Trusted Certificate Authorities for HFED or Trusted Headers Applications
When applications are added to RSA using either the HTTP Federation Proxy (HFED) or trusted headers method, the identity routers connect directly to the application web servers. If SSL is enabled for these applications, the application web server must have a valid certificate signed by a certificate authority (CA) that the identity routers trust.
The identity routers automatically trust valid certificates signed by:
- Most well-known CAs. For a complete list of the CAs automatically trusted by the identity routers, see List of Trusted Certificate Authorities for HFED and Trusted Headers Applications.
- The CA that signed the certificates uploaded to the Company Settings section of the Cloud Administration Console. For more information, see Configure Company Information and Certificates.
However, some companies use an internal or lesser-known CA to sign certificates used for their application web servers. To establish trust between the identity router and an internal CA, you can upload one or more CA certificates using the Cloud Administration Console.
The identity routers require that an SSL certificate is valid. Valid SSL certificates contain:
- A signature from a trusted CA
- A name that matches the web server's hostname
- An expiration date that has not passed
Concept Information
Certificates and Keys for Service Providers and Identity Providers for the SSO Agent
Related Tasks
Upload Certificates for Trusted Certificate Authorities
Delete a Trusted Certificate Authority Certificate
Reference Materials
List of Trusted Certificate Authorities for HFED and Trusted Headers Applications
Related Articles
Authentication Manager Log Messages (20121-20180) 44Number of Views Error: "The certificate file is not valid." when importing a SMS provider certificate AM8.1 - error importing certificate 127Number of Views Edit Session Lifetime Settings for Operating System Access 18Number of Views Replace a RADIUS Server Certificate 57Number of Views RSA Reminder - End of Product Support EOPS Date for RSA Identity Governance and Lifecycle 7.1.x was March 31 2021 44Number of Views
Trending Articles
An example of SSO using SAML and ADFS with RSA Identity Management and Governance 6.9.x RSA Authentication Manager 8.9 Release Notes (January 2026) RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide Passwordless Authentication in Windows MFA Agent for Active Directory – Quick Setup Guide RSA Authentication Manager Upgrade Process