Updating RSA SecurID Access SSL portal certificate can break Authenticate App tokencode - Authentication Manager integration
Originally Published: 2017-07-24
Last Modified: 2026-06-29
Article Number
Applies To
Issue
When attempting authentication, the Authentication Manager Authentication Activity Monitor shows:
RSA SecurID Access Authenticator Tokencode verification failed for user "<username>" Unexpected return code or unexpected exception occurred.
Cause
The Authenticate App<->Authentication Manager agent integration (both trusted realm for SecurID Access-only users and the Authenticate App integration for Authentication Manager users) depends on the Authentication Manager trusting the IDR root certificate. Changing the IDR root certificate will break either type of existing IDR<->Authentication Manager trust relationship.
Resolution
- If using a trusted realm for Authenticate App integration (SecurID Access-only users), delete the existing trusted realm in the Security Console and then re-run the manage-securid-access-trusts command line utility per Add an SecurID Deployment to RSA Authentication Manager as a Trusted Realm.
- If Authentication Manager users are using the Authenticate App to authenticate through SecurID Agents then load the IDR's new root certificate per step 6 of Configure RSA Authentication Manager to Handle Authenticate Tokencodes.
Notes
Related Articles
Can the Microsoft Integrated Windows Authentication (IWA) icon be hidden in the RSA SecurID Access Application Portal? 94Number of Views WTD 5.0.2 - WTD broken after adding IPs to whitelist 26Number of Views After updating the certificates for RSA Identity Governance & Lifecycle, WildFly reports error: JBAS015299: The KeyStore /… 418Number of Views RSA Via Lifecycle and Governance Appliance Updater 7Number of Views Envision: error upgrading enVision appliance : backupFiles etc/*.* FATAL ERROR: -2147024773 6Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Unable to login to RSA Authentication Manager Security Console as super admin Manual synchronization introduced in RSA Authentication Manager 8.2 Service Pack 1 patch 6 Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory How to verify NTP server synchronization is not working in RSA Authentication Manager 8.x
Don't see what you're looking for?