MFA Agent Test Authentication fails with error ServerConnectionFailed
Article Number
Applies To
RSA Product/Service Type: MFA Agent for Microsoft Windows
Issue
unsuccessful to connect to a server
Cause
Caught Api exception: IO.Swagger.OfflineAuthenticationClient.ApiException: Error calling RequestOfflineMetadata: The request was aborted: Could not create SSL/TLS secure channel. at IO.Swagger.OfflineAuthenticationApi.OfflineMetadataApi.RequestOfflineMetadataWithHttpInfo(OfflineMetadataRequest offlineMetadataRequest) at RSA.Authentication.Offline.Services.DayFileSvc.GetOfflineMetaData(String offlineUrl, String accessKey, String clientId, String accessPolicyId, String userName, String domain, String attemptId) error code 0
The TLS failure implies that either
1) the CAS Root CA cert is not trusted by this system, or
2) the Agent cannot negotiate a mutually acceptable cipher algorithm with CAS.
From Wireshark capture logs there is a TLS Handshake failure due to cipher issues
Resolution
TLS_DHE_RSA_WITH_AES_256_GCM_SHA384 (0x9f)
TLS_DHE_RSA_WITH_AES_128_GCM_SHA256 (0x9e)
Notes
- Open MMC > Certificates > Computer and verify that the CAS root CA (Entrust Root Certification Authority - G2) is listed in the Trusted Root Certificate Authority store
Related Articles
RSA MFA Agent 3.x AD FS for Windows Not Prompting for MFA on Test Page 17Number of Views RSA MFA Agent 2.0 for Epic Hyperdrive Release Notes 40Number of Views 'com.rsa.authmgr.admin.tokenmgt.ListTokensByPrincipalCommand execution' error when trying to assign a token on RSA Authent… 72Number of Views 'javax.net.ssl.SSLHandshakeException: sun.security.validator.ValidatorException: PKIX path' error when testing a RESTful W… 325Number of Views Operations Console Administrators 78Number of Views
Trending Articles
Downloading RSA Authentication Manager license files or RSA Software token seed records Unable to login to RSA Authentication Manager Security Console as super admin RSA Authentication Manager 8.9 Release Notes (January 2026) How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Connection fails to Cloud Authentication Service when connecting through a proxy server from RSA Authentication Manager to…
Don't see what you're looking for?