Sentinel 7.3.1 (and above) or Change Guardian 4.2 do not receive events from Sentinel UNIX Agent 7.4.

  • 7017336
  • 07-Mar-2016
  • 24-Jun-2016

Environment

NetIQ Sentinel 7.3.1, 7.3.2, and 7.4 Sentinel Server
NetIQ Change Guardian 4.2

Situation

Sentinel(7.3.1 & above) or Change Guardian 4.2 are not able to receive the events from sentinel UNIX agent 7.4.
The Sentinel Unix Agent must match the ciphers supported by the Sentinel or Change Guardian server to communicate without any issue.

Resolution

To resolve this issue on Sentinel install hotfix 7017336 from https://dl.netiq.com/patch/finder/ location.
To resolve this issue on Change Guardian, apply Security Agent for UNIX 7.4 HF7017336 Hotfix 9.

Cause

The security vulnerability fixes and the Java update in Sentinel 7.3.1 (and later) disables the RC4 ciphers on the ports enabled for the Web server. However, the UNIX Agent uses RC4 ciphers to communicate with Sentinel, and Change Guardian. Therefore, UNIX Agent can no longer communicate with Sentinel or Change Guardian.