RSA Product/Service Type: Authentication Manager & MFA Agent for Microsoft Windows
RSA Version: 8.x (Authentication Manager) & 2.x (MFA Agent for Microsoft Windows)
Users are unable to authenticate with the RSA MFA Agent for Windows configured with the Authentication Manager.
Testing authentication with the "RSA MFA Agent Test Authentication" utility fails and results in an "Unsuccessful connection to RSA" or "Unsuccessful connection to SecurID Access" message.
The "RsaMfaAgentTestAuthentication(RSA_MFA_Agent_Test_Authentication).log" file includes the following error message:
[E] [RSA.Authentication.Connection.ConnectionHandler.ServerCertificateValidator] Error in Server certificate validation: Certificate Name Mismatch
but the hostname in the Authentication Manager (AM) server certificate used for the communication between the AM server and MFA Agent matches the hostname of the AM server, hence the certificate name does not actually mismatch.
It was found that there was an IP address included as a Subject Alternative Name (SAN) in the Authentication Manager server's Console Certificate and that this was causing the issue.
Replace the Authentication Manager Console Certificate with a server certificate that does not include an IP address as a Subject Alternative Name.
Replacing the Authentication Manager (AM) Console Certificate also changes the certificates that AM uses on port 5555 TCP, which is the port that REST-based agents, such as the MFA Agent for Windows, use when communicating with AM.
Related Articles
'Host name configured is not listed in subject alternative names of certificate' and 'LDAP_CERT_HOSTNAME_MISMATCH_MSG_SHOR… 352Number of Views Server certificate validation error when trying to authenticate using the RSA Authentication Agent 2.0 for AD FS 324Number of Views RSA MFA Agent for Windows will not run due to error "This module is blocked from loading into the Local Security Authority" 850Number of Views Node secret mismatch error when authenticating with an RSA Authentication Agent for Windows when NetMotion is installed 266Number of Views Mandatory Certificate Upgrade Required by 6th October 2025 for RSA MFA Agent for PAM, RSA MFA Agent for Apache, and Third … 376Number of Views
Trending Articles
RSA Authentication Manager Upgrade Process How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Download RSA SecurID Access Cloud User Event audit logs using Cloud Administration REST API CLU RSA Authentication Manager 8.9 Release Notes (January 2026) AFX Server Fails to Start with 'Could Not Build a Validated Path' and 'Timed Out Waiting for AFX Applications to Start' in…