Authentication Manager version 8.5: Failed to register to the FedRamp - Govcloud Cloud Authentication Service
Originally Published: 2021-08-30
Article Number
Applies To
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.5.0
Platform: Linux
O/S Version: Suse Linux
Issue
ERROR: Failed to register to the Cloud Authentication Service
An unknown system error occurred.
===imsTrace.log===
2021-08-09 12:19:52,772, [[ACTIVE] ExecuteThread: '12' for queue: 'weblogic.kernel.Default (self-tuning)'], (RetriveRootCertificate.java:178), trace.com.rsa.authmgr.integration.via.internal.client.RetriveRootCertificate, FATAL, <primary_FQDN>,,,,Exception while retrieving the root certificate.
java.lang.RuntimeException: io.netty.channel.ConnectTimeoutException: connection timed out: access.securidgov.com/20.140.188.86:80
Connection to https://access.securidgov.com from AM Primary and Embedded IDR fails with
FATAL, <primary>.qnet.com,,,,Exception while retrieving the root certificate.
Connection timed out: access.securidgov.com/20.140.188.86:80
Cause
- Original, Non-FedRamp to https://access.securid.com supported since AM 8.3 P1
- Newer, FedRamp to https://access.securidgov.com which is CAS for Govcloud sites, supported in AM 8.5 P5 and AM 8.6 P1 or later.
Both connections are essentially the same, though they have slightly different Certificate Trust chains that must be included in an internal .jks key store by Engineering in a specific patch or version of Authentication Manager.
Typical registration failure messages are somewhat clear, like this: Invalid or expired registration code
But when you see unknown system error occurred
is the Security Console, and the /opt/rsa/am/server/logs/imsTrace.log shows
FATAL, <primary_FQDN>,,,,Exception while retrieving the root certificate.
java.lang.RuntimeException: io.netty.channel.ConnectTimeoutException: connection timed out: access.securidgov.com/20.140.188.86:80
The first thing to check is that you have AM 8.5 patch 5.
Resolution
AM-42355. Added support for the FedRAMP domain name securidgov.com to the embedded identity router.
You need AM 8.5 P5 or AM 8.6 P1 or later.
Notes
Related Articles
Error message when attempting to register on the RSA Community (The Salesforce record provisioning for the user failed wit… 10Number of Views Unable to register an RSA SecurID Access SSO application in the Cloud Administration Console 42Number of Views Initialization error "Unable to register plugin InformationCommandHandler" using Websphere 9 in RSA Identity Governance an… 9Number of Views Simple migration from RSA Authentication Manager 7.1 to version 8.1 or higher 1.37KNumber of Views IDR Cannot Register with Cloud Authentication Service with Explicit Proxy and DNS Does not Resolve Authentication Service … 236Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device RSA-2026-10: RSA Authentication Manager Security Update for Third-Party Component Vulnerabilities Download RSA SecurID Access Cloud User Event audit logs using Cloud Administration REST API CLU RSA SecurID Desktop Token 5.0.3 for Windows Administrator's Guide RSA SecurID Software Token 4.2.1 for Mac OS X Administrator's Guide
Don't see what you're looking for?