My Oracle Support Banner

Not Able To Use ManageDIPServerConfig Script On SSL For 11G OID-DIP Server:Destination Unreachable, Check Server Host And Port Values (Doc ID 2503635.1)

Last updated on AUGUST 13, 2020

Applies to:

Oracle Internet Directory - Version 11.1.1.9.0 and later
Information in this document applies to any platform.

Symptoms

Trying to manage DIP server through manageDIPServerConfig script on SSl mode returns error:

<BEA-090905> <Disabling CryptoJ JCE Provider self-integrity check for better startup performance. To enable this check, specify -Dweblogic.security.allowCryptoJDefaultJCEVerification=true>
<BEA-090906> <Changing the default Random Number Generator in RSA CryptoJ from ECDRBG to FIPS186PRNG. To disable this change, specify -Dweblogic.security.allowCryptoJDefaultPRNG=true>
 Destination unreachable, check server host and port values.

 

The issue happens only when the certificate is signed with SHA2 algorithm.

The script works fine on non-ssl port and on wallets with certificates signed with SHA1.

Cause

To view full details, sign in with your My Oracle Support account.

Don't have a My Oracle Support account? Click to get started!


In this Document
Symptoms
Cause
Solution
References


My Oracle Support provides customers with access to over a million knowledge articles and a vibrant support community of peers and Oracle experts.