IBM Support

Firmware 4.0.0 changes the default behavior for DataPower SSL connectivity

Troubleshooting


Problem

With firmware version 4.0.0, the default behavior has changed to reject when the DataPower appliance acts as the SSL client connecting to an insecure server. An insecure server is a server that does not support RFC 5746. You can allow connections to insecure servers with a new option in the SSL Proxy Profile.

Symptom

Starting with DataPower firmware 4.0.0, connections to servers which do not support RFC 5746 are rejected.

The log shows the following error:


SSL handshake aborted due to detection of insecure SSL server

[{"Product":{"code":"SS9H2Y","label":"IBM DataPower Gateway"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Component":"General","Platform":[{"code":"PF009","label":"Firmware"}],"Version":"4.0.2;4.0.1;4.0;5.0.0;6.0.0;6.0.1","Edition":"","Line of Business":{"code":"LOB77","label":"Automation Platform"}}]

Log InLog in to view more of this document

This document has the abstract of a technical article that is available to authorized users once you have logged on. Please use Log in button above to access the full document. After log in, if you do not have the right authorization for this document, there will be instructions on what to do next.

Document Information

Modified date:
08 June 2021

UID

swg21497539