Certificates for sensors running version 5.1.1 fail to validate if the SSP is running 5.1
search cancel

Certificates for sensors running version 5.1.1 fail to validate if the SSP is running 5.1

book

Article ID: 423629

calendar_today

Updated On:

Products

VMware vDefend Firewall VMware vDefend Firewall with Advanced Threat Prevention

Issue/Introduction

For an NDR Sensor 5.1.1, which is not registered with Security Services Platform (SSP), registration fails if the NDR Sensor 5.1.1 and beyond tries registration with SSP platform version 5.1.0.

If user tries to register a Sensor 5.1.1 with SSP 5.1.0, then the registration will fail with an error like

% Sensor registration failed with HTTP status: 400, error code: 888057, error message: Registration token decryption failed. Please check if token and/or passphrase is specified correctly.

 

Environment

vDefend SSP = 5.1.0
NDR Sensor >= 5.1.1

Cause

Changes done on NDR Sensor and Security Services Platform (SSP) to libraries - responsible for registration of NDR Sensor with Security Services Platform (SSP) - for complying with Federal Information Processing Standard (FIPS) in version 5.1.1 and beyond. These changes are not present in NDR Sensor and Security Services Platform (SSP) in version 5.1.0.

 

Resolution

User will need to delete the NDR Sensor 5.1.1 VM from vSphere and deploy a fresh NDR Sensor VM of version 5.1.0, which is of the same version as Security Services Platform (SSP), that is, version 5.1.0 and then proceed with registering the newly deployed NDR Sensor.