OIDC Connect fails when DLP Enforce Integration is enabled
search cancel

OIDC Connect fails when DLP Enforce Integration is enabled

book

Article ID: 416053

calendar_today

Updated On:

Products

Messaging Gateway

Issue/Introduction

When attempting to use both the DLP Enforce integration and OIDC Connect features in Messaging Gateway (SMG), the OIDC Connect discovery fails with the following error:

BrightmailLog.log
Jan 05 2026 16:35:42 [https-jsse-nio-443-exec-5] [OidcFlow] ERROR - Error occured while fetching IDP metadata. Exception:
javax.net.ssl.SSLHandshakeException: Could not generate secret

This issue may also cause failures in both the DLP Enforce synchronization in SMG and the DLP FlexResponse API integration in DLP.

Environment

Version: 10.9.1, 10.9.2

Cause

Generating the TLS 1.3 secret for TLS negotiation with the OIDC Connect server and possibly the DLP Enforce server is failing.

Resolution

This issue will be addressed in an upcoming Messaging Gateway release.

Please subscribe to this article to be automatically notified of any updates to this issue.

Additional Information