Problem/Symptom: Creation of an MDR pair fails with the following error log in the ems.log file.
javax.net.ssl.SSLHandshakeException:Certificates do not conform to algorithm constraints
Potential Cause: This issue occurs when the Managers in the MDR pair use CA signed certificates with ECDSA algorithm.
Remedy:
Perform the following steps when this error occurs in the ems.log file:
Login to the Manager server.
Navigate to
<Manager_Install_Dir>\jre\lib\security.Note
The default Manager installation directory is
%programfiles%\Trellix\IPS Manager\App.Open the
java.securityfile.Remove the ECDSA value from the
jdk.tls.disabledAlgorithmsparameter.Close the
java.securityfile.Restart the Manager server.