IBM Guardium

IBM Guardium

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Error After install GIM on Redhat8

    Posted Sun March 10, 2024 03:39 AM

    Hi,

    My database server is RedHat 8 and My IBM guardium server is version 11.488 after installing the GIm agent with this command:

    ./guard-bundle-GIM-10.6.0.0_r105601_v10_6_1-rhel-7-linux-x86_64.gim.sh -- --dir /usr/local/guardium --tapip  <DB Ip> --sqlguardip <Guardium ip> --perl /usr/ 

    Failed sending REGISTER message to 10.112.2.3:8446 (400,140040203045624:error:0407006A:rsa routines :RSA is not 01:rsa_pkl.c:102:
    1400402030456z4:error:04067072:rsa routines:RSA_EAY_PUBLIC_DECRYPT:padding check failed: rsa eay.c:786:
    149940293045624:errorioDoc5oo6:asnl encoding routines :ASNi_item_veriFy:EvB
    140040203045624:error:14090086:SSL routines:ssl3_get_server_certificate:cer Enstallation completed with some errors. Please check central_logger.log

    please Guide me

    Tanks

    Milad



    ------------------------------
    milad baousi
    ------------------------------


  • 2.  RE: Error After install GIM on Redhat8

    Posted Mon March 11, 2024 01:46 AM

    Hi Milad,

    Could you confirm if my high level observations are correct?

    • Database server (you need to install GIM client to) runs RedHat 8
    • Your Guardium system is 11.4
    • Based on command you run to install GIM client, you are attempting to install GIM v10.6 built for RedHat 7

    If my assumptions are accurate, I'd recommend you to download v11.4 GIM installer built for RHEL 8.

    Best regards,



    ------------------------------
    Maksym Tykhenko
    ------------------------------



  • 3.  RE: Error After install GIM on Redhat8

    Posted Mon March 11, 2024 02:06 AM

    Hi Maksym

    No, I made a mistake with the command. This is the command I use:

     ./guard-bundle-GIM-11.4.3.0_r114889_v11_4_1-rhel-8-linux-x86_64.gim.sh -- --dir /opt/guardium --tapip  192.168.73.72 --sqlguardip 192.168.73.73 --perl /usr/bin

    I am using GIm version 11.4 with redhat 8 operating system.

    Please help me if you know the problem

    Tanks

    Milad



    ------------------------------
    milad baousi
    ------------------------------



  • 4.  RE: Error After install GIM on Redhat8

    Posted Mon March 11, 2024 03:24 AM

    Hi Milad,

    It looks like secure SSL communication has failed to establish between GIM client and Guardium appliance. Do you use default or customer certificates for GIM? Are there any extra hints in central_logger.log?

    If you can't spot a root cause, I'd suggest opening case with IBM support where you will securely share your diagnostic information.

    Best regards,



    ------------------------------
    Maksym Tykhenko
    ------------------------------



  • 5.  RE: Error After install GIM on Redhat8

    Posted Mon March 11, 2024 03:56 AM

    Hi Dear

    Yes, I use IBM guardium's default certificate, and no changes have been made to the ssl service on the guardium server. 

    This is also from the central_logger.log :

    And that the support of our organization is over. Is it possible to register a ticket for support without having support time?
    Thank you for your help.

    Milad



    ------------------------------
    milad baousi
    ------------------------------



  • 6.  RE: Error After install GIM on Redhat8

    Posted Tue March 12, 2024 09:42 AM

    Hi Milad,

    Unfortunately, if your support subscription is over, you won't be able to get assistance there.

    It's impossible to do real troubleshooting here. I can provide some guidance only. Based on logs, you are definitely having problems with SSL certificates.

    My suggestion:

    • check commands on Guardium appliance side that can help you get more insights about certificates, their expiration, etc. i.e.: show certificate summary
    • Read this article https://www.ibm.com/support/pages/updating-guardium-data-protection-gim-clients-sha256-certificates, Guardium is switching from SHA128 to SHA256 certificates. Make sure you use right GIM bundles that will work with your Guardium appliance. You maybe in situation, when your appliance is still using SHA128 certificate and you're trying to deploy GIM client that is already packaged with SHA256 certificate.

    I hope that helps with at least direction of investigation.

    Best regards,



    ------------------------------
    Maksym Tykhenko
    ------------------------------



  • 7.  RE: Error After install GIM on Redhat8

    Posted Thu March 14, 2024 05:05 PM

    Hi,

    It is possible that your Guardium system does not support SHA256 Certificates and you are trying to install a version of the GIM agent that works with SHA256, in this case I recommend using a version of the GIM agent that works with SHA128, such as 11.4.0.0

    I think that could solve your problem.



    ------------------------------
    Andres Lopez
    ------------------------------