To generate FIPS compliant pkcs12 file using Openssl
Originally Published: 2009-12-07
Last Modified: 2023-09-25
Article Number
Issue
In FIPS mode, when importing pkcs12 file created using openssl (with default options), R_PKCS12_DECODE returns error 10009 : NOT_AVAILABLE.
Cause
Resolution
openssl pkcs12 -export -in <your server cert>.pem -inkey <your server key>.pem -out mycert.p12 -descert
The -descert option will instruct openssl to encrypt pkcs12 certificates with triple DES.
Related Articles
Error "No appropriate protocol" in RSA Access Manager 6.2 45Number of Views FIPS status of RSA Cloud Access Service components 355Number of Views AFX Connectors remain in a Deployed state and 'java.lang.SecurityException: Algorithm not allowable in FIPS140 mode: MD5' … 432Number of Views Are RSA SecurID hardware and software tokens FIPS 140-2 compliant? 676Number of Views How to disable weak or non-FIPS compliant Ciphers in Authentication Manager v.8.8 or Identity Router v. 12.24.0.x.x 59Number of Views
Trending Articles
Artifacts to gather in RSA Identity Governance & Lifecycle How to Update the Root (Server) and Client Certificates in RSA Identity Governance & Lifecycle How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Troubleshooting AFX Connector issues in RSA Identity Governance & Lifecycle How to Download and Reinstall the AFX Server Archive in RSA Governance & Lifecycle
Don't see what you're looking for?