SUPPORT / SAMPLES & SAS NOTES
 

Support

Problem Note 48142: The SAS® Metadata Server might not respond when you use SSL with direct LDAP authentication

DetailsHotfixAboutRate It

When you configure for direct Lightweight Directory Access Protocol (LDAP) authentication over the Secure Sockets Layer (SSL), the SAS® Metadata Server might stop responding to all requests. The server's lack of response might be sporadic, producing various errors. The only way to recover from this condition is to restart the SAS Metadata Server.

Client applications that connect to the SAS Metadata Server might produce a message regarding a failed connection, a failed authentication, or a connection time–out. Client applications might not provide any message and appear to be unresponsive.

To indicate the problem, the SAS Metadata Server log might contain a message like the following, after which there is no activity logged:

OpenSSL error 185057381 occurred in function SSL_connect at line 1725, the error message is SSL error 
"error:0B07C065:x509 certificate routines:X509_STORE_add_cert:cert already in hash table(0xb07c065)."

The problem occurs because of an error in handling multi–threaded connections to the LDAP server using SSL encryption. Note that Microsoft Active Directory is an LDAP provider, and you can experience the same problem using Active Directory.

The only circumvention is to configure the SAS Metadata Server to connect to LDAP without SSL.

Related Documentation

  • See Direct LDAP Authentication in the SAS(R) 9.3 Intelligence Platform: Security Administration Guide for additional information about configuring the SAS Metadata Server to directly authenticate to an LDAP server.
  • See How to Configure SSL between the Metadata Server and an LDAP Server in the SAS(R) 9.3 Intelligence Platform: Security Administration Guide for additional information about using SSL encryption with direct LDAP authentication.


  • Operating System and Release Information

    Product FamilyProductSystemProduct ReleaseSAS Release
    ReportedFixed*ReportedFixed*
    SAS SystemSAS Metadata Serverz/OS9.39.49.3 TS1M09.4 TS1M0
    Microsoft® Windows® for x649.39.49.3 TS1M09.4 TS1M0
    Microsoft Windows Server 2003 Datacenter Edition9.39.49.3 TS1M09.4 TS1M0
    Microsoft Windows Server 2003 Enterprise Edition9.39.49.3 TS1M09.4 TS1M0
    Microsoft Windows Server 2003 Standard Edition9.39.49.3 TS1M09.4 TS1M0
    Microsoft Windows Server 2003 for x649.39.49.3 TS1M09.4 TS1M0
    Microsoft Windows Server 20089.39.49.3 TS1M09.4 TS1M0
    Microsoft Windows Server 2008 for x649.39.49.3 TS1M09.4 TS1M0
    Microsoft Windows XP Professional9.39.49.3 TS1M09.4 TS1M0
    Windows 7 Enterprise 32 bit9.39.49.3 TS1M09.4 TS1M0
    Windows 7 Enterprise x649.39.49.3 TS1M09.4 TS1M0
    Windows 7 Home Premium 32 bit9.39.49.3 TS1M09.4 TS1M0
    Windows 7 Home Premium x649.39.49.3 TS1M09.4 TS1M0
    Windows 7 Professional 32 bit9.39.49.3 TS1M09.4 TS1M0
    Windows 7 Professional x649.39.49.3 TS1M09.4 TS1M0
    Windows 7 Ultimate 32 bit9.39.49.3 TS1M09.4 TS1M0
    Windows 7 Ultimate x649.39.49.3 TS1M09.4 TS1M0
    Windows Vista9.39.49.3 TS1M09.4 TS1M0
    Windows Vista for x649.39.49.3 TS1M09.4 TS1M0
    64-bit Enabled AIX9.39.49.3 TS1M09.4 TS1M0
    64-bit Enabled HP-UX9.39.49.3 TS1M09.4 TS1M0
    64-bit Enabled Solaris9.39.49.3 TS1M09.4 TS1M0
    HP-UX IPF9.39.49.3 TS1M09.4 TS1M0
    Linux9.39.49.3 TS1M09.4 TS1M0
    Linux for x649.39.49.3 TS1M09.4 TS1M0
    Solaris for x649.39.49.3 TS1M09.4 TS1M0
    * For software releases that are not yet generally available, the Fixed Release is the software release in which the problem is planned to be fixed.