<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Certificate does not conform to algorithm constraints in ArcGIS Enterprise Questions</title>
    <link>https://community.esri.com/t5/arcgis-enterprise-questions/certificate-does-not-conform-to-algorithm/m-p/352858#M13610</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Michael,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes that is correct, only supports TLS 1.2 at this stage.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is no such Esri documentation as yet that I'm aware of.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My statement regarding TLS 1.3 was in relation to JRE / Java security roadmap / roll outs / bug fixes that I discovered in the &lt;A href="https://bugs.java.com/bugdatabase/view_bug.do?bug_id=8202625"&gt;Oracle Java Bug Database&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Dean&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 09 Jan 2020 13:52:14 GMT</pubDate>
    <dc:creator>DeanMoiler</dc:creator>
    <dc:date>2020-01-09T13:52:14Z</dc:date>
    <item>
      <title>Certificate does not conform to algorithm constraints</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/certificate-does-not-conform-to-algorithm/m-p/352855#M13607</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello fellow mappers!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm having an issue with Portal/Server (10.5.1) federation validation when using certificates signed with the &lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;RSASSA-PSS&lt;/STRONG&gt;&lt;/SPAN&gt;&amp;nbsp;(&lt;STRONG&gt;SHA1withRSAandMGF1&lt;/STRONG&gt;) signature algorithm.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The certificates along with root and intermediate certificates installed fine, so no problems there.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The system operates within a Windows Domain&amp;nbsp;so i'm assuming that it's an MS CA doing the signing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The error i'm receiving when validating is the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;P&gt;Error: javax.net.ssl.SSLHanshakeException: java.security.cert.CertificateException: Certificate does not conform to algorithm constraints&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I believe this is causing some other issues relating to CPU flooding from the javaw.exe process over time, causing the Portal server to become unresponsive as well as not being able to contact the ArcGIS DataStore due to the issues validating the hosting server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From what I can tell the &lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;RSASSA-PSS&lt;/STRONG&gt;&lt;/SPAN&gt; cipher suite&amp;nbsp;has been &lt;A href="https://bugs.java.com/bugdatabase/view_bug.do?bug_id=8146293"&gt;updated in JDK&lt;/A&gt;&amp;nbsp;as part of &lt;A href="http://openjdk.java.net/jeps/332"&gt;TLS 1.3 rollout&lt;/A&gt;, though I can't seem to find reference in the &lt;A href="https://java.com/en/jre-jdk-cryptoroadmap.html"&gt;JRE crypto roadmap&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So&amp;nbsp;I've got two questions:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Does anyone know when Java/Esri will support the above algorithm constraints?&lt;/LI&gt;&lt;LI&gt;Is it possible for the CA to "simply" sign the CSR with a &lt;A href="http://enterprise.arcgis.com/en/portal/10.5/administer/windows/restrict-portal-for-arcgis-ssl-protocols-and-cipher-suites.htm#ESRI_SECTION1_AF37E915749E412EA1099CDA660A0281"&gt;supported algorithm&lt;/A&gt;&amp;nbsp;to establish normal operations?&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dean&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Mar 2019 18:25:54 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/certificate-does-not-conform-to-algorithm/m-p/352855#M13607</guid>
      <dc:creator>DeanMoiler</dc:creator>
      <dc:date>2019-03-19T18:25:54Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate does not conform to algorithm constraints</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/certificate-does-not-conform-to-algorithm/m-p/352856#M13608</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As an update in case anyone comes across a similar issue, certificates signed with &lt;A href="https://www.pkisolutions.com/pkcs1v2-1rsassa-pss/"&gt;PKCS #1 Version 2.1&lt;/A&gt; will be&amp;nbsp;shown as&amp;nbsp;&lt;STRONG style="color: #ff0000; background-color: #ffffff; border: 0px; font-weight: bold;"&gt;RSASSA-PSS.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A CA was configured with an SHA256 (rather than SHA1)&amp;nbsp;hash algorithm and :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-size: 8.5pt; color: black;"&gt;CNGEncryptionAlgorithm 3DES&lt;BR /&gt; CNGPublicKeyAlgorithm RSA&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Generating the CSR's in AGS and being signed by new CA worked a treat.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Oct 2019 15:14:52 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/certificate-does-not-conform-to-algorithm/m-p/352856#M13608</guid>
      <dc:creator>DeanMoiler</dc:creator>
      <dc:date>2019-10-08T15:14:52Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate does not conform to algorithm constraints</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/certificate-does-not-conform-to-algorithm/m-p/352857#M13609</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You mention a TLS 1.3 rollout in your original post.&amp;nbsp; I thought ESRI software only recognized up to TLS 1.2 at this point in time.&amp;nbsp; Do you have any ESRI documentation that mentions TLS 1.3 that you can provide links to?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Oct 2019 15:28:45 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/certificate-does-not-conform-to-algorithm/m-p/352857#M13609</guid>
      <dc:creator>MichaelVolz</dc:creator>
      <dc:date>2019-10-08T15:28:45Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate does not conform to algorithm constraints</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/certificate-does-not-conform-to-algorithm/m-p/352858#M13610</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Michael,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes that is correct, only supports TLS 1.2 at this stage.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is no such Esri documentation as yet that I'm aware of.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My statement regarding TLS 1.3 was in relation to JRE / Java security roadmap / roll outs / bug fixes that I discovered in the &lt;A href="https://bugs.java.com/bugdatabase/view_bug.do?bug_id=8202625"&gt;Oracle Java Bug Database&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Dean&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Jan 2020 13:52:14 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/certificate-does-not-conform-to-algorithm/m-p/352858#M13610</guid>
      <dc:creator>DeanMoiler</dc:creator>
      <dc:date>2020-01-09T13:52:14Z</dc:date>
    </item>
  </channel>
</rss>

