MFA Agent Test Authentication fails with error ServerConnectionFailed
Article Number
Applies To
RSA Product/Service Type: MFA Agent for Microsoft Windows
Issue
unsuccessful to connect to a server
Cause
Caught Api exception: IO.Swagger.OfflineAuthenticationClient.ApiException: Error calling RequestOfflineMetadata: The request was aborted: Could not create SSL/TLS secure channel. at IO.Swagger.OfflineAuthenticationApi.OfflineMetadataApi.RequestOfflineMetadataWithHttpInfo(OfflineMetadataRequest offlineMetadataRequest) at RSA.Authentication.Offline.Services.DayFileSvc.GetOfflineMetaData(String offlineUrl, String accessKey, String clientId, String accessPolicyId, String userName, String domain, String attemptId) error code 0
The TLS failure implies that either
1) the CAS Root CA cert is not trusted by this system, or
2) the Agent cannot negotiate a mutually acceptable cipher algorithm with CAS.
From Wireshark capture logs there is a TLS Handshake failure due to cipher issues
Resolution
TLS_DHE_RSA_WITH_AES_256_GCM_SHA384 (0x9f)
TLS_DHE_RSA_WITH_AES_128_GCM_SHA256 (0x9e)
Notes
- Open MMC > Certificates > Computer and verify that the CAS root CA (Entrust Root Certification Authority - G2) is listed in the Trusted Root Certificate Authority store
Related Articles
Test Authentication with RSA MFA Agent for Microsoft Windows 32Number of Views RSA MFA Agent 3.x AD FS for Windows Not Prompting for MFA on Test Page 17Number of Views Enable a web proxy for RSA MFA Agent for Microsoft Windows 464Number of Views Determine the challenge mode of RSA Authentication Agent 7.x for Windows from Windows registry 140Number of Views Disable multi-factor authentication (MFA) prompt for "Run as" on machine on which the RSA MFA Agent for Microsoft Windows … 1.24KNumber of Views
Trending Articles
RSA Authentication Manager Upgrade Process RSA Release Notes for RSA Authentication Manager 8.8 RSA RADIUS Server service failed to start in the RSA Authentication Manager 8.1 Operations Console Microsoft Entra ID External MFA - Relying Party Configuration Using OIDC - RSA Ready Implementation Guide RSA Release Notes: Cloud Access Service and RSA Authenticators
Don't see what you're looking for?