Error: Failed to connect to Identity Router, RSA SecurID Access Authenticate app tokencodes fail with an RSA Authentication Manager protected resource
Originally Published: 2019-08-14
Article Number
Applies To
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.4 Patch 4
Issue
Attempting to authenticate to an Authentication Manager protected resource using an Authenticate App tokencode results in an authentication failure.
The following error is shown in the: Security Console > Reporting > Real-time Activity Monitors > System Activity Monitor:
Error: Failed to connect to Identity Router
Cause
- Authentication Manager is connected to the Cloud Authentication Service by setting up the configuration under: Security Console > Home > Connect to the Cloud Authentication Service.
- Authentication Manager is also configured to send the Authenticate tokencodes to the Cloud Authentication Service through the identity router(s) under: Operations Console > Deployment Configuration > RSA SecurID Authenticate App.
- Authentication Manager is no longer able to successfully communicate with an identity router as needed for the configuration of (2) above. This can be verified by using the Test Connection button on the Operations Console > Deployment Configuration > RSA SecurID Authenticate App page. (If there are any replica Authentication Manager servers in the environment, the connection should also be tested from each replica's Operations Console to verify the connection to the identity router(s) from that particular Authentication Manager instance.)
Resolution
Solution 1: Disable the configuration that allows Authenticate app tokencodes to be sent from the Authentication Manager to the Cloud Authentication Service through the identity router(s). This can be done by going to: Operations Console > Deployment Configuration > RSA SecurID Authenticate App and unchecking the "Allow authentication using Authenticate Tokencodes" option. Then save these settings.
With this option disabled, the Authenticate tokencodes will no longer attempt to be sent to the Cloud Authentication Service through the identity router(s) but will instead be sent using Authentication Manager's direct connection to the Cloud Authentication Service.
Solution 2: Resolve the connection issue between the Authentication Manager server(s) and identity router(s) to allow the Authenticate tokencodes to be sent to the Cloud Authentication Service through the identity router(s).
Related Articles
Error: Principal does not possess one or more authenticators when using RSA SecurID Access Authenticate app tokencode with… 591Number of Views Failed to connect to the database error during upgrade to RSA Identity Governance & Lifecycle 7.0.1 230Number of Views Intermittent failures authenticating to RSA SecurID Authentication Manager protected resources using the RSA SecurID Acces… 71Number of Views REMINDER: Mandatory Time-Bound Upgrade Required for RSA Authentication Manager and RSA Authenticate App/RSA Authenticator … 166Number of Views Multi-App Collector Circuit Breaker trips incorrectly in SecurID Governance & Lifecycle 208Number of Views
Don't see what you're looking for?