Connection fails to Cloud Authentication Service when connecting through a proxy server from RSA Authentication Manager to the RSA SecurID Access Cloud Authentication Service
Originally Published: 2020-04-23
Article Number
Applies To
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.4 patch 4 and above
Issue
Failed to register to the Cloud Authentication Service
Connection failed to Cloud Authentication Service
Connection failed to Cloud Authentication Service
The /opt/rsa/am/server/logs/imsTrace log from the RSA Authentication Manager server shows:
2020-04-17 14:22:07,977, [[ACTIVE] ExecuteThread: '9' for queue: 'weblogic.kernel.Default (self-tuning)'],
(CASApiAdminOperationsImpl.java:624), trace.com.rsa.internal.admin.casapimgmt.impl.CASApiAdminOperationsImpl, INFO,
<Authentication Manager hostname>,,,,processRequest: casRegistration
2020-04-17 14:22:08,052, [[ACTIVE] ExecuteThread: '9' for queue: 'weblogic.kernel.Default (self-tuning)'],
(CASApiAdminOperationsImpl.java:644), trace.com.rsa.internal.admin.casapimgmt.impl.CASApiAdminOperationsImpl, ERROR,
<Authentication Manager hostname>,,,,Failed to initialize connection
javax.net.ssl.SSLException: Certificate not verified
Caused by: com.rsa.sslj.x.aL: Certificate not verified.
at com.rsa.sslj.x.bh.a(Unknown Source)
at com.rsa.sslj.x.bh.a(Unknown Source)
at com.rsa.sslj.x.bh.a(Unknown Source)
... 86 more
Caused by: java.security.cert.CertificateException: the certificate chain is not trusted, Could not validate path.
at com.rsa.sslj.x.ck.a(Unknown Source)
at com.rsa.sslj.x.ck.checkServerTrusted(Unknown Source)
at com.rsa.sslj.x.aF.a(Unknown Source)
... 89 more
2020-04-17 14:22:08,058, [[ACTIVE] ExecuteThread: '9' for queue: 'weblogic.kernel.Default (self-tuning)'],
(CASApiAdminOperationsImpl.java:406), trace.com.rsa.internal.admin.casapimgmt.impl.CASApiAdminOperationsImpl, ERROR,
<Authentication Manager hostname>,,,,Unable to set connection
com.rsa.admin.casapimgt.CASConnectionManagerException: Authentication Manager cannot connect to
Cloud Authentication Service. Connection failed.
(CASApiAdminOperationsImpl.java:624), trace.com.rsa.internal.admin.casapimgmt.impl.CASApiAdminOperationsImpl, INFO,
<Authentication Manager hostname>,,,,processRequest: casRegistration
2020-04-17 14:22:08,052, [[ACTIVE] ExecuteThread: '9' for queue: 'weblogic.kernel.Default (self-tuning)'],
(CASApiAdminOperationsImpl.java:644), trace.com.rsa.internal.admin.casapimgmt.impl.CASApiAdminOperationsImpl, ERROR,
<Authentication Manager hostname>,,,,Failed to initialize connection
javax.net.ssl.SSLException: Certificate not verified
Caused by: com.rsa.sslj.x.aL: Certificate not verified.
at com.rsa.sslj.x.bh.a(Unknown Source)
at com.rsa.sslj.x.bh.a(Unknown Source)
at com.rsa.sslj.x.bh.a(Unknown Source)
... 86 more
Caused by: java.security.cert.CertificateException: the certificate chain is not trusted, Could not validate path.
at com.rsa.sslj.x.ck.a(Unknown Source)
at com.rsa.sslj.x.ck.checkServerTrusted(Unknown Source)
at com.rsa.sslj.x.aF.a(Unknown Source)
... 89 more
2020-04-17 14:22:08,058, [[ACTIVE] ExecuteThread: '9' for queue: 'weblogic.kernel.Default (self-tuning)'],
(CASApiAdminOperationsImpl.java:406), trace.com.rsa.internal.admin.casapimgmt.impl.CASApiAdminOperationsImpl, ERROR,
<Authentication Manager hostname>,,,,Unable to set connection
com.rsa.admin.casapimgt.CASConnectionManagerException: Authentication Manager cannot connect to
Cloud Authentication Service. Connection failed.
Cause
Resolution
- Configure the proxy server to use SSL Passthrough rather than SSL Termination for the connection from RSA Authentication Manager to the Cloud Authentication Service,
- Import the root certificate from the proxy server into each RSA Authentication Manager instance in the environment that communicates with the Cloud Authentication Service through the proxy. For steps, contact RSA Customer Support.
Related Articles
RSA Authentication Manager Administration Server with Operations Console service fails to start when restarted from the SS… 1.66KNumber of Views Identity router (IDR) registration fails with error cannot connect to Cloud Authentication Service for RSA SecurID Access 760Number of Views Connection to Cloud Authentication service via Security Console fails with an error; ""Failed to register to the Cloud Aut… 447Number of Views Mandatory Certificate Upgrade Required by 6th October 2025 for RSA MFA Agent for PAM, RSA MFA Agent for Apache, and Third … 326Number of Views The License/serial number being installed does not match the license/serial number stored on the server when installing an… 2.8KNumber of Views
Trending Articles
RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide RSA Release Notes for RSA Authentication Manager 8.8 Troubleshooting RSA MFA Agent for Microsoft Windows How to download and install the AFX Server Archive in RSA Identity Governance & Lifecycle The Template ({Connector Template Name}) has missing file content error when creating AFX Connectors in RSA Identity Gover…
Don't see what you're looking for?