FIM 3.1.2 - CryptoJ jar causing signature verification errors with md2 signature algorithm
Originally Published: 2008-05-22
Article Number
Applies To
IBM WebSphere 6.0.2
Crypto J jar version 3.5.2 - jsafeJCEFIPS.jar in security.providers
Certificate caontains an md2RSA hash
Issue
signature verification error in system log
2008-05-05 20:52:06,042, (SSOHelper.java:608), uhaps004, , , , SSO top-level profile exception: , com.rsa.fim.exception.ProfileException: The response signature cannot be verified: The message is signed, but the signature cannot be verified
Cause
Resolution
Apply one of the following three solutions:
- Move the jsafeJCEFIPS.jar to the bottom of the security providers list or at least below the IBM versions of Jsafe com.ibm.crypto.provider.IBMJCE or com.ibm.crypto.fips.provider.IBMJCEFIPS.
- Replace the certs with signature algorithms other than MD2, such as SHA1
- Obtain hotfix FIM 3.1.2.5 which uses version 4.0 of the jsafeJCEFIPS. jar and add "com.rsa.cryptoj.jce.fips140initialmode=NON_FIPS140_MODE" to the bottom of the java.security file. This will turn off forced FIPS compliance ( added since CRYPTOJ 3.6 version) which would not of allowed md2 certs to be used.
Related Articles
Bootstrapping can fail if Symantec Antivirus is installed on Enterprise or Site Coordinator (Named Pipe Error) 62Number of Views What are RSA Security's plans to support SHA-256 with KCA? 69Number of Views AAOP - Scheduler SP3P1 on Weblogic 10.3 deployment issue->Cannot find the declaration of element 'beans'. 18Number of Views Error: '%1 is not a valid win32 application' when starting RSA RADIUS Server 6.1 12Number of Views How to view a certificate fingerprint as SHA-256, SHA-1 or MD5 using OpenSSL for RSA Authentication Manager 78Number of Views
Trending Articles
RSA Authentication Manager 8.9 Release Notes (January 2026) RSA announces the availability of the RSA SecurID Hardware Appliance 230 based on the Dell PowerEdge R240 Server How to troubleshoot Oracle database ORA-04030 errors in RSA Identity Governance & Lifecycle RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA Authentication Manager Upgrade Process
Don't see what you're looking for?