Not Able To Use ManageDIPServerConfig Script On SSL For 11G OID-DIP Server:Destination Unreachable, Check Server Host And Port Values
(Doc ID 2503635.1)
Last updated on MARCH 30, 2022
Applies to:
Oracle Internet Directory - Version 11.1.1.9.0 and laterInformation in this document applies to any platform.
Symptoms
Trying to manage DIP server through manageDIPServerConfig script on SSl mode returns error:
<BEA-090905> <Disabling CryptoJ JCE Provider self-integrity check for better startup performance. To enable this check, specify -Dweblogic.security.allowCryptoJDefaultJCEVerification=true>
<BEA-090906> <Changing the default Random Number Generator in RSA CryptoJ from ECDRBG to FIPS186PRNG. To disable this change, specify -Dweblogic.security.allowCryptoJDefaultPRNG=true>
Destination unreachable, check server host and port values.
The issue happens only when the certificate is signed with SHA2 algorithm.
The script works fine on non-ssl port and on wallets with certificates signed with SHA1.
Cause
To view full details, sign in with your My Oracle Support account. |
|
Don't have a My Oracle Support account? Click to get started! |
In this Document
Symptoms |
Cause |
Solution |
References |