IDR Cannot Register with Cloud Authentication Service with Explicit Proxy and DNS Does not Resolve Authentication Service Domain
2 years ago
Article Number
000072012
Applies To
RSA Product Set: RSA 
RSA Product/Service Type: Identity Router
RSA Version/Condition:
Issue
IDR cannot register with Cloud Authentication Service with explicit proxy and DNS does not resolve the Authentication Service domain. This applies to the customers whose IDR is behind the firewall and want to use a proxy server to resolve its DNS request for IDR registration instead of providing a DNS server on the IDR Setup page.
Cause
During the registration, IDR uses the ‘/usr/bin/host’ command to do a DNS check. The host command does not go through a proxy and tries to go directly DNS server to resolve the external domain.
If DNS server is unable to resolve the URL, the request will not go to the configured proxy due to which the IDR registration fails.
Workaround
Customers should either configure a DNS server to resolve all external DNS or contact RSA Customer Support for a quick hotfix and apply it as instructed by RSA Customer Support.