Trusted Certificate Authorities for HFED or Trusted Headers Applications
When applications are added to RSA using either the HTTP Federation Proxy (HFED) or trusted headers method, the identity routers connect directly to the application web servers. If SSL is enabled for these applications, the application web server must have a valid certificate signed by a certificate authority (CA) that the identity routers trust.
The identity routers automatically trust valid certificates signed by:
- Most well-known CAs. For a complete list of the CAs automatically trusted by the identity routers, see List of Trusted Certificate Authorities for HFED and Trusted Headers Applications.
- The CA that signed the certificates uploaded to the Company Settings section of the Cloud Administration Console. For more information, see Configure Company Information and Certificates.
However, some companies use an internal or lesser-known CA to sign certificates used for their application web servers. To establish trust between the identity router and an internal CA, you can upload one or more CA certificates using the Cloud Administration Console.
The identity routers require that an SSL certificate is valid. Valid SSL certificates contain:
- A signature from a trusted CA
- A name that matches the web server's hostname
- An expiration date that has not passed
Concept Information
Certificates and Keys for Service Providers and Identity Providers for the SSO Agent
Related Tasks
Upload Certificates for Trusted Certificate Authorities
Delete a Trusted Certificate Authority Certificate
Reference Materials
List of Trusted Certificate Authorities for HFED and Trusted Headers Applications
Related Articles
Authentication Manager Log Messages (20121-20180) 44Number of Views Edit Session Lifetime Settings for Operating System Access 18Number of Views Remote Agent fails to start with 'Could not load certificate' error in RSA Identity Governance & Lifecycle 302Number of Views Replace a RADIUS Server Certificate 57Number of Views AFX Server fails to start in RSA Identity Governance & Lifecycle 411Number of Views
Trending Articles
How to recover the Application and AFX after an unexpected database failure in RSA Identity Governance & Lifecycle Troubleshooting AFX Connector issues in RSA Identity Governance & Lifecycle RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA Release Notes for RSA Authentication Manager 8.8 RSA Authentication Manager 8.9 Release Notes (January 2026)