SEPM replication error after 14.3 RU8 upgrade with FQDN-only certificate
search cancel

SEPM replication error after 14.3 RU8 upgrade with FQDN-only certificate

book

Article ID: 274734

calendar_today

Updated On:

Products

Endpoint Protection

Issue/Introduction

After upgrading the SEPM to version 14.3 RU8, replication is not working.

Environment

SEPM sites running 14.3 RU8 and replicating with a CA-issued certificate that does not include IP addresses in the SAN (Subject Alternative Name) of the certificate.

  • During replication setup you see these errors:
    • Failed to connect to the specified replication partner server.
    • Verify that the server name and port are correct.
  • The scm-server0.log on the SEPM shows entries similar to these:
    • HREAD 28 WARNING: javax.net.ssl.SSLHandshakeException: No subject alternative names matching IP address xx.xx.xx.xx found
    • javax.net.ssl.SSLHandshakeException: No subject alternative DNS name matching [HOSTNAME] found
  • CA-issued certificates without IP addresses in the SAN.

Cause

A new system check was introduced with SEP 14.3 RU8. Details on this change are documented in:

https://techdocs.broadcom.com/us/en/symantec-security-software/endpoint-security-and-management/endpoint-protection/all/upgrading-to-a-new-release-v14510472-d27e6/ru8-server-login-failed-server-certificate-not-validated.html 

Resolution

This issue is fixed in release 14.3 RU9. Upgrade to resolve this issue.

If you are unable to upgrade, please follow these steps:

  1. Before starting do DB backup on both sites
  2. Go to <SEPM_INSTALL>\tomcat\webapps\ROOT\WEB-INF\lib folder and back up scm-server.jar to desktop
  3. Stop SEPM services
  4. Replace the jars on both site SEPMs after back with the signed scm-server.jar file provided by support (see the "Additional information" section in this KB.)
  5. Start SEPM services
  6. Delete and re-add replication partners
  7. You can see the hostname instead of IP address on SEPM UI as well
  8. Run replication from any SEPM

In case of any issues, revert to the backup of the scm-server.jar done in step #2.

Additional Information

Updated scm-server.jar file is not publicly available.  Please reach out to Broadcom support for this file.