A more concise guide to updating Authentication Manager 8.x passwords
Originally Published: 2017-01-25
Article Number
Applies To
RSA Product Set: SecurID
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.x
Issue
- When trying to access the RSA Authentication Manager Security Console, the following error is seen:
Error: Authentication with user name/password failed
- When configuring the RADIUS server:
There was a problem processing your request.
Unexpected failure in configuring RADIUS server.
Unexpected failure in configuring RADIUS server.
Tasks
Tasks to complete:
- Access Authentication Manager primary via SSH or console.
- Navigate to /opt/rsa/am/utils.
- Run the restore-admin command to create a temporary admin user.
It is a good idea to create this admin account with the date appended to it, e. g., scadminNov132025
Do NOT include the -p <tempAdminPassword> value on the rsautil command line because the password will remain the the Linux history and special character combinations in a password can be interpreted instead of copied, resulting in unknown password. Let the utility prompt you for new <tempAdmin> password.
Resolution
I. How to reset/restore an unknown super admin password when you know the Operations Console administrator password
- SSH to the Authentication Manager primary server with the rsaadmin account and the operating system password created during deployment.
- Navigate to /opt/rsa/am/utils.
- Run the restore-admin utility. Here we are creating a new temp admin named scadminNov132025 (./rsautil restore-admin -u scadminNove132025). Note: The temp admin user must be unique, it cannot already exist
- When compete, there will be a message that the temporary admin is only valid for 24 hours.
- Login to the Security Console to update your original admin's password.
Notes
- It is good to avoid the following special characters:
& @ ~
- It is safer to enter the super admin password when prompted, as opposed to on the command line with the -p switch. See notes above.
- RSA Authentication Manager appliances have three main login accounts with passwords:
- The super admin account is used to login to the Security Console on port 7004. This account is stored in the internal database.
- The Operations Console admin account is used to login to the Operations Console on port 7072. This account is store in a system file.
- The rsaadmin account, aka the operating system account, for access into Linux.
- When you deploy an Authentication Manager 8.x server with Quick Setup you are creating these three accounts.
- The super admin account is replicated to all replicas through in-band replication.
- The Operations Console admin account is replicated to all replicas through Out Of Band (OOB) replication.
- The rsaadmin account is not replicated and could be unique to each primary and replica within a deployment realm. If you change it on the primary, you must change it on the replicas to keep it in sync.
- If you know at least two of these accounts and passwords, you can reset or recover the other one.
Related Articles
Update freezes when updating from RSA Authentication Manager 8.3 to Authentication Manager 8.3 patch 6 23Number of Views After updating the certificates for RSA Identity Governance & Lifecycle, WildFly reports error: JBAS015299: The KeyStore /… 338Number of Views Error 413--Request Entity Too Large, now system cannot be restarted when updating RSA Authentication Manager 8.3.0.… 585Number of Views Logging on to security console is very slow after updating to AM 8.5 157Number of Views How to Update the Root (Server) and Client Certificates in RSA Identity Governance & Lifecycle 2.15KNumber of Views
Trending Articles
How to recover the Application and AFX after an unexpected database failure in RSA Identity Governance & Lifecycle Troubleshooting AFX Connector issues in RSA Identity Governance & Lifecycle RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA Release Notes for RSA Authentication Manager 8.8 RSA Authentication Manager 8.9 Release Notes (January 2026)
Don't see what you're looking for?