Authentication agent for Windows, AAWin autoregistration fails after update to RSA Authentication Manager 8.4 Patch 14
Originally Published: 2021-01-14
Article Number
Applies To
RSA Product/Service Type: Authentication Agent for Windows
RSA Version/Condition: AAWin 7.4, 7.4.4, AM 8.4 P14, AM 8.5 P1
Platform: Windows, Linux
Issue
Symptoms:
===autoreg log from agent====
Handshake failed ssl_error
Handshake failed: SSL Protocol Failure File
Handshake failed sdErr <1>
errCliUtlOpenServerConnection():
SDSSLPerformHandshake failed with error code SD_ERR_SSL_HANDSHAKE_FAILED <20023>
===imsTrace.log===
Failover list: |AAAAAgAAAAFyc2FyZXBsaWNhLm1ja3NkYy5jb20AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA...
WARN, rsa.domain.com,,,,SSL handshake fails for the socket [ServerMode...
CipherSuite: SSL_NULL_WITH_NULL_NULL, Protocol: SSLv3]...
javax.net.ssl.SSLException: Fatal Alert received: Certificate Unknown...
Cause
Resolution
Or
Instead of downloading server.cer from Security console, use WinSCP to copy it from Linux
/opt/rsa/am/config/src/resources/certs/server.cer from the appliance.
Or
Use the older version of server.cer, downloaded from AM 8.4 P13 or earlier, making sure that this server.cer is equivalent and not from an earlier license or different instance.
Workaround
Related Articles
java.lang.NoClassDefFoundError when saving a JAVA Code Based AFX Connector in version 7.0.2 of RSA Identity Governance & L… 70Number of Views RSA Token Client returns error 40032 - R_TC_ERR_REGISTRATION_FAIL 17Number of Views UI not reachable on port 443 in RSA Governance & Lifecyle Virtual Application 119Number of Views Console and web tier virtual host certificates no longer trusted by Google Chrome 58.0.3029.81 in RSA Authentication Manag… 255Number of Views How to understand SSL protocols and ciphers in Authentication Manager 8.x 1.21KNumber of Views
Trending Articles
RSA Authentication Manager Upgrade Process RSA Release Notes for RSA Authentication Manager 8.8 RSA RADIUS Server service failed to start in the RSA Authentication Manager 8.1 Operations Console Microsoft Entra ID External MFA - Relying Party Configuration Using OIDC - RSA Ready Implementation Guide RSA Release Notes: Cloud Access Service and RSA Authenticators
Don't see what you're looking for?