FIM Unsupported encryption algorithm error when importing partner metadata
Originally Published: 2008-09-25
Article Number
Applies To
Issue
2008-09-24 14:17:24,983, (SSOHelper.java:608), servera, , , , SSO top-level profile exception: , com.rsa.fim.profile.sso.SSOProfileException: Error encrypting the nameid: Unable to encrypt due to an error: Unsupported encryption algorithm
at com.rsa.fim.profile.util.ProfileHelper.encryptOrSignResponse(ProfileHelper.java:1165)
at com.rsa.fim.profile.sso.SSOProfileBean.processAuthnRequest(SSOProfileBean.java:1104)
This error indicates that FIM cannot determine the encryption algorithm of the certificates embedded in the metadata.
In this instance the following algorithm is listed in the metadata
<md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes-cbc"/>
The correct format for the algorithm should be:
<md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes128-cbc"/>
Resolution
Related Articles
Password incorrect error when importing a PKCS#12 generated by RSA Certificate Manager on Microsoft Internet Explorer 108Number of Views RSA Governance & Lifecycle LDAP Novell eDirectory Connector Guide 17Number of Views RSA Governance & Lifecycle Custom Schema Connector Guide 45Number of Views Cloud Administration Enable FIDO Authenticator API 40Number of Views AFX Connectors remain in a Deployed state and 'java.lang.SecurityException: Algorithm not allowable in FIPS140 mode: MD5' … 427Number of Views
Don't see what you're looking for?