KB Article #162288
PESIT transfers with SSL double authentication do not success with Interchange as PESIT server
Problem
--Interchange is acting as PESIT (Synchrony Transfer) SSL server,
--Partners (PESIT SSL clients) do not receive the complete list of certificate authorities during TLS Handshake process. On the received certificate authorities list from Interchange there is only one cert which is the one Interchange have to use to authenticate to the client.
=> In most of the case this list will appear empty on partner's logs as Interchange's server cert is not a Root cert.
=> In such scenario, client may be not able to send a certificate or is sending one and getting an 'alert 46 (certificate unknown)' in return from Interchange.
Resolution
1. Apply SP1 minimum on Interchange 5.10.1
2. Embedded PeSIT SSL on Pick a delivery exchange need to be re-create.
=> without re-creating the Embedded PeSIT SSL on Pick a delivery exchange error will still happen even with a recent SP version.