Version Affected: 9.x (FileSync 4.0.9)
Overview
After configuring FileSync, the secondary server receives the configuration successfully, but sending a one-time passcode (OTP) by SMS or phone fails with Unable to Use Selected Registration Method.
Cause
The Cloud Client Certificate is either missing on the secondary server, or its private key permissions are incorrect. Although FileSync copies the primary certificate, the Cloud certificate can in some cases be different and not get copied along with it.
Resolution
- On the Primary server, open the Admin Console, go to the realm's System Info tab, and scroll to the WSE 3.0 Configuration section.
- Next to Client Cert Serial Nbr, click Select Certificate and note which certificate is selected.
- On the Secondary server, open the Certificates console (D:\MFCApp_Bin\Certificates Console.msc).
- Confirm that certificate is present on the secondary server.
- Right-click the certificate and select All Tasks > Manage Private Keys.
- Confirm Network Service and IIS AppPool\SecureAuth0Pool both have Read permission.
- If the realm uses Windows SSO, you may also need to add Authenticated Users to the permissions.
SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.
Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.
Comments
Please sign in to leave a comment.