RSA Authentication Manager Consoles Show ERR_SSL_PROTOCOL_ERROR in Chrome 117 and Later
Originally Published: 2023-12-01
Article Number
Applies To
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.x
Issue
After upgrading to Google Chrome 117 or later, the RSA Authentication Manager Security Console and Operations Console are no longer accessible. Chrome displays an SSL protocol error when attempting to load either console.
Observable symptoms:
- The Security Console and Operations Console fail to load in Google Chrome 117 and later
- Chrome displays the following error in the browser window:
This site can't provide a secure connection
ERR_SSL_PROTOCOL_ERROR
- The same consoles load successfully in Mozilla Firefox and Microsoft Edge
Cause
The RSA Authentication Manager console certificates are signed using SHA-1, which Google Chrome 117 no longer supports during the TLS handshake.
Chrome 117 removed support for SHA-1 server signatures as part of an ongoing security hardening effort. When Chrome attempts to establish a secure connection to the Security Console or Operations Console, it rejects the SHA-1 certificate and terminates the connection — producing the
ERR_SSL_PROTOCOL_ERROR. Browsers such as Firefox and Edge have not yet enforced this restriction, which is why the consoles remain accessible in those browsers.
Resolution
Two resolution paths are available depending on your certificate type. Follow the steps for the path that matches your environment.
Step 1: Determine which certificate type your environment uses:
- Self-signed certificate — the default RSA Authentication Manager internal certificate, not issued by an external CA
- Third-party certificate — a certificate issued and signed by an internal or external trusted Certificate Authority (CA)
ℹ️ NOTE: If you are unsure which certificate type is in use, check the certificate details in your browser before the upgrade to Chrome 117. The issuer field will indicate whether it is self-signed or CA-issued.
Option A — Self-Signed Certificate (SHA-1 → SHA-256 Upgrade)
Step 2: Follow the steps in Upgrade Internal Authentication Manager Certificates to SHA-256 — covers the full procedure to regenerate and apply the self-signed console certificate using SHA-256.
Option B — Third-Party Certificate Replacement
Step 2: Obtain a new certificate signed by your internal or external trusted CA using SHA-256 as the signature algorithm.
Step 3: Follow the steps in How to Replace the RSA Authentication Manager Console Certificate — covers the full procedure to install the new third-party SHA-256 certificate on the Security Console and Operations Console.
Step 4 — Verification: After completing either option, open Google Chrome 117 or later and navigate to the Security Console and Operations Console URLs. Confirm both consoles load successfully with no
ERR_SSL_PROTOCOL_ERROR displayed.⚠️ CAUTION: Do not delete or overwrite the existing certificate until the new SHA-256 certificate has been successfully installed and verified — reverting may require a full certificate regeneration.
Notes
Related Articles
Console and web tier virtual host certificates no longer trusted by Google Chrome 58.0.3029.81 in RSA Authentication Manag… 265Number of Views RSA Token Client returns error 40032 - R_TC_ERR_REGISTRATION_FAIL 17Number of Views Authentication Manager Console Access using CNAME or DNS alias fails with Redirect Logon Loop - ERR_TOO_MANY_REDIRECTS 6Number of Views UI not reachable on port 443 in RSA Governance & Lifecyle Virtual Application 121Number of Views java.lang.NoClassDefFoundError when saving a JAVA Code Based AFX Connector in version 7.0.2 of RSA Identity Governance & L… 72Number of Views
Trending Articles
RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide RSA Governance & Lifecycle 8.0.0 Installation Guide Troubleshooting RSA MFA Agent for Microsoft Windows How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device
Don't see what you're looking for?