RSA Product/Service Type: Authentication Manager & MFA Agent for Microsoft Windows
RSA Version: 8.x (Authentication Manager) & 2.x (MFA Agent for Microsoft Windows)
Users are unable to authenticate with the RSA MFA Agent for Windows configured with the Authentication Manager.
Testing authentication with the "RSA MFA Agent Test Authentication" utility fails and results in an "Unsuccessful connection to RSA" or "Unsuccessful connection to SecurID Access" message.
The "RsaMfaAgentTestAuthentication(RSA_MFA_Agent_Test_Authentication).log" file includes the following error message:
[E] [RSA.Authentication.Connection.ConnectionHandler.ServerCertificateValidator] Error in Server certificate validation: Certificate Name Mismatch
but the hostname in the Authentication Manager (AM) server certificate used for the communication between the AM server and MFA Agent matches the hostname of the AM server, hence the certificate name does not actually mismatch.
It was found that there was an IP address included as a Subject Alternative Name (SAN) in the Authentication Manager server's Console Certificate and that this was causing the issue.
Replace the Authentication Manager Console Certificate with a server certificate that does not include an IP address as a Subject Alternative Name.
Replacing the Authentication Manager (AM) Console Certificate also changes the certificates that AM uses on port 5555 TCP, which is the port that REST-based agents, such as the MFA Agent for Windows, use when communicating with AM.
Related Articles
Okta - SAML My Page SSO Configuration - RSA Ready Implementation Guide 48Number of Views How to temporarily enable HTTP login to RSA Identity Governance & Lifecycle 426Number of Views RSA Governance & Lifecycle Recipes: Overview - User Accounts 27Number of Views RSA Identity Governance and Lifecycle7.0.2 installation with remote database fails with "Invalid Username/Password" in the… 203Number of Views AFX Server and Connector failures if AFX is started as the root user in RSA Identity Governance & Lifecycle 724Number of Views
Trending Articles
RSA announces the availability of the RSA SecurID Hardware Appliance 230 based on the Dell PowerEdge R240 Server RSA Authentication Manager 8.9 Release Notes (January 2026) RSA-2026-07: RSA Identity Router Security Update for Third-Party Component Vulnerabilities How to troubleshoot Oracle database ORA-04030 errors in RSA Identity Governance & Lifecycle Artifacts to gather in RSA Identity Governance & Lifecycle