Connector Server Add failed. Unable to negotiate key exchange for kex algorithms.
search cancel

Connector Server Add failed. Unable to negotiate key exchange for kex algorithms.

book

Article ID: 408487

calendar_today

Updated On:

Products

CA Identity Manager

Issue/Introduction

After upgrade from 14.4 to 14.5 endpoint cannot be acquired any longer.

Endpoint is Red Hat Enterprise Linux Server release 5.7 (Tikanga).

Unix V2 connector is used.

Error message:

IM Provisioning Manager

:ETA_E_0003 <ADI>, Endpoint '#########' creation failed: Connector Server Add failed: code 80
(OTHER-LdapCommunicationException): failed to add entry
eTDYNDirectoryName=endpoint_name,eTNamespaceName=UNIX v2,dc=im,dc=etasa: JCS@########: UNIX: Cannot connect to the Endpoint [JCS@########: UNIX: ] because an unexpected error occurred: [Unable to negotiate key exchange for kex algorithms (client:
curve25519-sha256,[email protected],curve448-sha512 ,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-h ellman-group-exchange-sha256,diffie-hellman-group18-sha512,diffie -hellman-group17-sha512,diffie-hellman-group16-sha512,diffie-hell
man-group15-sha512, diffie-hellman-group14-sha256,ext-info-c /
server:
diffie-hellman-group-exchange-sha1, diffie-hellman-group14-sha1,diff ie-hellman-group1-sha1)]. (Idaps://########:20411)

Environment

IM 14.5

Cause

The error indicates that the client (Java code) and the server (Red Hat Enterprise Linux Server release 5.7 (Tikanga)) did not manage to negotiate a communication protocol. The problem is that the endpoint does not have recent security updates and not able to satisfy current security requirements. See for example Red Hat Enterprise Linux Retired Life Cycle Dates to find that Red Hat Enterprise Linux Server release 5.7 (Tikanga) is an old OS and even extended life-cycle support ended in November 30, 2020.

Resolution

Upgrade endpoint OS to the supported version.