RSA Product/Service Type: Authentication Manager & MFA Agent for Microsoft Windows
RSA Version: 8.x (Authentication Manager) & 2.x (MFA Agent for Microsoft Windows)
Users are unable to authenticate with the RSA MFA Agent for Windows configured with the Authentication Manager.
Testing authentication with the "RSA MFA Agent Test Authentication" utility fails and results in an "Unsuccessful connection to RSA" or "Unsuccessful connection to SecurID Access" message.
The "RsaMfaAgentTestAuthentication(RSA_MFA_Agent_Test_Authentication).log" file includes the following error message:
[E] [RSA.Authentication.Connection.ConnectionHandler.ServerCertificateValidator] Error in Server certificate validation: Certificate Name Mismatch
but the hostname in the Authentication Manager (AM) server certificate used for the communication between the AM server and MFA Agent matches the hostname of the AM server, hence the certificate name does not actually mismatch.
It was found that there was an IP address included as a Subject Alternative Name (SAN) in the Authentication Manager server's Console Certificate and that this was causing the issue.
Replace the Authentication Manager Console Certificate with a server certificate that does not include an IP address as a Subject Alternative Name.
Replacing the Authentication Manager (AM) Console Certificate also changes the certificates that AM uses on port 5555 TCP, which is the port that REST-based agents, such as the MFA Agent for Windows, use when communicating with AM.
Related Articles
Web Server certificate verification failed with RSA Authentication Agent 8.0 for Web for Apache 76Number of Views After updating the certificates for RSA Identity Governance & Lifecycle, WildFly reports error: JBAS015299: The KeyStore /… 352Number of Views 7./0 Apache Web Agent for Securid/Auth Manager 7.X on Unix - why is RPC required? 66Number of Views RSA Cloud Authentication Service password authentication fails due to "LDAP account not permitted to authenticate via this… 151Number of Views Ports for the RSA Authentication Manager Instance 798Number of Views
Trending Articles
Passwordless Authentication in Windows MFA Agent for Active Directory – Quick Setup Guide RSA Authentication Manager 8.9 Release Notes (January 2026) RSA Authentication Manager Upgrade Process RSA Authentication Manager 8.7 SP2 Setup and Configuration Guide An example of SSO using SAML and ADFS with RSA Identity Management and Governance 6.9.x