LDAPS connection does not work with RSA Authentication Manager 8.4
2 years ago
Originally Published: 2019-02-21
Article Number
000044682
Applies To
RSA Product Set: SecurID
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.4.0
 
Issue
An Active Directory LDAPS connection is not working since the Authentication Manager deployment was upgraded to 8.4.  There is an issue seen on an Active Directory instance hosted on Microsoft Windows 2012 Server where the connection fails. 
Cause
This is due to new FIPS-Inside compliance in Authentication Manager 8.4 and the LDAP server not being FIPS compliant
Resolution
First verify that your LDAPS certificate is at least 2048 bits in size.

How?
Workaround
In progress, if you encounter this issue.

Incomplete sentence
Notes
If you encounter an LDAPS connection error and receive the following error in imsTrace.log
 
Caused by: java.security.InvalidAlgorithmParameterException: Accepted DH prime length is 2048 or higher
 
If you encounter an LDAPS connection error . . . then what?