AAOP- Adapter Siteminder 1.1.4 ssl handshake is breaking on newly upgraded Solaris 10
Originally Published: 2012-09-20
Last Modified: 2023-10-06
Article Number
Issue
3144/1][Tue Aug 28 2012 09:54:35][CServer.cpp:5111][INFO] Waiting for messages on thread id 1
[3144/10][Tue Aug 28 2012 09:54:36][CServer.cpp:1575][ERROR] Handshake error: Unknown client name 'cfs216pw9htphost' in hello message
[3144/10][Tue Aug 28 2012 09:54:36][CServer.cpp:1651][ERROR] Bad security handshake attempt. Handshake error: 3160
[3144/10][Tue Aug 28 2012 09:54:36][CServer.cpp:1672][ERROR] Handshake error: Bad hostname in hello message
[3144/10][Tue Aug 28 2012 09:54:36][CServer.cpp:1793][ERROR] Failed handshake with 10.64.160.61:64665
[3144/13][Tue Aug 28 2012 09:54:36][CServer.cpp:1575][ERROR] Handshake error: Unknown client name 'cfs216pw9htphost' in hello message
[3144/13][Tue Aug 28 2012 09:54:36][CServer.cpp:1651][ERROR] Bad security handshake attempt. Handshake error: 3160
[3144/13][Tue Aug 28 2012 09:54:36][CServer.cpp:1672][ERROR] Handshake error: Bad hostname in hello message
[3144/13][Tue Aug 28 2012 09:54:36][CServer.cpp:1793][ERROR] Failed handshake with 10.64.160.61:64666
[3144/7][Tue Aug 28 2012 09:54:36][CServer.cpp:1575][ERROR] Handshake error: Unknown client name 'cfs216pw9htphost' in hello message
This shows on the stdout of the smps siteminder adapter.
Thread-6, READ: SSLv3 Alert, length = 32
Padded plaintext after DECRYPTION: len = 32
0000: 8E 27 B1 5C FA 45 96 91 BF 34 2D C4 19 DF F2 E4 .'.\.E...4-.....
0010: CB 19 12 87 75 94 37 D5 F6 88 0F BA 3E C8 06 90 ....u.7.....>...
Thread-6, SEND SSLv3 ALERT: fatal, [Loaded com.sun.net.ssl.internal.ssl.Alerts from /usr/jdk/jre1.6.0_25/lib/jsse.jar]
description = bad_record_mac
Thread-6, called closeSocket()
Thread-6, handling exception: javax.net.ssl.SSLException: Invalid padding
Resolution
The sunpkcs11 was first on the list. this was changed and the handshakign went through.
The issue was with the key Cipher Suite: TLS_RSA_WITH_AES_128_CBC_SHA which both sides agreed on but
there was padding issue.
From :-> security.provider.4=com.sun.crypto.provider.SunJCE
To: -> security.provider.1=com.sun.crypto.provider.SunJCE
Related Articles
RSA Announces the Release of RSA Authentication Agent 2.0.2 for Microsoft AD FS 17Number of Views Cloud Administration Manage FIDO Configuration API 11Number of Views Cloud Administration Read FIDO Configuration API 9Number of Views How to check the TTLS ( LDAPS /ODA )certificate from the packet capture 26Number of Views Availability of Passkey Feature in RSA Authenticator 4.5 for iOS and Android 93Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Unable to login to RSA Authentication Manager Security Console as super admin Manual synchronization introduced in RSA Authentication Manager 8.2 Service Pack 1 patch 6 Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory How to verify NTP server synchronization is not working in RSA Authentication Manager 8.x
Don't see what you're looking for?