Herman's answer suggests to switch the GIM server configuration to ignore incorrect certificate from GIM client.
It is good for a while only because it leads to situation that any GIM client can register itself on your GIM server.
I suggest check - why your GIM client is not able to register with valid certificate, two situations can happen:
1 - You have installed GIM with predefined certificates and GIM server is configured with customer owned
2 - You provided in the installation process incorrect certificates
------------------------------
Zbigniew Szmigiero
IBM
Warsaw
------------------------------
Original Message:
Sent: Tue October 08, 2019 11:57 AM
From: Herman Engström
Subject: First install ok, re-install not ok - Not supporting unauthenticated GIM clients
Hi,
Actions prior to issue:
I installed a GIM 10.2 on a Microsoft server 2012 with MSSQL and got a connection back to my appliance and I installed a S-TAP remotely with GIM without any issue. However, the inspection engine did not verify properly due to a misconfiguration during the S-TAP installation. So, I decided to remove the S-TAP but the GUI continued to show that the S-TAP was installed and then I decided to reset the GIM client by using the reset function in Set up by client. Since the reset didnt seem to propagate properly I decided to remove it manually in the Windows server environment and reinstall the GIM. After the re-installation the GIM would not call back to the appliance as it did the first time.
The problem:
GIM appliance is not getting registered in appliance GUI.
System (DB):
- Windows server 2012 MSSQL
Tried the following actions:
- Remote connection to GIM => Connection refused error
- Installed different versions of GIM (10.2 & 10.6)
- Check the central logger (copy snipets from the log)=>
- <html><head> error report HTTP Status 400 - Not supporting unauthenticated GIM clients
- send_to_gim:: going to read at least 1 byte and at most 186
- recv_data_ssl:: Total read 175 bytes
- send_to_gim::Finished writing to file this block of bytes !
- HTTP response processed successfully (last row)
- GIM log under GIM/currents
- -I- send_to_gim_server:: Detected non HTTP error from stdout [GIM_HEADER_MARKER
- Error report: HTTP Status 400 - Not supporting unauthenticated GIM clients
- GIM Service failed to register with server
- HTTP Status 400 - Not supporting unauthenticated GIM clients) (last row)
- Run installation setup.exe as admin
- IBM Security Guardium Installation manager service is running
- Restared CLI GUI
- Check installed management => GIM/Event list/Installed modules/Unautheticated GIM clients
Question:
- Does anyone know how to resolve this issue?
Let me know if you need more infomration
------------------------------
Herman Engström
------------------------------