPropagationTokenBeforeAuthenticatedCallerSet 1691
 FFDC is "first failure data capure" and you can find more information about it here

I found a lot of information on a similar problem in Websphere 6 but this is 8. And it was related to automatic key generation. It is unchecked in my configuration.

I found this :
http://www-01.ibm.com/support/docview.wss?uid=swg21458372


I have HMGR0149E
Validation of LTPA token failed due to invalid keys or token

It seems that my LTPA (Lightweight Third Party Authentication is an authentication technology) is not valid, but how do I check the validity ?

I disabled administrative security, stopped everything on both servers, rebooted the marchines
Enabled "Synchronize Changes with Nodes"




Enabled Administrative security back again and rebooted everything.

Now my nodes are synchronized and no errors in the logs.

Wednesday, July 10, 2013

Installing Filenet fixes for IBM Connections 4.5

Here is how I did. YMMV

Filenet installation directory is :
C:\IBM\Connections\addons\ccm\ContentEngine

Backup these files :
C:\IBM\Connections\addons\ccm\ContentEngine\tools\configure\profiles\CCM\ear\Engine-ws.ear
C:\IBM\Connections\addons\ccm\ContentEngine\lib\BootstrapConfig.jar


Uninstall FileNetEngine application in websphere



Turn every websphere process off and delete this directory :

C:\IBM\WebSphere\AppServer\profiles\AppSrv01\temp\DEMOCONNECTIONSNode01\IBMConnections_server1\FilenetEngine

From the fixpack, copy the 2 files Engine-ws.ear and BootstrapConfig.jar into :

C:\IBM\Connections\addons\ccm\ContentEngine\lib\

It is said in the read me not to overwrite the Engine-ws.ear. I don't really know what this means as there already is a Engine-ws.ear, so I backed it up as well.
I start everything again.
Launch the configuration manager. Open profile :


C:\IBM\Connections\addons\ccm\ContentEngine\tools\configure\profiles\CCM\CCM.cfgp

Then, edit Configure Bootstrap :


Save and run "Upgrade" task :

Same with Deploy Application, edit and run :



I got "The following task has one or more blank passwords: Deploy Application" :

I do not have any "blank password", or course. Maybe it is considered "not valid", but my password is pretty secure.

But the deploy application got stuck. Processes are not working at all. I stopped after 15 mn. And restarted websphere.


Restart servers -> The Filenet Engine Application is not deployed in websphere so not OK.

In :
C:\IBM\Connections\addons\ccm\ContentEngine\tools\configure\configuration
There is a log file which has 4 "access refused" FileNotFoundException error.

I went back to the Deploy Application task, and this time saved before running (which wasn't explicit in the readme but ok i guess) and I got an error back. The default_host was not accepted.



Application server virtual host: com.ibm.ecm.configmgr.engine.ConfigurationManagerException: The connection to the web application server cannot be established. Ensure that the specified administrator user name and password are correct.


And indeed, in the application server properties :

I don't have a password for wasadmin :
Connection to the server seems ok after entering the password :
I run the "Deploy Application" task again and restart all websphere layers.

How to verify that the update is ok : 

  • Verify the Content Platform Engine build number in the Startup Message key is the same as the Content Platform Engine build number from the version.txt file, which is located in the temporary directory where you extracted the contents of this interim fix.


I checked on :

and version.txt :

Everything is good!