Recovery ID's not working with CA Process: HELP!

We are struck with a problem on our test domino server. I spent almost four days working on this, looked in lotus fourms andadmin doumentation thoroughly but no help. I’m sure fix is very simple, but i just couldn’t figure out where i was going wrong.

Issue:

I was trying to use CA Process & Recovery Information together, but whenever i choose CA process to create OU’s or user ID’s

their backup copies of ID are not getting mail back to mail-in databases. This is what i’m doing;

  1. After finishing up fresh installation and making sure Adminp is working, i migrate certifier O=SUNYIT.

  2. I process all jobs in Admin req. database and do a ‘load ca’. Certifier O=SUNYIT shows as associated with CA Process.

  3. I now edit recovery information using CA Process for this certifier and do ‘tell ca refresh’ → ‘tell adminp process all’ →

‘tell ca refresh’

  1. I made sure no jobs are pending in Admin Req. database.

  2. Now i create OU or user ID’s using CA Process. After updating ca process and running adminp jobs, backup copies of OU’s do

not showup in mail-in database.

  1. I went ahead and installed Notes client and authenticated user against the server. Left Notes client running on the

workstation.

  1. Even after waiting few minutes, user’s ID does not show up in mail-in database.

Now if i create OU or user ID’s using certifier ID instead of CA Process,

recovery works and i find Backup copies of ID’s mailed back. At this point i cannot conclude that CA Process is broken because

i’m able to create certificates, but for some reason recovery isn’t working.

I didn’t see any error or warning messages on console. Coudn’t find any errors or pending jobs in Adminp database. Made sure

Registration and Administration servers are same as the server i was working.

I would really appreciate if could help me with this, Thanks

-Raghu

Subject: Recovery ID’s not working with CA Process: HELP!

the key is step #7 because the difference between using the CA and not is when the ID gets sent to recovery. Without CA it gets sent at registration time with CA the id gets sent some time after the user sets up their workstation and has interacted with their home server. It is a somewhat indefinite timeframe though. Also make sure that ndyncfg is running correctly on the workstation. To do that look in the log on the workstation and make sure it kicks off at start up.

HTH,

Rob

Subject: RE: Recovery ID’s not working with CA Process: HELP!

Notes client on the worksation has been running since yesterday. I’m not sure how to enable logging on the client ( looked under lotus\notes\data :-> directories, haven’t found a log file ). But i tried to run ndyncfg from cmd line.

I believe OU’s created under O=SUNYIT using CA Process should have left their certifier id’s in mail-in database. Even this i snot happenning. Any Clues ?

Thanks,

Raghu

Subject: RE: Recovery ID’s not working with CA Process: HELP!

Hi Raghu,We have experienced the same problem. You can actually wait FOREVER and it will not download the recovery information into the ID, not will it send the ID to the recovery database.

The only way we have managed to get it working reliably it to make the user change their password. This action on the ID seems to kick off the Dynamic Client Process after approx. 5 Minutes, finalises the ID and sends it to the mailin database.