Tips for finding Knowledge Articles

  • - Enter just a few key words related to your question or problem
  • - Add Key words to refine your search as necessary
  • - Do not use punctuation
  • - Search is not case sensitive
  • - Avoid non-descriptive filler words like "how", "the", "what", etc.
  • - If you do not find what you are looking for the first time,reduce the number of key words you enter and try searching again.
  • - Minimum supported Internet Explorer version is IE9
Home  >
article

KB-8005: Centrify Privileged Service cannot connect to Oracle database when FIPS is enabled

Centrify Privilege Service ,  

20 December,16 at 09:23 AM

Applies to: Centrify Privilege Service

Problem:
If a cloud connector has FIPS algorithm policy enabled, administrators will not be able to add Oracle databases into CPS with an error message "Verification failed. Bad credentials." shown.
Verification failed. Bad credentials.

Cause:
With ODP.NET version older than 12.1.0.2 or 11.2.0.4, If the cloud connector has FIPS algorithm policy enabled, the Oracle managed driver plugin will fail to work.

Workaround:
Disable the FIPS algorithm policy on the machine. To disable FIPS algorithm policy on the machine, use regedit to set the following registry value.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy] "Enabled"=dword:00000000

Resolution:
The issue was resolved with ODP.NET 12.1.0.2 and patched on 11.2.0.4, which you can upgrade as part of the Oracle 12.1.0.2 and 11.2.0.4 patchset or as part of ODAC 12c R3. And on the server side, version 12.1.0.2 or higher is a must.

References:
ORA-01017 with managed ODP.NET provider when FIPS is enabled
https://community.oracle.com/message/12738172#12738172

Still have questions? Click here to log a technical support case, or collaborate with your peers in Centrify's Online Community.