DWA login using smart card (CAC) results in "CRCRW5016l Login has failed" error

Technote (troubleshooting)


Problem(Abstract)

Attempts to log in using IBM Rational DOORS Web Access (DWA) client results in the error "CRCRW5016l Login has failed: FAILED_UNEXPECTED_EXCEPTION".

Symptom

You login to DWA after you configure DOORS for Common Access Card (CAC) authentication


Cause

The failure is due to invalid XML being sent from the browser during the login process.

Diagnosing the problem

The CAC implementation has a significant difference to the base SSL setup, so it is possible that one setup can work while the other is experiencing problems.

  • The base SSL configuration ensures that DWA provides a Certificate to identify itself.
  • The CAC configuration requires that the browser provide a certificate that DWA then checks against its trust-store to determine validity

Troubleshooting Procedure:

  1. Enable advanced DWA server logging and start the Interop server with logging.

    The logs may show an error related to the failure due to the server receiving invalid XML from the browser during the login process where XML control characters (0x13) in the data is not valid content that can be parsed.

  2. Verify your certificates.

    You should have generated certificates for use with your CAC implementation, verifying the ones on the cards against those in the trust-store on the server. These would normally be generated using the java key tool, which gives you a range of options for keystore type (such as JKS) and for signature algorithms (such as RSA). The tool should allow you to list which certificates are present in your trust-store, along with your certificate fingerprints. Depending on how exactly you are storing the certificates on your cards, you should have a similar means to view or list the certificates on the cards that you are having problems using to login.

Resolving the problem

Your configuration must be setup to submit valid certificates using your browser with DWA.

  1. Fix any errors or mismatches found in the error at any point during the certificate generation or deployment when the server is attempting to process the incoming certificate information that the CAC setup is providing.

  2. Resolve any certificate information mismatches that have been identified to ensure a valid certificate is being submitted for validation on the server.

Related information

Configuring smart cards and certificates

Cross reference information
Segment Product Component Platform Version Edition
Rational DOORS

Rate this page:

(0 users)Average rating

Document information


More support for:

Rational DOORS
General Information

Software version:

1.5, 1.5.0.1, 9.5, 9.5.0.1

Operating system(s):

Windows

Reference #:

1637127

Modified date:

2013-05-13

Translate my page

Machine Translation

Content navigation