Authentication connection fails from RSA Identity Router to RSA Authentication Manager
Originally Published: 2017-12-13
Last Modified: 2026-10-07
Article Number
000040590
Applies To

RSA Product Set:  RSA ID Plus

RSA Product/Service Type:

RSA Cloud Access Service

RSA Identity Router

RSA Authentication Manager

 

Issue

Note: This article applies only to the Authentication connection from the Cloud Access Service (CAS) to Authentication Manager (AM) using the TCP Agent method. That is, where Identity Routers (IDRs) connect to AM's TCP 5500 port.  See Enable SecurID Token Users to Access Resources Protected by Cloud Access Service .   Specifically, this KB does not apply to:

  • Authentication connections from IDRs to AM using the REST Agent method (which is to the AM SecurID Authentication REST API port, default TCP 5555)
  • Notification connections from IDRs to AM
  • Connections from AM directly to the Cloud (Cloud Access Service)

 

When this issue occurs, all of the following symptoms will be seen:

 

  • All authentications with an authenticator assigned to a user in AM (e.g. a SecurID soft token) will fail.
  • Test the Authentication Manager Connection is unsuccessful.
  • In the Cloud Administration Console, page Platform > Identity Routers:  Authentication Manager's Authentication status is red/unhealthy for all IDRs.  To view AM status for an IDR on that page:
    1. Click the arrow to the left of an IDR's name to show its detailed status
    2. In the Status section for the IDR, click the arrow to the right of Authentication Manager to view Authentication status.

 

  • Either or both of the following types of FATAL/ERROR events will be logged to each IDRs' system log:
    • Cert validation and verification failed

2026-09-30/22:18:51.420/UTC [Thread-6395] FATAL com.rsa.authagent.authapi.v8.logger.b[?] - {validateSignCertwithRootCert} ConfigResponse Signing Cert Validation failed Certificate verify failed!
2026-09-30/22:18:51.420/UTC [Thread-6395] FATAL com.rsa.authagent.authapi.v8.logger.b[?] - {validateConfigResponse} ConfigResponse signing cert validation and verification failed: com.rsa.authagent.authapi.AuthAgentException: Signature Certificate Verification Failed:Certificate verify failed!
2026-09-30/22:18:51.420/UTC [Thread-6395] FATAL com.rsa.authagent.authapi.v8.logger.b[?] - {handleConfigUpdate} ConfigurationResponse(Init) - Response validation & verification failed
2026-09-30/22:18:51.420/UTC [Thread-6395] ERROR com.rsa.authagent.authapi.v8.logger.b[?] - Exception processing configuration data Exception processing configuration data Invalid config response from the server: Response validation & verification failed!
2026-09-30/22:18:51.420/UTC [Thread-6395] ERROR com.rsa.nga.sidproxy.AuthSessionFactoryManager[254] - unable to connect to the AM server

 

    • Key negotiation exchange failed

2026-09-30/21:57:44.813/UTC [Thread-202573] ERROR com.rsa.authagent.authapi.v8.logger.b[?] - Error in processing Authn request: connect exception processing key negotiation request: com.rsa.authmgr.commonagent.k: Key negotiation exchange failed. Server response was CANCELLED
2026-09-30/21:57:44.813/UTC [Thread-202573] ERROR com.rsa.authagent.authapi.v8.logger.b[?] - Error in initial AuthnReq/Rsp for serverTime.Error in processing Authn request: connect exception processing key negotiation request: com.rsa.authmgr.commonagent.k: Key negotiation exchange failed. Server response was CANCELLED
2026-09-30/21:57:44.813/UTC [Thread-202573] ERROR com.rsa.nga.sidproxy.AuthSessionFactoryManager[254] - unable to connect to the AM server

 

To check an IDR's system log, use either one of the following methods:

    • View the Identity Router System Log .  Note that this method only shows the last 1000 lines of the log, so you may have to access it a few times to see if any of the above messages are there.  Ensure IDR log level is set to Standard logging.  Debug will cause this view of the log to rotate very quickly making it hard to see the relevant events.
    • Generate and Download IDR Bundle Logs.  The log bundle will be a Zip file.   The IDR's system log is /var/log/symplified/symplified.log within the Zip file.  Up to ten older copies of that log will also be in the bundle, named symplified.log.1, symplified.log.2, etc.
Cause
The RSA Authentication Manager root certificate published to the Identity Router is no longer being used by Authentication Manager for secure agent communications. This can occur due to certain Authentication Manager database restore scenarios.
Resolution

Update the Authentication Manager agent communications root certificate and then publish a new sdconf.rec file to the Identity Router.
 

Note that instructions to retrieve the root certificate vary by browser type, the instructions below are for Chrome.

  1. Optional:  as with any AM configuration change, RSA recommends first creating a backup of AM.
  2. Browse to https://<YOUR_AUTH_MANAGER>:7002 and ignore the 404 error.
  3. Click on the three vertical dots in upper right and choose More tools > Developer tools.
  4. In the Tools window click the Security tab and then, from Security Overview click View certificate.
  5. In the Certificate popup, click the Certification Path tab and the top level root certificate
  6. Click the View Certificate button.
  7. Click the Details tab then the Copy to File button.
  8. Follow the wizard to save a .DER encoded certificate to a file.
  9. Now in the RSA Authentication Manager Security Console go to Setup > System Settings > Agents.
  10. Click on the link labeled To configure agents using IPV6, click here.
  11. In the Existing Certificate Details section click Choose File and select the just exported Authentication Manager root certificate file and then click Update.
  12. Now browse to Access > Authentication Agents > Generate Configuration File. 
  13. Generate and download a new AM_Config.zip file.
  14. Unzip the AM_Config.zip to extract the new sdconf.rec.
  15. Upload the new sdconf.rec file via the ID Plus Cloud Administration Console > Platform > Authentication Manager > Connection Settings menu and click Save.
  16. Click Publish Changes.  RSA recommends that Publish should be done during off-peak hours.  See section "When to Publish" on page Publishing Changes to the Identity Router and Cloud Access Service .
  17. After publish check that the issue is now fixed:
    • Test Connection should be successful
    • IDR status in the Cloud Administration Console should show the Authentication Manager Authentication connection is green/healthy for every IDR.
    • Users logging into applications protected by CAS should now be able to authenticate with SecurID tokens and other methods assigned to them in AM.

 

Notes
There are also Linux command line tools such as openssl and wget that can be used as an alternative to a browser for retrieving a site's SSL certificates.