RSA Product/ Service Type: Authentication Manager
RSA Version/Condition: 8.x
When RSA Authentication Manager 8.x services are down, direct SSH access to the server may be needed to copy files for investigation (e.g., log files or debug scripts). Normally, SSH is enabled through the Operations Console — but if the Operations Console is unavailable (for example, due to unknown credentials), SSH cannot be enabled through the standard UI method. This article describes how to enable SSH directly from the appliance console as an alternative.
Prerequisites:
- Physical or virtual console access to the Authentication Manager server (hardware keyboard/monitor, or hypervisor VM console such as VMware vSphere)
rsaadminoperating system account credentials- TCP port 22 must not be blocked by a firewall between your SSH client and the Authentication Manager server
| Task | Method | Key Detail |
|---|---|---|
| Task 1: Enable SSH | Appliance Console + configureSSH.sh | Enables the SSH daemon and saves iptables configuration |
| Task 2: Disable SSH | Appliance Console + configureSSH.sh | Disables the SSH daemon when SSH access is no longer needed |
Task 1: Enable SSH
- Open a console connection to the Authentication Manager server:
- Hardware appliance: Connect a keyboard and monitor directly to the server.
- Virtual machine: Open the VM console from your hypervisor client (e.g., VMware vSphere Console).
- Log in as
rsaadminand enter the operating system password when prompted - Escalate to root:
sudo su -Enter the
rsaadminoperating system password when prompted. - Run the following command to enable SSH:
Expected output:/opt/rsa/am/utils/bin/appliance/configureSSH.sh enableShutting down the listening SSH daemon done Checking for missing server keys in /etc/ssh Starting SSH daemon done Saving iptables configuration done Saving iptables configuration done
Verification: Open an SSH client (e.g., PuTTY) and connect to the appliance IP address. Confirm you can log in successfully as rsaadmin.
Task 2: Disable SSH
-
From the appliance console (or via SSH if still connected), ensure you are logged in as root. If not, repeat Steps 2–3 from Task 1.
-
Run the following command to disable SSH:
/opt/rsa/am/utils/bin/appliance/configureSSH.sh disableExpected output:
Shutting down the listening SSH daemon done Saving iptables configuration done Saving iptables configuration done
Verification: Attempt to connect to the appliance via SSH. Confirm the connection is refused, confirming SSH has been successfully disabled.
Standard Method — Enable SSH via the Operations Console: Once Authentication Manager services are restored and the Operations Console is accessible again, SSH can be enabled and disabled through the standard UI method: log in to the Operations Console and navigate to Administration > Operating System Access > Enable SSH Access. This is the recommended method for routine SSH management.
Related Articles
Enable SSH debug logs for RSA Authentication Manager 8.x 192Number of Views Collecting logs in RSA Authentication Manager 8.x via SSH 466Number of Views How to SSH to an RSA Authentication Manager version 8.x server 109Number of Views Enable SSH using the command line on RSA Authentication Manager 8.1 up to 8.3 1.14KNumber of Views How to generate a SQL Explain Plan in RSA Identity Governance & Lifecycle if Oracle Enterprise Manager (OEM) access is not… 276Number of Views
Trending Articles
How to generate a PASSCODE for manual entry on a Ericsson R380 WAP phone RSA Authentication Manager 8.9 Release Notes (January 2026) IDR SSO - Step 3: Deploy the Identity Router RSA-2026-11: RSA Authentication Manager Security Update for Third-Party Component Vulnerabilities Authentication Manager Supported Hardware and Upgrade Paths