Certificates for sensors running version 5.1 fail to validate with SSP 5.1.1
search cancel

Certificates for sensors running version 5.1 fail to validate with SSP 5.1.1

book

Article ID: 423631

calendar_today

Updated On:

Products

VMware vDefend Firewall VMware vDefend Firewall with Advanced Threat Prevention

Issue/Introduction

For an NDR Sensor 5.1.0 GA, which is not registered with Security Services Platform (SSP), registration fails if the SSP platform is of version 5.1.1 or beyond.

If user tries to register a Sensor 5.1.0 with SSP including and beyond 5.1.1, then the registration will fail with an error like

% Sensor registration failed with HTTP status: 400, error code: 888057, error message: Registration token decryption failed. Please check if token and/or passphrase is specified correctly.

Environment

vDefend SSP >= 5.1.1
NDR Sensor = 5.1.0

Cause

Changes done on NDR Sensor and Security Services Platform (SSP) to libraries - responsible for registration of NDR Sensor with Security Services Platform (SSP) - for complying with Federal Information Processing Standard (FIPS) in version 5.1.1 and beyond. These changes are not present in NDR Sensor and Security Services Platform (SSP) in version 5.1.0.

Resolution

User will need to perform one of the following actions:

1. Recommended - Delete the NDR Sensor 5.1.0 VM from vSphere and deploy a fresh NDR Sensor VM which is of the same version as Security Services Platform (SSP) and then proceed with registering the newly deployed NDR Sensor.
For E.g.
If Security Services Platform (SSP) is of version 5.1.1, user needs to deploy an NDR Sensor VM of version 5.1.1.


2. Upgrade the NDR Sensor 5.1.0 VM to the the same version as Security Services Platform (SSP) and then proceed with registering the upgraded NDR Sensor.
For E.g.
If Security Services Platform (SSP) is of version 5.1.1, user needs to upgrade the NDR Sensor VM to version 5.1.1.
Steps for upgrading the NDR Sensor are available in the NDR Sensor section of the Security Services Platform (SSP) user guide.