Certificate verification failed and ConfigResponse is not valid for RSA Authentication Agent API 8.5 and later
Originally Published: 2016-09-16
Article Number
Applies To
RSA Product/Service Type: Authentication Agent API for C or Java
RSA Version/Condition: 8.5 or later, 8.6, includes RSA Authentication Agent 8.0 for Web configured for TCP authentication
Platform: Linux
Issue
This article is relevant to authentication to RSA Authentication Manager server using TCP port 5500, not UDP 5500.
Any attempt to authenticate or communicate with the Authentication Manager server fails in the agent log.error SignatureVerifier.cpp 247 The certificate verification failed
error AgentConfigHandler.cpp 135 ConfigResponse is not valid
When authentication is initiated from RSA Authentication Agent API 8.5 or later, the ACEInitialize program reads the sdconf.rec to:
- Create bootstrap.xml & root.cer based on what is in sdconf.rec.
- Verify the certificate.
- Negotiate to exchange message keys.
Cause
Scroll down to the bottom of the IPv4/IPv6 Agent page to view the Existing Certificate Details.
If you restore a backup from another Authentication Manager 8.x server, you will import a different Agent Certificate, which will not be recognized by the Authentication Manager API 8.5 Agent.
Even if the two servers in this example were both Quick Setup with same name and IP, unless they are VM clones they do not have the same agent certificate.
Resolution
- Import the original agent certificate back into the IPv4/IPv6 page.
- From the Security Console select Setup > System.
- On left is Agents.
- Click IPv6 and then click the Choose File button at the bottom of the page.
- Generate and download a new sdconf.rec file.
- From the Security Console select Access > Authentication Agents > Generate Configuration File).
- Download the AM_Config.zip and extract the sdconf.rec.
- On the agent, delete the agent files including bootstrap.xml and root.cer
- Place the new sdconf.rec file on the agent.
- Try to authenticate again
The RSA Authentication Manager API 8.5 files are located in /var/ace by default, or configured in the rsa_api.properties file
Workaround
Related Articles
Security Levels and Identity Router Connection Ciphers 100Number of Views AFX Connector "Accepted DH prime length is 2048 or higher" message in SecurID Governance & Lifecycle 182Number of Views Web Server certificate verification failed with RSA Authentication Agent 8.0 for Web for Apache 76Number of Views Unable to SSH to IdR with Error "Host key verification failed" 53Number of Views Configure Identity Router Security Levels 147Number of Views
Trending Articles
RSA Authentication Manager Upgrade Process How to Update the Root (Server) and Client Certificates in RSA Identity Governance & Lifecycle RSA Authenticator 6.2.2 for Windows Administrator Guide RSA SecurID software token .sdtid file fails to import into RSA SecurID Software Token 5.0 for Windows RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide
Don't see what you're looking for?