Trusted Certificate Authorities for HFED or Trusted Headers Applications
When applications are added to RSA using either the HTTP Federation Proxy (HFED) or trusted headers method, the identity routers connect directly to the application web servers. If SSL is enabled for these applications, the application web server must have a valid certificate signed by a certificate authority (CA) that the identity routers trust.
The identity routers automatically trust valid certificates signed by:
- Most well-known CAs. For a complete list of the CAs automatically trusted by the identity routers, see List of Trusted Certificate Authorities for HFED and Trusted Headers Applications.
- The CA that signed the certificates uploaded to the Company Settings section of the Cloud Administration Console. For more information, see Configure Company Information and Certificates.
However, some companies use an internal or lesser-known CA to sign certificates used for their application web servers. To establish trust between the identity router and an internal CA, you can upload one or more CA certificates using the Cloud Administration Console.
The identity routers require that an SSL certificate is valid. Valid SSL certificates contain:
- A signature from a trusted CA
- A name that matches the web server's hostname
- An expiration date that has not passed
Concept Information
Certificates and Keys for Service Providers and Identity Providers for the SSO Agent
Related Tasks
Upload Certificates for Trusted Certificate Authorities
Delete a Trusted Certificate Authority Certificate
Reference Materials
List of Trusted Certificate Authorities for HFED and Trusted Headers Applications
Related Articles
Active Directory Password Capture Guide 21Number of Views List of Trusted Certificate Authorities for HFED and Trusted Headers Applications 72Number of Views RSA Authentication Manager SNMP 182Number of Views Cloud Administration Retrieve RSA DS100 OTP Credential API 23Number of Views Authentication Manager Log Messages (20121-20180) 50Number of Views
Trending Articles
RSA Authentication Manager 8.9 Release Notes (January 2026) RSA announces the availability of the RSA SecurID Hardware Appliance 230 based on the Dell PowerEdge R240 Server How to troubleshoot Oracle database ORA-04030 errors in RSA Identity Governance & Lifecycle RSA Authentication Manager Upgrade Process Microsoft SQL Server Collectors can no longer connect to the SQL Server database after upgrade to Microsoft SQL Server 201…