Problem/Symptom: Creation of an MDR pair fails with the following error log in the ems.log file.
javax.net.ssl.SSLHandshakeException:Certificates do not conform to algorithm constraints
Potential Cause: This issue occurs when the Managers in the MDR pair use CA signed certificates with ECDSA algorithm.
Remedy:
Perform the following steps when this error occurs in the ems.log file:
- Login to the Manager server.
- Navigate to
<Manager_Install_Dir>\jre\lib\security.
Note
The default Manager installation directory is %programfiles%\Trellix\IPS Manager\App.
- Open the java.security file.
- Remove the ECDSA value from the jdk.tls.disabledAlgorithms parameter.
- Close the java.security file.
- Restart the Manager server.