Applications Systems

SolarWinds Platform Agent on FIPS-Enabled Linux (RHEL 9): "Failed to load fips provider; OSSL_PROVIDER_load failed" and Plug-in Ping-Test Failure

A SolarWinds Platform Agent on a FIPS-enabled RHEL 9 host fails to start or finish updating because the OpenSSL FIPS provider cannot be loaded (Failed to load fips provider; OSSL_PROVIDER_load failed, Error 0x9). This surfaces as an agent stuck in "Update in progress," a "Plug-in error" status, or a plug-in that "failed the ping test after installation."

First published date

8/13/2026 6:41 PM

Last published date

8/13/2026 6:41 PM

Overview

On a FIPS-enabled Red Hat Enterprise Linux (RHEL 9.x) host, the SolarWinds Platform Agent fails to start or complete an update. The agent may sit for days in "Update in progress," and after a reinstall may show a "Plug-in error" state because a plug-in fails its post-install ping test.

The exact, full error observed in the system journal / agent output is:

vdyd-ps-redis1v swiagent[3659744]: SolarWinds Agent[3659744]: Agent failed. Error [0x9] : std::exception caught: Description: [Failed to load fips provider; OSSL_PROVIDER_load failed], File: ./Src/EminentWare.Agent.Service/Agent.Service.cpp, Line: 771
vdyd-ps-redis1v systemd[1]: swiagentd.update.service: New main PID 3659744 does not exist or is a zombie.

In the console, the affected agent shows:

  • Agent Status: Plug-in error

  • Connection Status: Connected (green)

  • A plug-in (for example, Log Analyzer "Log Files") reporting "Installation Failed – the plug-in failed the ping test after installation."

This article explains:

  • How to recognize that an agent startup/update failure on a FIPS host is caused by the OpenSSL FIPS provider failing to load.

  • How to determine whether the fault is at the operating-system level or in the agent's own configuration (the openssl list -providers gate).

  • How to resolve it with a clean, STIG/FIPS-compliant manual reinstall.

  • How to prevent recurrence on FIPS-enabled hosts.

Symptoms:

  • A single Linux (RHEL 9.x) server with FIPS enabled shows an available agent update that never completes and hangs in "Update in progress" for days.

  • Other, identical RHEL 9.x hosts are not affected.

  • After an uninstall/reinstall, the agent connects and upgrades, but one plug-in fails and the agent shows "Plug-in error."

  • The server journal repeatedly reports the agent failing to start with a FIPS provider load error, and swiagentd.update.service terminating (PID "does not exist or is a zombie").

Product section

Server Application Monitor

Cause

Because the host is FIPS-enabled, the agent must initialize OpenSSL in FIPS mode at startup by calling OSSL_PROVIDER_load("fips"). When that call fails, the agent process exits with Error 0x9, and swiagentd.update.service cannot stay running (systemd reports the PID as absent / a "zombie"). The systemd message is a consequence of the agent exiting, not a separate service defect.

The FIPS provider fails to load for one of two reasons:

  • Agent-side (most common): The agent's local FIPS configuration (fips.cnf / fipsmodule.cnf) is missing, stale, or its integrity MAC no longer matches the shipped FIPS module — the state typically left behind by a failed or interrupted agent update. Plug-ins that run as their own worker process (for example, the Go-based Log Analyzer "Log Files" plug-in) then crash during initialization and fail the post-install ping test, flipping the agent to "Plug-in error."

  • OS-side: The host's system OpenSSL FIPS provider itself is not loading (broken or version-mismatched). In this case the agent cannot load a FIPS module the host itself cannot load.

The difference between an agent-side and OS-side cause is what openssl list -providers distinguishes, and it determines whether a reinstall will resolve the issue.

Resolution

Perform the steps in order. Do not skip Step 1 — it determines whether a reinstall can succeed.

Step 1 — Confirm FIPS is healthy at the OS level (gating check). Run on the affected host:

openssl list -providers
  • If the fips provider is listed with status: active, the OS module is healthy and the fault is in the agent's own configuration. Continue to Step 2.

  • If the fips provider does not load, the host's system OpenSSL FIPS module must be validated and repaired first (customer/OS side). A reinstall will not hold until the OS-level provider loads.

On RHEL 9, it is normal and correct for the base/default providers to report a newer OpenSSL version (for example, 3.5.5) while the fips provider reports the Red Hat FIPS 140-3 validated version (for example, 3.0.7). A validated FIPS provider intentionally trails the general library; this is not a mismatch.

Step 2 — Clean manual reinstall of the agent, run as root. Perform a full uninstall followed by a fresh manual reinstall as root. A clean install regenerates the agent's local FIPS configuration so it matches the shipped FIPS module. This stays within STIG/FIPS requirements — it does not change the nosuid mount option and adds no unauthorized setuid/setgid files. Reference: Deploy SolarWinds Platform Agents manually to a Linux/Unix-based computer

Step 3 — Reinstall the failing plug-in. If the agent connects but a plug-in still shows "Installation Failed – failed the ping test," use Reinstall plug-in for that plug-in in the console. Once it passes its ping test, the agent status clears from "Plug-in error." Reference: View the status of agent plug-ins

Step 4 — If it still fails after a clean reinstall. Collect /opt/SolarWinds/Agent/bin/appdata/Logs/swiagent.log and openssl version -a, and compare fips.cnf / fipsmodule.cnf on the affected host against a known-good RHEL 9.x host to identify the difference.

Prevention (required for FIPS hosts). FIPS-mode agents must be deployed and updated manually. Automatic or push updates from the console are not supported in FIPS mode and can leave the agent's FIPS configuration in an incomplete state. Treat FIPS-enabled hosts as manual-update nodes for all future platform upgrades. Reference: SolarWinds Platform Agent requirements (FIPS support)