How to handle when a component is failing to authenticate(handshake failure) after install in RSA Web Threat Detection 6.0
Originally Published: 2016-11-15
Article Number
Applies To
RSA Product/Service Type: Forensics
RSA Version/Condition: 6.0
Platform: Linux
Issue
Actual customer case -- After 6.0 installation, Silverplex is failing authentication. Here is an example of a handshake error on the Silverplex component:
Oct 27 15:59:23 slcst21a silverplex[81959]: [info] back [T11 st::tls::Server::MasterRunnable] [tls server 1] Accepted connection from 10.73.101.208:41799 Oct 27 15:59:23 slcst21a silverplex[81959]: [info] back [T6 st::task::QueueRunner] [st::tls::ServerHandshaker] [handshaker 1.6] [session 29309] TLS handshake on 8 Oct 27 15:59:23 slcst21a silverplex[81959]: [error] back [T6 st::task::QueueRunner] [st::tls::ServerHandshaker] [handshaker 1.6] [session 29309] TLS handshake error: Decryption has failed. Oct 27 15:59:23 slcst21a silverplex[81959]: [info] back [T6 st::task::QueueRunner] [st::tls::ServerHandshaker] [handshaker 1.6] [session 29309] Closing TLS session on 8 Oct 27 15:59:26 slcst21a rsyslogd-2177: imuxsock lost 143243 messages from pid 81641 due to rate-limiting
Tasks
Resolution
- Most processes use the SilverTail cert and key for different things-- passwords, shard encryption, interprocess communication. It may be best to restart all the services. Note -- Scout is used for interbox processes, so make sure this component is restarted first.
- Get an understanding of the Customer system architecture, which components are located on each server.
- Review /var/log/messages to check for TLS handshake errors and identify the components that are having these errors.
- Use md5sum command to make sure cert and key are the same on the servers that have failing components.
- Use Varz to see which components are connecting and passing messages and which are not.
Notes
Related Articles
Clearing PuTTY's Cache Of Host Finger Prints On Windows OS Event Sources 7Number of Views Poodle Bite Sandworm .Net MS14-057 OpenSSL Vulnerabilities and Impact in RSA products 4.79KNumber of Views Poodle Bite, Sandworm, .NET MS14-057, and other OpenSSL Vulnerabilities and Impact in RSA products 87Number of Views Third-party products using RSA Authentication Agents to send authentications are failing to authenticate 67Number of Views RCM xudad.exe is failing to start 21Number of Views
Trending Articles
Troubleshooting RSA SecurID Access Identity Router to RSA Authentication Manager test connection failures RSA SecurID Software Token 5.0.2 Downloads for Microsoft Windows RSA Authentication Manager 8.9 Release Notes (January 2026) Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory RSA Authentication Manager 8.8 Setup and Configuration Guide
Don't see what you're looking for?