- RSA Identity Governance & Lifecycle 7.2.1, 7.5.0
- SecurID Governance & Lifecycle 7.5.2
AFX Connectors that use SSH, including but not limited to the Generic SSH Connector and the PowerShell Connector, generate the following error message when using or testing the connector:
java.io.IOException: Session.connect: java.security.InvalidAlgorithmParameterException: Accepted DH prime length is 2048 or higher at net.sf.commons.ssh.jsch.JschConnectionFactory.connectUsingPassword(JschConnectionFactory.java:82)
This is a known issue in AFX Connectors that use SSH connections in the following versions:
- RSA Identity Governance & Lifecycle 7.2.1 P12
- RSA Identity Governance & Lifecycle 7.5.0 P07
- SecurID Governance & Lifecycle 7.5.2
The latest versions and patches of SecurID Governance & Lifecycle include updated versions of BSAFE crypto libraries (6.2.5.x) that enforce a minimum key length of 2048-bit for DH (Diffie-Hellman) Key Exchange keys during SSL connections to remote endpoints. Older versions allowed 1024-bit keys which are known to be insecure.
This issue error occurs when a remote endpoint (remote SSH server) attempts to negotiate an SSL connection using a DH Key Exchange with keys less than 2048-bit in size.
It is not possible to reduce the security of SecurID Governance & Lifecycle to allow insecure SSL connections.
The version of the SSL libraries on the target machines should be updated to later (more secure) versions that support and enforce 2048-bit DH keys.
For example, if you are using the OpenSSL version of SSH it is recommended you upgrade to openSSL 3.1 (or later) which supports 2048 bit DH keys and disallows 1024 bit keys. At minimum you should upgrade to openSSL 1.0.1r which supports 2048 bit DH keys. For other SSL implementations, refer to the respective vendor.
Related Articles
Configure Identity Router Security Levels 145Number of Views Security Levels and Identity Router Connection Ciphers 81Number of Views Microsoft Exchange 2010 AFX Connector Enable-mailbox command fails with 'Value cannot be null' in RSA Identity Governance … 95Number of Views RSA Governance & Lifecycle Exchange SSH Connector Datasheet 53Number of Views How to enable HTTP Strict Transport Security (HSTS) Header on Authentication Manager Prime Self-Service Portal 35Number of Views
Trending Articles
Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA Authentication Manager 8.9 Release Notes (January 2026) RSA Governance & Lifecycle 8.0.0 Administrators Guide RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide