How to export root certificates for RSA Authentication Manager, Identity Router, or Cloud Authentication Service
a year ago
Originally Published: 2018-08-21
Article Number
000063937
Applies To

RSA Product Set: SecurID
RSA Product/Service Type: Authentication Manager, Identity Router, Cloud Authentication Service
Version(s): All supported versions

Issue
There are several system configuration scenarios where an administrator must obtain the SSL root certificate from the RSA Authentication Manager server, the Identity Router, or the Cloud Authentication Service.
Resolution

These specific instructions are for Chrome. If you cannot use Chrome in your environment search the internet for export root certificate from <browser vendor name>. Other browser types use similar steps.

The images below show the steps for obtaining the Cloud Authentication Service root certificate.

  • For an RSA Authentication Manager root certificate, browse to https://<Authentication Manager server fully qualified domain name>/sc.
  • For an Identity Router root certificate, browse to https://<IDR Management IP>/setup.jsp.
  • For the Cloud Authentication Service root certificate, browse to any valid Administration Console URL, such as https://<company subdomain>-<baseAccessDNSName>.securid.com.

Refer to the following table for baseAccessDNSName.

DeploymentbaseAccessDNSName
USaccess
GOVaccess
ANZaccess-anz
EMEAaccess-eu
Indiaaccess-in
Japanaccess-jp
Canadaaccess-ca
Singaporeaccess-sg
  1. Browse to your RSA Authentication Manager Security Console, to the Identity Router setup.jsp page, or to the Cloud Administration Console, as appropriate.
  2. Click the lock icon in the browser address bar:
User-added image
  1. Click Certificate:
User-added image
  1. Click the Certification Path tab.
  2. Double-click the top-level (root) certificate in the list.
Certificate chain up to Entrust Root
  1. Click the Details tab.
  2. Click Copy to File...

Certificate Details

  1. Click Next.
User-added image
  1. Choose Base-64 encoded X.509 output format.
  2. Click Next.
User-added image
  1. Specify the filename for the export.
  2. Click Next.
User-added image
  1. Click Finish.
User-added image
  1. The certificate should now be available in the specified file.
Notes

Note that for certain versions of Authentication Manager and associated agents (e.g., MFA agents like the MFA Agent 9.0 for PAM, etc.) that a SHA256 certificate is required.