Move users and tokens from one RSA Authentication Manager 8.x server to another
Originally Published: 2016-03-04
Article Number
Applies To
RSA Product/Service Type: RSA Authentication Manager
RSA Version/Condition: 8.x
Issue
There was a problem processing your request.
An error occurred while decrypting data. The import file is corrupt.
An error occurred while decrypting data. The import file is corrupt.
Resolution
Before continuing, please take a backup of the database from the Operations Console (Maintenance > Backup and Restore > Backup Now) or take a snapshot of the virtual server.
The steps below provide information on how to export users from one Authentication Manager 8.x deployment to another.
1. Download the encryption key from Security Console of the Authentication Manager 8.x target deployment
- In the Security Console of the target deployment, click Administration > Export/ Import Tokens and Users > Download Encryption Key.
- Click Download Now.
- Use the File Download dialog box to select a location for the encryption key, and click Save.
- Complete the save operation to your local directory, as required by your browser.
- Click Done.
- In the Security Console of the source deployment, click Administration > Export/Import Tokens and Users > Export Tokens and Users.
- In the Encryption Key Location field, browse to the encryption key that you downloaded from the target deployment.
- In the Export Job Name field, specify the name of the export job. RSA recommends you keep the default job name. If you edit the job name, the new name must be unique.
- In the Export Type field, select Users with Tokens.
- Click Next.
- In the Security Console of the target deployment, click Administration > Export/Import Tokens and Users > Import Tokens and Users.
- In the Import Job Name field, specify the name of the import job.
- Select the import file location.
- Click Next.
Notes
- If the RSA Authentication Manager 8.x source server uses an external identity source but the target does not, imported users will be saved to the internal database.
- The encryption key is the public key corresponding to an RSA public-private key pair. The key ensures the following:
- Token and user records being exported can be imported only to the target deployment.
- The exported data is encrypted, thus preventing the data from being read or tampered with in transit.
- The source and target deployments communicate only with each other.
- You must download the encryption key from the target deployment before exporting users or tokens from a source deployment.
Related Articles
Moving the RSA Authentication Manager 8.x virtual appliance from one ESX host to another 556Number of Views Migrating an RSA Authentication Manager deployment from one environment to another 420Number of Views Migrating users from one identity source to another in Authentication Manager 19Number of Views How to move users from one group to another in RSA ACE/Server Administration API 15Number of Views Overview of steps to move Authentication Manager 8.1 production data to VMware ESX 6.0 168Number of Views
Trending Articles
RSA Release Notes for RSA Authentication Manager 8.8 RSA MFA Agent 2.4.3 for Microsoft Windows Group Policy Object Template Guide RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA MFA Agent 2.4.3 for Microsoft Windows Installation and Administration Guide RSA Authentication Manager 8.9 Release Notes (January 2026)
Don't see what you're looking for?