KB Article #66839
Alert 40 sent (handshake failure) After Root certificate is Removed from Gateway Database but not from Security Profile
-- Configure PESIT transfer en SSL
-- Create a Sever SSL profile and check 2 ROOT Certificates : CERT1 and CERT2
-- Create a transfer - OK
-- Delete the certificate CERT2
-- Check the SSL security profile - the certificate is not anymore availalbe in the Accepted Authorities list
-- Try the same transfer with the same PESIT partner. Get the following error :
20100915 165840 013 SECS I SES_INIT (35651600) Server TLS Security Profile : SSL_PHSE_SERVER selected
ENGQTAXABgA 20100915 165840 103 NET I CONN_RESP (7) incoming connection response [resp_add=""]
20100915 165840 030 SECS I C_BUILD (35651600) Server Certificate sent: Sopra Sample User 2
20100915 165840 032 SECS I C_BUILD (35651600) Server Certificate sent: C=FR, ST=Hauts-de-Seine, L=Puteaux, O=SOPRA, OU=RDM-XFB, CN=Sopra Sample User 2
20100915 165840 030 SECS I C_BUILD (35651600) Server Certificate sent: Sopra Sample CA
20100915 165840 032 SECS I C_BUILD (35651600) Server Certificate sent: O=SOPRA, OU=CertificationUnit, CN=Sopra Sample CA
20100915 165840 014 SECS I CA_BUILD (35651600) Server Sending Accepted DN: Sopra Sample CA
20100915 165840 016 SECS I CA_BUILD (35651600) Server Sending Accepted DN : O=SOPRA, OU=CertificationUnit, CN=Sopra Sample CA
20100915 165840 017 SECS E CA_BUILD (35651600) Server Accepted DN : CERT2
ENGQTAXABgA 20100915 165840 053 NET W TLSALSND (7) alert 40 sent (handshake failure)
ENGQTAXABgA 20100915 165840 105 NET I DISC_REQ (7) disconnection request [reason="0"]
-- CERT2 was NOT used at any time, but after deleting it there is no option to remove it from the security profile, as this certificate doesn't appear anymore there
Resolution
* The issue is resolved starting from SP18 for Synchrony Gateway 6.11.4 which is available on the Axway Support site
* After applying, go to the Security profile - Accepted authorities and click OK ( even if it seems to change nothing ) and then click OK on the screen of Security profile modification.
* Retest the issue.