Users are unable to authenticate to external Self-Service Portal (SSP) after RSA Authentication Manager Integration Service certificate change for RSA Authentication Manager Prime Kit
Originally Published: 2020-06-08
Last Modified: 2023-09-22
Article Number
Applies To
RSA Product/Service Type: Authentication Manager, Authentication Manager Prime
Platform: Linux
Issue
2020-06-09T00:06:37,363+0200,com.rsa.pso.selfservice.web.LoginActionBean,62, ERROR,Exception: auth /com.rsa.pso.services.ServiceException: com.rsa.pso.services.ServiceException: org.springframework.web.client.ResourceAccessException: I/O error on GET request for "https://prime.testlab.com:8443/rsa-endpoints/endpoints": sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target; nested exception is javax.net.ssl.SSLHandshakeException: sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target
Cause
Resolution
- Log in to the external SSP server.
- Run the following command against the server FQDN and port reported in the error to retrieve the connection certificate:
# openssl s_client -connect prime.testlab.com:8443 -showcerts CONNECTED(00000003) --- Certificate chain 0 s:/C=EG/ST=EG/L=Cairo/O=RSA/OU=RSA/CN=prime.testlab.com i:/C=EG/ST=EG/L=Cairo/O=RSA/OU=RSA/CN=prime.testlab.com -----BEGIN CERTIFICATE----- MIIDZTCCAk2gAwIBAgIEc3QN9DANBgkqhkiG9w0BAQsFADBjMQswCQYDVQQGEwJF RzELMAkGA1UECBMCRUcxDjAMBgNVBAcTBUNhaXJvMQwwCgYDVQQKEwNSU0ExDDAK BgNVBAsTA1JTQTEbMBkGA1UEAxMScHJpbWUuc2FiZXJsYWIuY29tMB4XDTE5MDQw NTA4MzUxMVoXDTE5MDcwNDA4MzUxMVowYzELMAkGA1UEBhMCRUcxCzAJBgNVBAgT AkVHMQ4wDAYDVQQHEwVDYWlybzEMMAoGA1UEChMDUlNBMQwwCgYDVQQLEwNSU0Ex GzAZBgNVBAMTEnByaW1lLnNhYmVybGFiLmNvbTCCASIwDQYJKoZIhvcNAQEBBQAD ggEPADCCAQoCggEBAJ9wm2Qo9lsQ4CCu5pb9OJZjgCEQztmmjs80mMjPD8boVrZ5 GQOVQNjBIqXCGTUHi/SfCzDkCU7P71zn70/iZm1EbxelnuFJxaulVilsabQRjwXq jNdMDntKpKmZaYI5nPBh5IdDAbUCpZaYt2Lj4RT8ABPeTrDoHmz2tTPBnc93olHl eZCU2KqFtLouVT7QSxOdp/rduNwApOoYEH/Gk/LF5olFSRXke2y/QmOnjDNEsC3/ 6KtmvFDVa/028xrT0MJoLNF8rAFGPWd7m9V0nVWZ4I2uCWdQc5KCwoIA9QTNxoFG pvG0bxAz/WPHfIUav2tmM7O/xluWYttt8AUPhh8CAwEAAaMhMB8wHQYDVR0OBBYE FMBZNx5egr02A7sHMHjzqoXjoVZ1MA0GCSqGSIb3DQEBCwUAA4IBAQCADyU+BKvL Clbg0Ht9EZ1W7wFBdV1Hw/JDyi+ZHHYdd8ZQZJcxLEoeVl2N/jbRgTh5DLQnsqu8 kAWmrE/vEroSSwRUykOv4sarMfqvkmTUB1PRDHRbEWA+1cjjt5cwMWsP48OgUUSm ykFV7xxuc32i8M93+VuL03tK2/iRStBvtNHIU1hgmFIg3f8XBQO9fh41Z3CbK0yq A+Ts5EsxLNutV+RW3EWZq6jP1+FUcJre6Tgzbb4QVJrtlYg4UDWeXHae/4nQihH0 IjPiyFdwBeXje6rF6yUNOc1WAWL4LgOnfn/iXQD0Jegj60YE2JPQFNVviXLutCY0 mJt4E6qu/qer -----END CERTIFICATE----- --- Server certificate subject=/C=EG/ST=EG/L=Cairo/O=RSA/OU=RSA/CN=prime.testlab.com issuer=/C=EG/ST=EG/L=Cairo/O=RSA/OU=RSA/CN=prime.testlab.com ---
- Create a new certificate file:
touch /tmp/amis.cer
- Open the new /tmp/amis.cer in a text editor and copy any certificate of the chain into that file:
