Root (Server) and Client Certificates are RFC-5280 compliant starting in version 7.2.0 of RSA Identity Governance & Lifecycle
Originally Published: 2020-08-14
Article Number
Applies To
RSA Version/Condition: 7.2.x
Issue
An example of a non RFC-compliant certificate (SKI > 20 octets) is shown below. Most octets are redacted but that is what the redaction is covering:
Resolution
Note: This only needs to be done if you have Remote AFX Agents and/or Remote Collection Agents. If certificates are not regenerated, the firewall issue mentioned above will continue to occur and multiple Remote AFX Server failures may also occur. See related RSA Knowledge Base Article 000039237 -- Multiple Remote AFX Server Failures caused by 'Issuer key identifier for the subject and the Subject key identifier for the issuer must be the same' after upgrading to version 7.2.0 of RSA Identity Governance & Lifecycle for more information.
An example of an RFC-compliant certificate (SKI restricted to 20 octets) is shown below. Although redacted, you can see the difference between this Subject Key Identifier and the one above.Notes
Related Articles
BASE libraries can't be used on platforms that haven?t been upgraded with the latest MSVCRT libraries. 11Number of Views Virtual Attributes in Access Policies (Active Directory Only) 81Number of Views "HTTP response error! Response code=401" when starting RSA Identity Governance and Lifecycle Access Fulfillment Express (A… 234Number of Views How to overcome the RSA Identity Governance & Lifecycle initialization status error when the database schema version is hi… 176Number of Views Remote Java JMX agent is configured without SSL client and password authentication in RSA Governance & Lifecycle 37Number of Views
Don't see what you're looking for?