Network Management
Error 31224 Crypto Error - Unable to perform the requested algorithm
This article provides brief information and a resolution to the following error on some Orion Polling Engines when running a SNMP walk on the SNMPv3 device: Error 31224 Crypto Error - Unable to perform the requested algorithm. If FIPS restrictions are enabled, please select a FIPS compliant algorithm.
First published date
Last published date
Overview
This article provides brief information and a resolution to the cause for following error(s).
Error 31224 Crypto Error - Unable to perform the requested algorithm. If FIPS restristions are enabled, please select a FIPS compliant algorithm.
The errors are filled in various SNMP polling/collector plugin logs on one or more Orion Polling Engines where FIPS is enforced.
Also when you run a SNMP walk directly from one of the Orion servers against any device polled via SNMPv3 you will see same error in GUI. And when you perform SNMPv3 cred Test via Edit node it fails even though you can login with same credentials via SSH to the device directly.
Product section
Cause
- FipsAlgorithmPolicy was enforced on Solarwinds Orion Server(s) by means of GPO update, but Enable FIPS for Orion Platform products was not completed.
- FIPS enabled on Soalrwinds servers and in Orion platform as per Enable FIPS for Orion Platform products but some dll's missing x86 and x64 folders at C:\Program Files (x86)\Common Files\SolarWinds\OpenSSL
Resolution
Solution for cause 1 and steps to verify if FIPS Policy is enabled on Orion server(s)
1. Click Start > Run > secpol.msc
2. Expand to Security Settings\Local Policies\Security Options. If you get an error in MMC snap-in, then your account does not have sufficient rights to access Local Security policy settings. Please check with your domain admin.
3. Look for (it will probably be enabled in your case)
Another way to verify is to check for the following registry key is Enabled (1)
1. Open registry editor and navigate to HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy\
(Screenshots property of © 2022 Microsoft)
Once confirmed it is enabled and if it was indeed intended, then follow the steps to Enable FIPS for Orion Platform products
If it was not intended and it was enabled by accident, then check with your security team and roll back the FIPS policy and reboot the Servers.
Solution for cause 2:
Method 1:
- Browse to the directory C:\Program Files (x86)\Common Files\SolarWinds\OpenSSL and make sure "x64, x86" folders are not "Read-Only".
- Also check the directory C:\Program Files (x86)\Common Files\SolarWinds\OpenSSL\x86 make sure the following files are there and not blocked (by AV/security policy )
- Verify by right click > properties, unblock
- 4758cca.dll
- aep.dll
- atalla.dll
- capi.dll
- chil.dll
- cswift.dll
- gmp.dll
- gost.dll
- libeay32.dll
- nuron.dll
- padlock.dll
- ssleay32.dll
- sureware.dll
- ubsec.dll
Disclaimer: Please note, any content posted herein is provided as a suggestion or recommendation to you for your internal use. This is not part of the SolarWinds software or documentation that you purchased from SolarWinds, and the information set forth herein may come from third parties. Your organization should internally review and assess to what extent, if any, such custom scripts or recommendations will be incorporated into your environment. You elect to use third party content at your own risk, and you will be solely responsible for the incorporation of the same, if any.