RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.x
- From the Operations Console select Deployment Configuration > Console Certificate Management.
- Click Generate CSR.
- Under Certificate Basics, fill in the certificate information.
- Click Generate File.
- Download the CSR then open it with a text editor and copy the file content.
- On the Active Directory CA server, go to https://localhost/certsrv or https://<Active Directory_CA_FQDN>/certsrv:
- Click the link to submit an advanced certificate request.
- Click the option to submit a certificate request using a base-64-encoded CMC or PKCS #10 file, or submit a renewal request by using a base-64-encoded PKCS #7 file.
- Under Saved Request paste the CSR file content into the box labeled Base-64-encoded certificate request (CMC or PKCS #10 or PKCS #7).
- For Certificate Template make sure to select Web Server.
- Click Submit.
- Click Download Certificate Chain.
- From the Operations Console select Deployment Configuration > Console Certificate Management.
- Select PKCS#7 (.cer or .p7b) for the Type of Certificate to import.
- Choose Import Certificate.
- Click Activate.
- Review the certificate details to ensure this is the certificate you wish to activate.
- Place a check in the Activate Certificate Confirmation box.
- Click Activate Certificate.
- After selecting Activate Certificate, the Authentication Manager services will be restarted automatically.
Verify: Once services have restarted, open a web browser and navigate to the Operations Console URL. Confirm that:
- The browser displays no certificate warnings
- The certificate issuer matches your Microsoft AD CA
- The certificate expiry date is correct
-
Certificate Expiry — Plan for Renewal: Certificates issued by Microsoft AD CA are typically valid for 1–2 years. If the console certificate expires and Authentication Manager services are stopped, the services cannot restart until the expired certificate is replaced with a valid one. Monitor the expiry date noted in Step 21 and plan renewal ahead of time.
-
Replica Instances: This procedure replaces the console certificate on the primary Authentication Manager instance only. If your deployment includes replica instances, verify whether the certificate change propagates automatically or requires a separate procedure on each replica.
-
Certificate Format — PKCS#7 Required: Authentication Manager requires the certificate to be imported in PKCS#7 (.cer or .p7b) format. If your AD CA offers a DER or PEM format instead of a certificate chain, contact your CA administrator to request the full certificate chain in PKCS#7 format.
-
Third-Party CAs: The CSR generation and certificate import steps in this article are the same for any CA. Only the submission process (Part 2) differs. For third-party CA instructions, refer to your CA vendor's documentation.
-
Related Article: For background on how RSA Authentication Manager uses self-signed certificates for internal component communication (and why those should not be replaced), see RSA Authentication Manager and Self-Signed Certificates — KB 000068458.
Related Articles
How to Replace the Operations Console SSL Certificate with SHA-256 in RSA Authentication Manager 8.1 SP1 2.8KNumber of Views RSA Authentication Manager Displays Unwanted Certificate Signing Requests (CSRs) in the Operations Console Certificate Man… 2.64KNumber of Views How to delete old or pending certificate signing requests for RSA Authentication Manager console or virtual host replaceme… 1.64KNumber of Views How to 'Trust' the RSA Authentication Manager Security Console Self-Signed Root CA certificate and prevent Cert warnings. 811Number of Views RSA Authentication Manager and Self-Signed Certificates 425Number of Views
Trending Articles
RSA Announces the Release of RSA MFA Agent 2.5 for Microsoft Windows RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide How to generate a PASSCODE for manual entry on a Ericsson R380 WAP phone How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device RSA SecurID Desktop Token 5.0.3 for Windows Administrator's Guide