SSLHandshakeException error when IMAPS protocol is configured for Approval Email Server in RSA Governance & Lifecycle
Article Number
Applies To
Issue
javax.mail.MessagingException: Could not connect to message store for imaps://username@imaps-server.hostname:993; nested exception is: javax.mail.MessagingException: Remote host terminated the handshake; nested exception is: javax.net.ssl.SSLHandshakeException: Remote host terminated the handshake at com.aveksa.server.email.common.EmailUtils.connectToMailStore(EmailUtils.java:651) at com.aveksa.server.email.mailboxmonitor.MailboxMonitorThread.checkForMail(MailboxMonitorThread.java:178) at com.aveksa.server.email.mailboxmonitor.MailboxMonitorThread.run(MailboxMonitorThread.java:46) Caused by: javax.mail.MessagingException: Remote host terminated the handshake; nested exception is: javax.net.ssl.SSLHandshakeException: Remote host terminated the handshake at com.sun.mail.imap.IMAPStore.protocolConnect(IMAPStore.java:670) at javax.mail.Service.connect(Service.java:295) at javax.mail.Service.connect(Service.java:176) at javax.mail.Service.connect(Service.java:125) at com.aveksa.server.email.common.EmailUtils.connectToMailStore(EmailUtils.java:625) ... 2 more Caused by: javax.net.ssl.SSLHandshakeException: Remote host terminated the handshake at com.ibm.jsse2.bj.a(bj.java:18) at com.ibm.jsse2.bj.b(bj.java:1) at com.ibm.jsse2.bj.f(bj.java:427) at com.ibm.jsse2.bj.a(bj.java:406) at com.ibm.jsse2.bj.startHandshake(bj.java:160) at com.sun.mail.util.SocketFetcher.configureSSLSocket(SocketFetcher.java:549) at com.sun.mail.util.SocketFetcher.createSocket(SocketFetcher.java:354) at com.sun.mail.util.SocketFetcher.getSocket(SocketFetcher.java:237) at com.sun.mail.iap.Protocol.<init>(Protocol.java:116) at com.sun.mail.imap.protocol.IMAPProtocol.<init>(IMAPProtocol.java:115) at com.sun.mail.imap.IMAPStore.newIMAPProtocol(IMAPStore.java:685) at com.sun.mail.imap.IMAPStore.protocolConnect(IMAPStore.java:636) ... 6 moreAn inspection of the TCP network traffic capture data shows a connection being attempted using TLSv1.0.
Cause
Resolution
mail.imaps.ssl.protocols=TLSv1.2Note: The JVM argument can be added on the WebSphere console > click Servers > Server types > WebSphere application servers > Select server > select the server used for SecurID Governance & Lifecycle > Configuration tab > select Server Infrastructure > Java and Process Management > Process Definition > Additional Properties > Java Virtual Machine > Generic JVM Arguments.
Related Articles
Artifacts to gather in RSA Identity Governance & Lifecycle 3.87KNumber of Views How to Replace the Web Server Certificate for the RSA Identity Governance & Lifecycle Web Console 3.22KNumber of Views How to Download and Reinstall the AFX Server Archive in RSA Governance & Lifecycle 1.5KNumber of Views AveksaAdmin Super Account Locked or Password Lost in RSA Governance & Lifecycle 1.71KNumber of Views AFX Server stuck in 'Not running' State, with error 'timed out waiting for AFX applications to start' 3.6KNumber of Views
Trending Articles
Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide How to Download OTP Token Seed Files from myRSA RSA Authentication Manager 8.9 Release Notes (January 2026)
Don't see what you're looking for?