Ad Widget

Collapse

Zabbix Agent 2 on server with FIPS enabled, unable to connect

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • benevs
    Junior Member
    • Mar 2023
    • 1

    #1

    Zabbix Agent 2 on server with FIPS enabled, unable to connect

    We have Zabbix agent 2 on a RHEL 8.8 server with FIPS 140-2 enabled. We are using PSK encryption with 256bit keys

    The agent is unable to connect with our proxy server

    Error message:
    "failed to process an incoming connection from XXX.XXX.XX.XXX: unspecified certificate verification error: 140653826393856:error:0607B0C8:digital envelope routines:EVP_CipherInit_ex:disabled for FIPS:crypto/evp/evp_enc.c:227:+"


    We've reviewed the documentation here: https://www.zabbix.com/documentation...ual/encryption

    Our preferred cipher to use is TLS_AES_256_GCM_SHA384, can this be used for PSK?




  • BigSmooth
    Member
    • Jun 2023
    • 46

    #2
    Hi,
    Did you manage to bypass this issue without disabling FIPS?
    Regards,
    Olivier

    Comment

    • BigSmooth
      Member
      • Jun 2023
      • 46

      #3
      Update:
      On Oracle Linux 9, which is using OpenSSL 3.0.7, FIPS enabled, no issue.

      Comment

      • BigSmooth
        Member
        • Jun 2023
        • 46

        #4
        I enabled FIPS on both sides (agent was mandatory, but server was not enabled) and it worked.

        Comment

        Working...