My Oracle Support Banner

OPSS - After Configuring OWSM to Use the KSS Keystore unable use the Deployment Manager on OIM domain (Doc ID 2423554.1)

Last updated on MARCH 01, 2023

Applies to:

Oracle Platform Security for Java - Version 12.2.1.3.0 to 12.2.1.3.0 [Release 12c]
Information in this document applies to any platform.

Symptoms

On : 12.2.1.3.0 version, Java Platform Security

Deployment Manager does not open in the new OIM 12c installation.

Observing the next error on logs

[2018-07-11T14:11:57.738-04:00] [<WL_MANAGED_SERVER>] [ERROR] [] [oracle.iam.token.facade] [tid: [ACTIVE].ExecuteThread: '2' for queue: 'weblogic.kernel.Default (self-tuning)'] [userId: xelsysadm] [ecid: <ECID>] [APP: <APP>] [partition-name: DOMAIN] [tenant-name: GLOBAL] java.io.IOException: oracle.wsm.common.sdk.WSMException: WSM-00237 : KSS keystore with URI kss://opss/trustservice_ks can not be loaded due to java.security.PrivilegedActionException.[[
javax.ws.rs.ProcessingException: java.io.IOException: oracle.wsm.common.sdk.WSMException: WSM-00237 : KSS keystore with URI kss://opss/trustservice_ks can not be loaded due to java.security.PrivilegedActionException.
at org.glassfish.jersey.client.ClientFilteringStages$RequestFilteringStage.apply(ClientFilteringStages.java:121)
..................
Caused by: java.io.IOException: oracle.wsm.common.sdk.WSMException: WSM-00237 : KSS keystore with URI kss://opss/trustservice_ks can not be loaded due to java.security.PrivilegedActionException.
...........
Caused by: oracle.wsm.common.sdk.WSMException: WSM-00237 : KSS keystore with URI kss://opss/trustservice_ks can not be loaded due to java.security.PrivilegedActionException.
...................
Caused by: oracle.wsm.security.SecurityException: WSM-00237 : KSS keystore with URI kss://opss/trustservice_ks can not be loaded due to java.security.PrivilegedActionException.
...................
Caused by: java.security.PrivilegedActionException: oracle.wsm.security.SecurityException: WSM-00237 : KSS keystore with URI kss://opss/trustservice_ks can not be loaded due to oracle.security.jps.service.keystore.KeyStoreServiceException.
...................
Caused by: oracle.wsm.security.SecurityException: WSM-00237 : KSS keystore with URI kss://opss/trustservice_ks can not be loaded due to oracle.security.jps.service.keystore.KeyStoreServiceException.
.................
Caused by: oracle.security.jps.service.keystore.KeyStoreServiceException: Failed to load the keystore.
.................
Caused by: java.io.IOException: Failed to load the keystore.
..............
Caused by: java.security.AccessControlException: access denied ("oracle.security.jps.service.keystore.KeyStoreAccessPermission" "stripeName=opss,keystoreName=trustservice_ks,alias=*" "read")
at java.security.AccessControlContext.checkPermission(AccessControlContext.java:472)
at java.security.AccessController.checkPermission(AccessController.java:884)
at oracle.security.jps.util.JpsAuth$AuthorizationMechanism$3.checkPermission(JpsAuth.java:527)
at oracle.security.jps.util.JpsAuth.checkPermission(JpsAuth.java:587)
at oracle.security.jps.util.JpsAuth.checkPermission(JpsAuth.java:626)
at oracle.security.jps.internal.keystore.util.KeyStoreServiceUtil.checkPermission(KeyStoreServiceUtil.java:1376)
at oracle.security.jps.internal.keystore.provider.FarmKeyStoreSpi.engineLoad(FarmKeyStoreSpi.java:626)

 

Cause

To view full details, sign in with your My Oracle Support account.

Don't have a My Oracle Support account? Click to get started!


In this Document
Symptoms
Cause
Solution


My Oracle Support provides customers with access to over a million knowledge articles and a vibrant support community of peers and Oracle experts.