AFX Connectors remain in a Deployed state and 'java.lang.SecurityException: Algorithm not allowable in FIPS140 mode: MD5' error in RSA Identity Governance & Lifecycle
Originally Published: 2020-08-12
Last Modified: 2023-11-30
Article Number
Applies To
RSA Version/Condition: 7.2.0 P02
Issue
The $AFX_HOME/mmc-console/logs/mmc-console-app.log file reports the following error:
java.lang.SecurityException: Algorithm not allowable in FIPS140 mode: MD5
The $AFX_HOME/esb/logs/esb.AFX-MAIN.log file has the following errors:
2020-05-27 02:16:21.880 [WARN] com.aveksa.afx.server.manager.MMCRequestManagerImpl:186 - Connection request retry attempt #1 of 2
2020-05-27 02:16:21.919 [WARN] com.aveksa.afx.server.manager.MMCRequestManagerImpl:182 - Unable get/setup the flow list from the MMC request
2020-05-27 02:16:21.919 [WARN] com.aveksa.afx.server.manager.MMCRequestManagerImpl:183 - Retrying MMC connection and flow list setup...
2020-05-27 02:16:31.919 [WARN] com.aveksa.afx.server.manager.MMCRequestManagerImpl:186 - Connection request retry attempt #2 of 2
2020-05-27 02:16:31.960 [WARN] com.aveksa.afx.server.manager.MMCRequestManagerImpl:188 - Unable get/setup the flow list from the MMC request
2020-05-27 02:16:31.961 [ERROR] com.aveksa.afx.server.manager.MMCRequestManagerImpl:189 - Flow list setup try count exceeded
2020-05-27 02:16:31.961 [ERROR] com.aveksa.afx.server.manager.MMCRequestManagerImpl:190 - Please verify that the MMC console is running and Host & Port in the URL are correct.
2020-05-27 02:16:31.962 [ERROR] com.aveksa.afx.server.manager.MMCRequestManagerImpl:136 - Unable to get status for all Connectors from MMC
com.aveksa.afx.server.manager.MMCException: Unable to retrieve and setup the flow list for server: local$5a2c751f-bf66-4a79-bcc0-4c842aeb2c5b
at com.aveksa.afx.server.manager.MMCRequestManagerImpl.getFlowList(MMCRequestManagerImpl.java:191)
at com.aveksa.afx.server.manager.MMCRequestManagerImpl.getAllConnectorStatus(MMCRequestManagerImpl.java:119)
at com.aveksa.afx.server.component.PrimaryRequestConstructorComponent.constructRequest(PrimaryRequestConstructorComponent.java:59)
at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
...
2020-05-27 02:16:21.919 [WARN] com.aveksa.afx.server.manager.MMCRequestManagerImpl:182 - Unable get/setup the flow list from the MMC request
2020-05-27 02:16:21.919 [WARN] com.aveksa.afx.server.manager.MMCRequestManagerImpl:183 - Retrying MMC connection and flow list setup...
2020-05-27 02:16:31.919 [WARN] com.aveksa.afx.server.manager.MMCRequestManagerImpl:186 - Connection request retry attempt #2 of 2
2020-05-27 02:16:31.960 [WARN] com.aveksa.afx.server.manager.MMCRequestManagerImpl:188 - Unable get/setup the flow list from the MMC request
2020-05-27 02:16:31.961 [ERROR] com.aveksa.afx.server.manager.MMCRequestManagerImpl:189 - Flow list setup try count exceeded
2020-05-27 02:16:31.961 [ERROR] com.aveksa.afx.server.manager.MMCRequestManagerImpl:190 - Please verify that the MMC console is running and Host & Port in the URL are correct.
2020-05-27 02:16:31.962 [ERROR] com.aveksa.afx.server.manager.MMCRequestManagerImpl:136 - Unable to get status for all Connectors from MMC
com.aveksa.afx.server.manager.MMCException: Unable to retrieve and setup the flow list for server: local$5a2c751f-bf66-4a79-bcc0-4c842aeb2c5b
at com.aveksa.afx.server.manager.MMCRequestManagerImpl.getFlowList(MMCRequestManagerImpl.java:191)
at com.aveksa.afx.server.manager.MMCRequestManagerImpl.getAllConnectorStatus(MMCRequestManagerImpl.java:119)
at com.aveksa.afx.server.component.PrimaryRequestConstructorComponent.constructRequest(PrimaryRequestConstructorComponent.java:59)
at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
...
Cause
The cause of this issue is the same as reported in RSA Knowledge Base Article 000038503 -- AFX Server and Remote Collection Agents fail to start after updating Java to version 1.8u241 (1.8.0_241) / 1.7u251 (1.7.0_251) or later in RSA Identity Governance & Lifecycle. Upgrading to RSA Identity Governance & Lifecycle 7.2.0 P02 enables the AFX Server to start but the connectors remain in a Deployed state which, in effect, makes AFX unusable despite the Running state of the AFX Server.
Resolution
Workaround
Related Articles
RSA Authentication Manager 8.4 Patch 14 Web-Tier Readme 6Number of Views FIPS status of RSA Cloud Access Service components 352Number of Views How to get RSA Data Loss Prevention Endpoint logs for all components 76Number of Views Finish button is incorrectly enabled in Role Definition Review in RSA Governance & Lifecycle 51Number of Views Oracle AFX connector message "DH Parameters without subprime Q are not FIPS 140 approved" in RSA Governance & Lifecycle 121Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Manual synchronization introduced in RSA Authentication Manager 8.2 Service Pack 1 patch 6 Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory How to verify NTP server synchronization is not working in RSA Authentication Manager 8.x RSA Governance & Lifecycle 8.0.0 Installation Guide
Don't see what you're looking for?