The agent appears to be establishing twice as many connections to the aserver as required.
Connections to the aserver are being blocked by a firewall.
The ctagent.log file shows a large number of CT_SERVER_TIMED_OUT messages occurring at an interval equivalent to the cleartrust.agent.auth_server_pool_refresh value.
Mar 23, 2005 08:12:47 PM EST - [2944] - <Critical> - Critical error: CT_SERVER_TIMED_OUT
In a typical deployment only the "cleartrust.agent.dispatcher_list" parameter needs to be set. The "cleartrust.agent.auth_server_list" parameter should not be set at the same time. The agent will get a full list of available aservers from the dispatcher.
If the auth_server_list is populated in addition to the dispatcher list the connection pool will be established with additional connections to the duplicate aservers. This can cause unpredictable load balancing behaviour in DISTRIBUTED mode.
If the agent is in STANDARD mode the additional aservers connections will typically be idle and are usually disabled by the firewall idle timeout rule between the aserver. The CT_SERVER_TIMED_OUT messages are the result of the agent attempting to update the connection pool on the duplicate set of aservers. If these are duplicate connections, by definition they will be idle connections and will have been disabled by the firewall. If a firewal lis in place refer to solutions a14661 a28615
See solution RSA Cleartrust Agent 4.6 reports twice the numbers of authservers connected as there are physical servers
Related Articles
DSA-2019-134: RSA Identity Governance and Lifecycle Product Security Update for Multiple Vulnerabilities 9Number of Views DSA-2020-066: RSA Authentication Manager Stored Cross-Site Scripting 8Number of Views DSA-2020-052: RSA Authentication Manager Multiple Vulnerabilities 8Number of Views RSA SecurID Authenticator 6.1.1 for Windows Release Notes 13Number of Views OAuth 2.0-Based Permissions for the Cloud Administration APIs 73Number of Views
Trending Articles
Downloading RSA Authentication Manager license files or RSA Software token seed records RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory Mandatory Certificate Upgrade Required by 6th October 2025 for RSA MFA Agent for PAM, RSA MFA Agent for Apache, and Third … RSA Authentication Manager 8.9 Release Notes (January 2026)