Services failed to restart after upgrade to 8.8 while using custom signed certificates
Article Number
Applies To
Authentication Manager Version 8.8
Issue
Services failed to restart after upgrade to 8.8 while using custom signed certificates.
Logs show: javax.net.ssl.SSLHandshakeException: sun.security.validator.ValidatorException: Netscape cert type does not permit use for SSL server
Example certificate:
Cause
Authentication Manager version 8.8 uses Java version 12. This error occurred because Java 12 no longer accepts the "Netscape cert type" extension.
Resolution
Use a certificate that doesn't use the netscape extension.
Workaround
Revert back to self signed certificate.
rsaadmin@am81p:~> cd /opt/rsa/am/utils rsaadmin@am81p:/opt/rsa/am/utils> ./rsautil reset-server-cert Please enter OC Administrator username: <enter Operations Console admin user name> Please enter OC Administrator password: <enter the password for the Operations Console user>
After the certificate is replaced, restart the Authentication Manager services:
rsaadmin@am81p:/opt/rsa/am/utils> cd ../server rsaadmin@am81p:/opt/rsa/am/server> ./rsaserv restart all
Related Articles
RSA Authentication Manager 8.1 primary instance fails to upgrade to 8.2 with error: Replication flush failed 1.08KNumber of Views Authentication Manager 8.5 upgrade to 8.6 fails with error: Unactivated changes are present in the WebLogic Server config.xml 1.31KNumber of Views Authentication Manager 8.x upgrade fails with error "Failed to launch the update installer to apply the update" 549Number of Views Replication Showing Internal Replication Error During Upgrade to RSA Authentication Manager 8.2 994Number of Views Applying patch or upgrade fails after hardening RSA Authentication Manager appliance 833Number of Views
Trending Articles
RSA Authentication Manager Upgrade Process RSA Release Notes for RSA Authentication Manager 8.8 RSA RADIUS Server service failed to start in the RSA Authentication Manager 8.1 Operations Console Microsoft Entra ID External MFA - Relying Party Configuration Using OIDC - RSA Ready Implementation Guide RSA Release Notes: Cloud Access Service and RSA Authenticators
Don't see what you're looking for?