Real time system log monitor shows error handling OA request: No shared ciphers for protocol after upgrading to RSA Authentication Manager 8.3
2 years ago
Originally Published: 2018-08-01
Article Number
000040873
Applies To
RSA Product Set: SecurID
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.3

 
Issue
After upgrading to RSA Authentication Manager 8.3, the system logs and real time  authentication activity monitor shows the following warning message:
 
Error handling OA request: No shared ciphers for protocol
 
[OARequestHandler8], (RequestReceiver.java:41), trace.com.rsa.authmgr.internal.oa.RequestReceiver, ERROR, doaisd6520.state.mt.ads,,,,
Error handling OA request
javax.net.ssl.SSLException: No shared ciphers for protocol
at com.rsa.sslj.x.aG.b(Unknown Source)
... at com.rsa.authmgr.internal.common.server.TCPServer$TCPServerThread.run(TCPServer.java:764)
Caused by: com.rsa.sslj.x.aJ: No shared ciphers for protocol
at com.rsa.sslj.x.bG.j(Unknown Source)
No Cipher
Cause
RSA Authentication Agent 7.3.1 [48] through 7.3.2 [80] were linked with a BSAFE version where the TLS 1.2 handshake was somehow broken but still worked by negotiating down to TLS 1.1. RSA Authentication Manager 8.3 servers now log these re-negotiation cipher error messages as warnings. 
Resolution
Download and install RSA Authentication Agents for Windows that is at least RSA Authentication agent 7.3.2 [85] for this particular problem.
 

As of August 2018, for various offline dayfile download issues, contact RSA Customer Support and request RSA Authentication Agent 7.3.3 [120] or later.



 

Workaround
Workarounds are not recommended here because they would involve lowering the Logging level below Fatal and would result in losing other important log information.