25.3.1 Monitoring the Health of an Identity Server

To view detailed health status information for an Identity Server:

  1. In Administration Console Dashboard, click Devices > Identity Servers > [Name of Server] > Health.

    The status icon is followed by a description that explains the significance of the current state. For more information about the icons, see Section 25.1, Health States.

  2. To ensure that the information is current, select one of the following:

    • Click Refresh to refresh the page with the latest health available from Administration Console.

    • Click Update from Server to send a request to Identity Server to update its status information. This can take a few minutes.

  3. Examine the Services Detail section that displays the status of each service. For an Identity Server, this includes information such as the following:

    Status Category

    If not healthy

    Status: Indicates whether Identity Server is online and operational.

    Verify whether Identity Server has been stopped or is not configured.

    Also verify that network problems are not interfering with communications between Identity Server and Administration Console.

    Services: Indicates the general health of all configured services.

    If one service is unhealthy, this category reflects that status. See the particular service that also displays an unhealthy status.

    Identity Server Configuration: Indicates the status of the configuration.

    Configure Identity Server or assign the server to a configuration.See,Section 3.3, Setting up User Stores for Identity Server Configuration

    Configuration Datastore: Indicates the status of the installed configuration datastore.

    You might need to restart Tomcat or reinstall Administration Console.

    User Datastores: Indicates whether Identity Server can communicate with the user stores, authenticate as the admin user, and find the search context.

    Ensure that the user store is operating and configured correctly. You might need to import the SSL certificate for communication with Identity Server. See Section 5.1.1, Configuring Identity User Stores.

    Signing, Encryption and SSL Connector Keys: Indicates whether these keystores contain valid a key.

    Click Identity Servers > Edit > Security and replace any missing or expired keys.

    System Incoming and Outgoing HTTP Requests: Appears when throughput is slow. This health check monitors incoming HTTP requests, outgoing HTTP requests on the SOAP back channel, and HTTP proxy requests to cluster members. If one or more requests remain in the queue for over 2 minutes, this health check appears.

    Verify that all members of the cluster have sufficient bandwidth to handle requests. If a cluster member is going down, the problem resolves itself as other members of the cluster are informed that the member is down.

    If a cluster member is slow because it does not’ have enough physical resources (speed or memory) to handle the load, upgrade the hardware.

    SSL Communication: Indicates whether SSL communication is operating correctly. This health check appears only when the SSL communication check fails.

    Check SSL connectivity. Check for expired SSL certificates.

    Audit Logging Server: Indicates whether the audit agent is functioning and able to log events to the auditing server.

    Auditing must be enabled on Identity Server to activate this health check (click Devices > Identity Servers > Edit > Auditing and Logging).

    Check the network connection between Identity Server and the auditing server.

    See “Troubleshooting Novell Audit”.

  4. Click Close.