Error "Key negotiation exchange failed. Server response was CANCELLED" with RSA Authentication Agent API 8.5 and later
Originally Published: 2020-06-01
Last Modified: 2026-06-10
Article Number
Applies To
RSA Product/Service Type: RSA Authentication Agent API
RSA Version/Condition: 8.5 and later
Issue
com.rsa.authagent.authapi.AuthAgentException: Error in initial AuthnReq/Rsp for serverTime.Error in processing Authn request: connect exception processing key negotiation request: com.rsa.authmgr.commonagent.h: Key negotiation exchange failed. Server response was CANCELLED
com.rsa.authagent.authapi.AuthAgentException: com.rsa.authagent.authapi.AuthAgentException: Error in initial AuthnReq/Rsp for serverTime.Error in processing Authn request: connect exception processing key negotiation request: com.rsa.authmgr.commonagent.h: Key negotiation exchange failed. Server response was CANCELLED
at com.rsa.authagent.authapi.AuthSessionFactory.a(AuthSessionFactory.java)
at com.rsa.authagent.authapi.AuthSessionFactory.getInstance(AuthSessionFactory.java)
at sample.AuthUser.<init>(AuthUser.java:32)
at sample.AuthUser.main(AuthUser.java:62)
Cause
This is the certificate the AM uses in the communication with the TCP Agents. If this certificate is not correct then the authentication will fail with the above error.
The certificate found in the above page should be the same as the one we can export after accessing https://AM fully qualified domain name:7002
Resolution
- Using Google Chrome, browse to https://AM fully qualified domain name:7002
- Click on the lock icon in the browser address bar.
- Click on Certificate.
- Click the Certification Path tab.
- Double-click on the top-level (root, very first) certificate in the list.
- Click on Details tab, then Copy to File...
- Click Next, then check the Second Option Base-64 encoded X.509 output format (.CER)
- Click Next, then click Browse to choose the location and give it any name, such as root then Click Save.
- Click Next then Finish, you'll find the exported certificate in the location chosen in Step 8
- Browse to Security Console –> Setup –> System Settings --> Agents, then click on To configure agents using IPV6, click here.
- Scroll down under Existing Certificate Details, click on the Choose File Option then browse to the certificate we just exported then Click Update.
Notes
If the Authentication Manager is on 8.2 SP1 till 8.2 SP1 Patch 4, you can still see the above errors even after you complete the steps in the Resolution. This is because there is a bug on AM 8.2 SP1 where it doesn't communicate with the certificate we export from the 7002 port that it should use, it communicates with the Console Certificate. The environments that will see this are the environments that have replaced the default self-signed certificate for the consoles with another certificate.
There are 3 workarounds to solve this:
- Upgrade to AM 8.2 SP1 Patch 5.
- Revert the Console Certificate to use the default self-signed certificate using below steps or normally from the Operations console: Reverting back to the RSA self-signed default certificates on Authentication Manager
- Follow the exact steps in the resolution here, but in step 1 rather than browsing to https://AM fully qualified domain name:7002, browse to either the Security Console or the Operations Console of the Authentication Manager and export the certificate from there, then complete the same steps as they are.
Related Articles
RACF-SSH based connector fails with Unable to Negotiate Key Exchange error in RSA Governance & Lifecycle 20Number of Views Error "Key negotiation exchange failed. Server response was CRED_MISMATCH" with RSA Authentication Agent SDK 8.6 for Java 238Number of Views Change Requests cancelled by Escalation Workflows progress to Fulfillment instead of getting cancelled in RSA Identity Gov… 137Number of Views Federated Salesforce Account Collector fails with 'Invalid Credentials' in RSA Identity Governance & Lifecycle 121Number of Views The Cancel Pending Requests button on the Pending Submissions page is disabled in RSA Identity Governance & Lifecycle 68Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Reporting on RSA Authentication Manager 8.x users with On-Demand Token, a fixed passcode or a hardware/software token assi… How to Download OTP Token Seed Files from myRSA Anomalix idGenius - SAML Relying Party Configuration - RSA Ready Implementation Guide RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide
Don't see what you're looking for?