The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

MDR pair creation fails when using CA signed certificates with ECDSA algorithm

Prev Next

Problem/Symptom: Creation of an MDR pair fails with the following error log in the ems.log file.

javax.net.ssl.SSLHandshakeException:Certificates do not conform to algorithm constraints

Potential Cause: This issue occurs when the Managers in the MDR pair use CA signed certificates with ECDSA algorithm.

Remedy:

Perform the following steps when this error occurs in the ems.log file:

  1. Login to the Manager server.

  2. Navigate to <Manager_Install_Dir>\jre\lib\security.

    Note

    The default Manager installation directory is %programfiles%\Trellix\IPS Manager\App.

  3. Open the java.security file.

  4. Remove the ECDSA value from the jdk.tls.disabledAlgorithms parameter.

  5. Close the java.security file.

  6. Restart the Manager server.