-----BEGIN CERTIFICATE----- MIIDZTCCAk2gAwIBAgIEc3QN9DANBgkqhkiG9w0BAQsFADBjMQswCQYDVQQGEwJF RzELMAkGA1UECBMCRUcxDjAMBgNVBAcTBUNhaXJvMQwwCgYDVQQKEwNSU0ExDDAK BgNVBAsTA1JTQTEbMBkGA1UEAxMScHJpbWUuc2FiZXJsYWIuY29tMB4XDTE5MDQw NTA4MzUxMVoXDTE5MDcwNDA4MzUxMVowYzELMAkGA1UEBhMCRUcxCzAJBgNVBAgT AkVHMQ4wDAYDVQQHEwVDYWlybzEMMAoGA1UEChMDUlNBMQwwCgYDVQQLEwNSU0Ex GzAZBgNVBAMTEnByaW1lLnNhYmVybGFiLmNvbTCCASIwDQYJKoZIhvcNAQEBBQAD ggEPADCCAQoCggEBAJ9wm2Qo9lsQ4CCu5pb9OJZjgCEQztmmjs80mMjPD8boVrZ5 GQOVQNjBIqXCGTUHi/SfCzDkCU7P71zn70/iZm1EbxelnuFJxaulVilsabQRjwXq jNdMDntKpKmZaYI5nPBh5IdDAbUCpZaYt2Lj4RT8ABPeTrDoHmz2tTPBnc93olHl eZCU2KqFtLouVT7QSxOdp/rduNwApOoYEH/Gk/LF5olFSRXke2y/QmOnjDNEsC3/ 6KtmvFDVa/028xrT0MJoLNF8rAFGPWd7m9V0nVWZ4I2uCWdQc5KCwoIA9QTNxoFG pvG0bxAz/WPHfIUav2tmM7O/xluWYttt8AUPhh8CAwEAAaMhMB8wHQYDVR0OBBYE FMBZNx5egr02A7sHMHjzqoXjoVZ1MA0GCSqGSIb3DQEBCwUAA4IBAQCADyU+BKvL Clbg0Ht9EZ1W7wFBdV1Hw/JDyi+ZHHYdd8ZQZJcxLEoeVl2N/jbRgTh5DLQnsqu8 kAWmrE/vEroSSwRUykOv4sarMfqvkmTUB1PRDHRbEWA+1cjjt5cwMWsP48OgUUSm ykFV7xxuc32i8M93+VuL03tK2/iRStBvtNHIU1hgmFIg3f8XBQO9fh41Z3CbK0yq A+Ts5EsxLNutV+RW3EWZq6jP1+FUcJre6Tgzbb4QVJrtlYg4UDWeXHae/4nQihH0 IjPiyFdwBeXje6rF6yUNOc1WAWL4LgOnfn/iXQD0Jegj60YE2JPQFNVviXLutCY0 mJt4E6qu/qer -----END CERTIFICATE-----
- Import the certificate into the truststore.jks. Enter the file password when prompted.
/opt/rsa/primekit/java/latest/bin/keytool -import -alias amis \ -file /tmp/amis.cer -keystore /opt/rsa/primekit/certificates/truststore.jks Enter keystore password: <Enter keystore password>
- When prompted to trust the certificate, type yes and press Enter.
Trust this certificate? [no]: yes Certificate was added to keystore
- Restart the external SSP service:
service tomcat-ssp restart
Notes
- The RSA Authentication Manager Prime Kit installation directory will differ from one environment to the other. The administrator should be aware of the installation directory. However, the subdirectories and file names will not change.
- Restarting the service steps will differ from one environment to the other. The administrator should know how to restart a certain service in their environment.
Related Articles
Unable to find valid certification path error when logging on to Help Desk Admin Portal (HDAP) and Self-Service Portal (SS… 512Number of Views Unauthorized error when logging in to RSA Authentication Manager Help Desk Admin Portal (HDAP) or Self-Service Portal (SSP… 115Number of Views QR code not displaying in the RSA Authentication Manager Prime Self-Service Portal (SSP) 357Number of Views RSA Authentication Manager – Unable to Add or Manage Users with Error “The specified ID is already in use” 5.26KNumber of Views Users unable to authenticate with LDAP password on both Security Console and Self-Service Console for RSA Authentication M… 243Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Troubleshooting AFX Connector issues in RSA Identity Governance & Lifecycle Authentication Manager Security Console and Operations Console Inaccessible After Certificate Update How to Forward RSA Authentication Manager 8.4 or Later Logs to Multiple Syslog Servers Using rsyslog RSA Authentication Manager 8.9 Patches and Hotfixes Readme
Don't see what you're looking for?