My answer inlline.
- Does that mean the encryption keys for both environments are same because I didn't see any errors during import?
Ujwol => Depends on whether you exported keys encrypted or not (used -c switch or not) . If you exported keys encrypted and if you were able to import it successfully, it would imply that Policy server encryption keys are the same.
- Before running the smkeyimport I had registered test web-agent with this 12.7 policy-server. I was able to successfully test authentication/authorization for the test protected page. After running smkeyimport I am not able to access that protected site and I get below errors.
[6551/140045428176640][Thu Mar 15 2018 15:02:45][CServer.cpp:2121][ERROR][sm-Tunnel-00010] Bad security handshake attempt. Handshake error: 3154
[6551/140045428176640][Thu Mar 15 2018 15:02:45][CServer.cpp:2132][ERROR][sm-Tunnel-00050] Handshake error: Shared secret incorrect for this client
Ujwol => This doesn't make sense. The shared secret in trusted host is encrypted using Policy store key which is dervied from Policy server encryption key. This has nothing to do with Persistent Key/Agent Key that you imported.
DId you reboot your web server host by any chance ?
I would say re-register the agent.
I haven't rolled over the keys yet from 12.7 policy-server. Should I do the rollover and that should take care of this error?
Ujwol => Don't do that. If you roll the keys, your keys wont' be in sync with 12.0 setup and you can no longer have SSO with it. You should disable any dynamic key rollover and never perform manual key rollover from either of the policy server.
If you want dynamic agent key rollover, you will need to configure common key store.
There are some additonal configuration which is needed to fully support this.
If you haven't already read through this , I would strongly encourage to read through this blog to fully understand different keys that CA SSO uses and how they are relevant for what function.
Tech Tip : CA Single Sign-On : Data Protection, Key Management,Configuration & Common Issues