FIM Unsupported encryption algorithm error when importing partner metadata
Originally Published: 2008-09-25
Article Number
Applies To
Issue
2008-09-24 14:17:24,983, (SSOHelper.java:608), servera, , , , SSO top-level profile exception: , com.rsa.fim.profile.sso.SSOProfileException: Error encrypting the nameid: Unable to encrypt due to an error: Unsupported encryption algorithm
at com.rsa.fim.profile.util.ProfileHelper.encryptOrSignResponse(ProfileHelper.java:1165)
at com.rsa.fim.profile.sso.SSOProfileBean.processAuthnRequest(SSOProfileBean.java:1104)
This error indicates that FIM cannot determine the encryption algorithm of the certificates embedded in the metadata.
In this instance the following algorithm is listed in the metadata
<md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes-cbc"/>
The correct format for the algorithm should be:
<md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes128-cbc"/>
Resolution
Related Articles
Password incorrect error when importing a PKCS#12 generated by RSA Certificate Manager on Microsoft Internet Explorer 108Number of Views How to recover from incorrectly uploading a DER encoded public SSL certificate to the SecurID Access Administration Console 30Number of Views RSA SecurID Appliance 3.0 Service Pack 4 Migration Failure at Task 'Importing Certificates' 14Number of Views AFX Connectors remain in a Deployed state and 'java.lang.SecurityException: Algorithm not allowable in FIPS140 mode: MD5' … 425Number of Views FIPS status of RSA Cloud Access Service components 346Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory How to Download OTP Token Seed Files from myRSA Microsoft Entra ID External MFA - Relying Party Configuration Using OIDC - RSA Ready Implementation Guide RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide
Don't see what you're looking for?