Version Affected: All
Overview
When downloading a PFX certificate and attempting to install it, an error states: This file is invalid for use as the following: Personal Information Exchange.
The downloaded PFX file is also much smaller than expected — around 2KB, compared to a healthy PFX file's roughly 8KB.
Cause
The downloaded file isn't an actual PFX certificate. The root cause is that the IdP server was unable to contact the SecureAuth Certificate Authority (CA) server to request a real PFX file at the time of enrollment.
Resolution
- Find the Certificate URL used by the IdP server, in the SecureAuth Cloud Services section of the System Info tab for the PFX Certificate realm.
- Open that URL directly in a browser to test connectivity. A working connection looks similar to:
- If a different page loads instead — a 404, a timeout page, and so on — the URL can't be reached, so a certificate request can't be made. Investigate the following:
- Required network ports closed on the firewall — confirm the ports required for your IdP version are open, per SecureAuth's Cloud Services connectivity documentation.
- Incorrect proxy settings — check IIS Application Request Routing, browser/computer proxy settings, and the realm's System Info > Proxy Server Configuration.
- An incorrect URL entered in the realm's Certificate URL field — confirm it against the Cloud Services connectivity documentation.
- A correct URL that isn't resolving to an active CA server — browse to the base URL (for example, https://us-cloud.secureauth.com) and hover over the browser tab to see which CA server it connects to:
If this looks wrong, open a case with SecureAuth Support and provide this information, along with all other relevant details, in the case.
SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.
Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.
Comments
Please sign in to leave a comment.