KCA gives invalid signature when approving certificate request
Originally Published: 2003-06-05
Article Number
Applies To
Microsoft Windows 2000 Server SP3
Certificate enrollment with a PKCS#10
Issue
Request does not give error on older versions of KCA
Cause
Attributes { ATTRIBUTE:IOSet } ::= SET OF Attribute{{ IOSet }}
The "Attributes" field is not marked as OPTIONAL, so it must be present. However, a "SET OF" can include zero or more elements. So, a properly constructed Certificate Request with no attributes will include the encoded SET OF with a zero length for the contents.
Historically, some PKI products (including earlier versions of the Keon Certificate Authority) have misinterpreted the standard and omitted the "Attributes" field when no attributes were present. This causes interoperability issues, and the issues have been fixed in later versions of KCA.
When attempting to import into KCA a PKCS#10 Certificate Request that omits the "Attributes" field, an error will be returned.
Resolution
Workaround
KCA 6.5 validates certificate request where older versions did not
Related Articles
Cannot log on to Microsoft Windows 8.1 with RSA Authentication Agent 7.3.x for Windows after Windows update is applied usi… 56Number of Views RSA Via Lifecycle and Governance access control setting for web services gets reset to default on server restart 90Number of Views How to check/restart the Webtier services deployed on a Linux machine in RSA Authentication Manager 8.x 1.04KNumber of Views How to open a case with Customer Asset Management (CAM) team for Authentication Manager token media replacement or license… 30Number of Views AFX Server remains in a 'Not running' State, afx status shows 'timed out waiting for AFX applications to start' and esb.AF… 1.12KNumber of Views
Trending Articles
Troubleshooting RSA SecurID Access Identity Router to RSA Authentication Manager test connection failures RSA SecurID Software Token 5.0.2 Downloads for Microsoft Windows RSA Authentication Manager 8.9 Release Notes (January 2026) Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory RSA Authentication Manager 8.8 Setup and Configuration Guide
Don't see what you're looking for?