Closed as fixed if next.
After upgrading and upon rotating the server signing key, the resigning process attempts to decrypt the EncryptedPassword column in the LDAP_SETTINGS table with the new key, which it can't, and this is what throws the error. The workaround is to delete the EncryptedPassword column, rotate the server signing key, and then fix the LDAP password in the console as a local master operator.
Workaround: 1. UPDATE LDAP_Settings SET EncryptedPassword = NULL 2. Open a command prompt and cd to the BES Server directory (or wherever BESAdmin is). 3. Run BESAdmin.exe /resignSecurityData 4. Log in as local MO. 5. Go to the LDAP Directories tree item. 6. Edit each LDAP Directory with the appropriate password.
This issue will be addressed in the next release of IBM Endpoint Manager. General availability Q1 2014 (release date subject to change).
Reported component name
TIV EP MG PLTFM
Reported component ID
Last modified date
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
Fixed component name
TIV EP MGR SERV
Fixed component ID
Applicable component levels