Error "Key negotiation exchange failed. Server response was CANCELLED" with RSA Authentication Agent API 8.5 and later
Originally Published: 2020-06-01
Article Number
Applies To
RSA Product/Service Type: RSA Authentication Agent API
RSA Version/Condition: 8.5 and later
Issue
com.rsa.authagent.authapi.AuthAgentException: Error in initial AuthnReq/Rsp for serverTime.Error in processing Authn request: connect exception processing key negotiation request: com.rsa.authmgr.commonagent.h: Key negotiation exchange failed. Server response was CANCELLED
com.rsa.authagent.authapi.AuthAgentException: com.rsa.authagent.authapi.AuthAgentException: Error in initial AuthnReq/Rsp for serverTime.Error in processing Authn request: connect exception processing key negotiation request: com.rsa.authmgr.commonagent.h: Key negotiation exchange failed. Server response was CANCELLED
at com.rsa.authagent.authapi.AuthSessionFactory.a(AuthSessionFactory.java)
at com.rsa.authagent.authapi.AuthSessionFactory.getInstance(AuthSessionFactory.java)
at sample.AuthUser.<init>(AuthUser.java:32)
at sample.AuthUser.main(AuthUser.java:62)
Cause
This is the certificate the AM uses in the communication with the TCP Agents. If this certificate is not correct then the authentication will fail with the above error.
The certificate found in the above page should be the same as the one we can export after accessing https://AM fully qualified domain name:7002
Resolution
- Using Google Chrome, browse to https://AM fully qualified domain name:7002
- Click on the lock icon in the browser address bar.
- Click on Certificate.
- Click the Certification Path tab.
- Double-click on the top-level (root, very first) certificate in the list.
- Click on Details tab, then Copy to File...
- Click Next, then check the Second Option Base-64 encoded X.509 output format (.CER)
- Click Next, then click Browse to choose the location and give it any name, such as root then Click Save.
- Click Next then Finish, you'll find the exported certificate in the location chosen in Step 8
- Browse to Security Console –> Setup –> System Settings --> Agents, then click on To configure agents using IPV6, click here.
- Scroll down under Existing Certificate Details, click on the Choose File Option then browse to the certificate we just exported then Click Update.
Notes
If the Authentication Manager is on 8.2 SP1 till 8.2 SP1 Patch 4, you can still see the above errors even after you complete the steps in the Resolution. This is because there is a bug on AM 8.2 SP1 where it doesn't communicate with the certificate we export from the 7002 port that it should use, it communicates with the Console Certificate. The environments that will see this are the environments that have replaced the default self-signed certificate for the consoles with another certificate.
There are 3 workarounds to solve this:
- Upgrade to AM 8.2 SP1 Patch 5.
- Revert the Console Certificate to use the default self-signed certificate using below steps or normally from the Operations console: Reverting back to the RSA self-signed default certificates on Authentication Manager
- Follow the exact steps in the resolution here, but in step 1 rather than browsing to https://AM fully qualified domain name:7002, browse to either the Security Console or the Operations Console of the Authentication Manager and export the certificate from there, then complete the same steps as they are.
Related Articles
RACF-SSH based connector fails with Unable to Negotiate Key Exchange error in RSA Governance & Lifecycle 20Number of Views Error handling Access Fulfillment Express (AFX) primary request in RSA Identity Governance & Lifecycle 90Number of Views Microsoft Exchange 2010 AFX Connector Enable-mailbox command fails with 'Value cannot be null' in RSA Identity Governance … 97Number of Views In RSA Identity Governance & Lifecycle 7.0.1, Review Reminder email sent out before configured period has elapsed 10Number of Views Running Data_Retention_Pkg.Prune_Access_Request gets ORA-01722: invalid number in RSA Identity Management and Governance 103Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device RSA Authentication Manager 8.9 Patches and Hotfixes Readme RSA SecurID software token .sdtid file fails to import into RSA SecurID Software Token 5.0 for Windows Download RSA SecurID Access Cloud User Event audit logs using Cloud Administration REST API CLU Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory
Don't see what you're looking for?