We've fixed the core issue, and are waiting for things to recover.
We've confirmed there is a problem, we're working to resolve it.
Customer might face login failures caused by an untrusted SSL certificate chain on legacy OS
Root Cause:
Certificate Rotation: Platform build 26.15-205 switched the .my.idaptive.app ,.id.cyberark.cloud certificate to a new CA chain rooted at GlobalSign Root R46.
Missing Root Trust: Microsoft added GlobalSign Root R46 to the Windows Trusted Root CTL on November 28, 2023. Any OS having EOL before that, will not receive this automatic update, causing SSL handshakes to fail with a "remote certificate is invalid" error.
Resolution: Download the GlobalSign Root R46 certificate (https://support.globalsign.com/ca-certificates/globalsign-root-certificates) Manually install it on the AD Proxy machine using the following command: Bash certutil -addstore Root GlobalSignRootR46.crt Restart the AD Proxy service, which will resolve the SSL handshake failures and will restore logins.
We’ll find your subscription and send you a link to login to manage your preferences.
We've sent you an email — please check your inbox and click the link to continue.
We’ll use your email to save your preferences so you can update them later.
Subscribe to other services using the bell icon on the subscribe button on the status page.
You’ll no long receive any status updates from Idira Status, are you sure?
{{ error }}
We’ll no longer send you any status updates about Idira Status.
Your email has been verified — you'll now receive status updates from Idira Status.