Intermittent Handshake Failure RHCS with Thales Luna HSM

Solution In Progress - Updated -

Issue

Intermittent issue where the cli goes into a failed state:

SEVERE: FATAL: SSL alert received: HANDSHAKE_FAILURE
IOException: SocketException cannot write on socket: Failed to write to socket: (-12227) SSL peer was unable to negotiate an acceptable set of security parameters.

And the Web UI issue is similar:

Secure Connection Failed

An error occurred during a connection to rhcs.example.com:8443. SSL peer was unable to negotiate an acceptable set of security parameters.

Error code: SSL_ERROR_HANDSHAKE_FAILURE_ALERT

Environment

  • Rhel 8
  • Redhat Certificate System 10.6
  • Thales Luna HSM
  • FIPS enabled
  • RSA CA install

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.

Current Customers and Partners

Log in for full access

Log In

New to Red Hat?

Learn more about Red Hat subscriptions

Using a Red Hat product through a public cloud?

How to access this content