Web Server certificate verification failed with RSA Authentication Agent 8.0 for Web for Apache
Originally Published: 2018-01-10
Last Modified: 2023-11-30
Article Number
Applies To
RSA Product/Service Type: Authentication Agent for Web
RSA Version/Condition: 8.x
Platform: Apache Web Server
Issue
118-00-03 12:38:23 4294967295.3952.2701068096 [E] error SignatureVerifier.cpp 248 The certificate verification failed
118-00-03 12:38:23 4294967295.3952.2701068096 [V] verbose SignatureVerifier.cpp 258 Leaving validateConfiguration()
Cause
If, at some point, the RSA Authentication Manager server name changed after its initial deployment, that certificate doesn't change (for backward compatibility) and at that point any new TCP agent when trying to connect it finds that the Authentication Manager server has a different name other than the one in the subject name in the current certificate, thus failing.
Resolution
To get the certificate and update it
- On the primary Authentication Manager server, open Internet Explorer and go to https://<primary hostname >:7002.
Port 7002 is used for communication between an Authentication Manager primary and replica instances and for communication between replica instances (for replay detection).
- Click on the Certificate error.
- Choose the top certificate and click View Certificate.
- Click the Copy To File... button.
- Click Next.
- Click Next > again. Be sure to leave the DER encoding format.
- Enter a name to save the DER-encoded root certificate.
- Login to the Security Console and select Setup > System Settings.
- Under the heading for Authentication Settings, click Agents.
- On the top left of the page click the link where it says To configure agents using IPv6, click here.
- Scroll down to the section on Existing Certificate Details.
- Click the button next to Import Certificate of the New Primary Server that is labeled Choose File.
- A common dialog box will open. Browse to the saved certificate, select it and click Open.
- When done, click Update.
- Generate a new configuration file (sdconf.rec) for the agent by selecting Access > Authentication Agents > Generate Configuration File > Generate Config File.
- Replace the existing sdconf.rec on the agent with the newly generated sdconf.rec.
Notes
Related Articles
How to Install a Third Party Certificate into RSA enVision 264Number of Views How to Install a Third Party Certificate into enVision 12Number of Views Collecting logs in RSA Authentication Manager 8.x via SSH 469Number of Views Quick Setup Guide - Configure IdP-Initiated SAML for Third-Party Application 101Number of Views Collector or AFX Connector or JSP or Collector or Connector TEST fails with "PKIX path building failed" in RSA Governance … 477Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Unable to login to RSA Authentication Manager Security Console as super admin Manual synchronization introduced in RSA Authentication Manager 8.2 Service Pack 1 patch 6 Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory How to verify NTP server synchronization is not working in RSA Authentication Manager 8.x
Don't see what you're looking for?