FortiNAC
NOTE: FortiNAC is now named FortiNAC-F. For post-9.4 articles, see FortiNAC-F. FortiNAC is a zero-trust network access solution that provides users with enhanced visibility into the Internet of Things (IoT) devices on their enterprise networks.
FortiKoala
Staff
Staff
Article Id 193860
Description
Admin UI Displays SSL Error When Trying to Establish Communication With MDM

Scope
Version: Network Sentry 7.x
Solution
Version: Network Sentry 7.x

Issue:  Network Sentry displays the following error after clicking the TEST button in MDM Service Settings:

java.net.ssl.SSLException:java.lang.RuntimeException: Could Not Generate DH Keypair

This error can occur if the SSL certificate installed on the MDM is larger than 1024 bit.  Network Sentry version 7.x uses java version 1.6, which has a limitation where it can only handle up to 1024 bit SSL certificates.   

Workaround:  Downgrade the certificate on the MDM to 1024 bit.

Solution:  Upgrade to Network Sentry version 8.0 when available. 8.0 includes a newer version of java which supports the 2048 bit certificates.

Contributors