Fidelis Network Common Criteria Configuration Guide Version 9.0.3
20
www.fidelissecurity.com
SFR
Error
Recovery
Steps
Sample Log
FCS_TLSS_
EXT.1
Failure to
establish a TLS
Session due to
ciphers mismatch.
Verify that the
TLS endpoint
and the TLS
peer configured
with Common
Criteria
validated
common
ciphers.
Aug 7 12:01:01 localhost FSS
audit[27394]: Sensor <linux90s-sensor>
TLS ERROR: Local: ::ffff:10.89.184.31,
Remote: ::ffff:10.89.184.32,
error:1408A0C1:SSL
routines:SSL3_GET_CLIENT_HELLO:n
o shared cipher
FCS_TLSS_
EXT.2
Failure to
establish a TLS
Session due to
invalid certificate
purpose.
Verify that the
peer is
configured with
certificate that
has extended
key usage bits
TLS Server
and/or TLS
Client set, as
appropriate.
Aug 11 13:34:33 localhost FSS
audit[42996]: TLS ERROR: Local:
::ffff:10.89.184.31, Remote: ::ffff:10
.89.184.32, Certificate verification error
26 : unsupported certificate purpose,
Aug 11 13:34:33 localhost Depth = 0,
Aug 11 13:34:33 localhost Issuer =
/C=US/ST=MD/L=Bethesda/O=Fidelis
Cybersecurity/OU=Research and De
velpoment/CN=Vadim-Fidelis-
RootCA1/emailAddress=VF-
[email protected],
Aug 11 13:34:33 localhost Subject =
/C=US/ST=MD/L=Bethesda/O=Fidelis
Cybersecurity/OU=Research and D
evelpoment/CN=VF-RCA1-
Server1/emailAddress=VF-RCA1-
[email protected]
Aug 11 13:34:33 localhost TLS ERROR:
Local: ::ffff:10.89.184.31, Remote:
::ffff:10.89.184.32, error:
140890B2:SSL
routines:SSL3_GET_CLIENT_CERTIFI
CATE:no certificate returned
Remote Authentication
LDAP is the only allowable remote authentication method, and neither RADIUS nor TACACS can be
used.