PAM Agent is failing to connect to RSA Servers (Curl error code: 35)
2 months ago
Originally Published: 2024-04-25
Article Number
000072169
Applies To
RSA Product Set: RSA SecurID
RSA Product/Service Type: Authentication Agent for PAM
Issue
  • PAM Agent authentication is failing using REST Protocol showing (Curl error code: 35) in the /var/ace/log/mfa_rest.log

image024.png
  • SSL/TLS Handshake is failing, showing Alert ( Level: Fatal, Description: Illegal Parameter) in the Server Hello.

Screenshot 2024-04-25 180812.png

 
Cause
The RSA Authentication Manager root certificate is using Signature Algorithm SHA-1. 
Resolution

Upgrade the  Internal Authentication Manager Certificates to SHA-256 by following the below article:
Upgrade Internal Authentication Manager Certificates to SHA-256