AM 8.6 RADIUS Pre-Migration Script FAILURES: Error while exporting the trusted root certificate
Article Number
Applies To
See
UPDATE: SecurID Recommends Waiting for a RADIUS Pre-Migration Script Before Upgrading to RSA Authentication Manager 8.6
February 11, 2022
https://community.securid.com/t5/securid-product-advisories/update-securid-recommends-waiting-for-a-radius-pre-migration/ta-p/667206
Issue
The RADIUS Pre-Migration Script released February 18, 2022, rsa_am_preupgrade_check-1.0.sh, reports finding a FAILURE that there was an Error while exporting the trusted root certificate.
There are two causes for this finding, which is a false flag finding
1. The AM 8.5 appliance that this script was run against has restored a backup from a different AM 8.5 appliance
2. The RADIUS Pre-Migration Script released February 18, 2022 was used
The RADIUS Pre-Migration Script released February 18, 2022 is only 7KB while the March 3rd script is 9Kb. Both were named rsa_am_preupgrade_check-1.0.sh and were included inside rsa-am-pre-upgrade-check-1.0.zip
This FAILURE is a script failure, not a potential migration error. The RADIUS Pre-Migration Script released March 3rd, 2022 does not find this FAILURE, because this version of the script changes file permissions on the trusted root certificate file so that it can read this Certificate and decrypt the RADIUS database.
Cause
The updated rsa_am_preupgrade_check-1.0.sh changes the permissions on this Root CA file by elevating priv with sudo
Tasks
If you see this finding, "Error while exporting the trusted root certificate" do not attempt to fix it, and DO NOT import a copy of the default console Root CA certificate into the Operations Console - Deployment Configuration - RADIUS Servers - EAP Trusted Root CA certificates. This particular fix would break replication on the updated AM 8.6 server appliances.
====ReplicaReplication.log file====
Caused by: org.postgresql.util.PSQLException: ERROR: duplicate key value violates unique constraint "uk_ims_certificates"
Detail: Key (name, purpose, ref_id)=(<Root_CA_filename>.der, RADIUS_TRUST_CERT, NULL) already exists.
Resolution
Do not try to fix this false finding.
Workaround
Related Articles
RSA Identity Governance and Lifecycle MigrationReports.zip fails to install Migration Reports with ORA-04063: package body… 149Number of Views Warnings that are safe to ignore when running the RSA Authentication Manager 8.6 Pre-Upgrade Check Tool 255Number of Views Pre-Upgrade Script Information 900Number of Views RSA Authentication Manager 8.6 Pre-Upgrade Check Tool Readme 753Number of Views RSA Authentication Manager 8.6 Patch 2 Web-Tier Readme 25Number of Views
Trending Articles
RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA Release Notes for RSA Authentication Manager 8.8 RSA Authentication Manager 8.9 Release Notes (January 2026) Deploying RSA Authenticator 6.2.2 for Windows Using DISM RSA MFA Agent 2.4 for Microsoft Windows Installation and Administration Guide
Don't see what you're looking for?