RSA Authentication Manager 8.x import of replacement certificate fails with the error This certificate is already imported
Originally Published: 2017-05-03
Article Number
Applies To
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.2, 8.2 SP1, 8.1 SP1
Issue
When importing a new web tier certificate, the following message is displayed:
There was a problem processing your request
This certificate is already imported
The /opt/rsa/am/server/logs/ops-console.log will also have the following message:
OC_CERT_IMPORT,26187,FAIL,UNEXPECTED_EXCEPTION,,,,,ocuser,,,,,,,,,"com.rsa.ims.security.tools.ssl.exception.InvalidCertificateException:
This certificate is already imported
Cause
- If the trust chain looks something like this, with the root CA at the top, any intermediary signing CA in the middle, and your server certificate at the bottom for a trust chain of three:
- And the response file you are trying to import looks something like this, with the same trust chain of three (i. e., the root CA at top, the intermediary signing CA in the middle, and your server certificate at the bottom):
Then it is not your server certificate that was already imported. It was one of the root certificates included in your server certificate response file that was already imported and is triggering the error that this certificate is already imported.
Resolution
- Right click on the remoteaccess.ws.loc certificate at the bottom of the list and select Open.
- This will bring up the General tab:
- Click on the Details tab and click Copy to File... in the lower right
- Click Next on the Certificate Export Wizard
- Select DER encoded binary X.509 (.CER) and click Next.
- Give your exported Certificate a file name, such as amserver2017.cer.
- Then Next and Finish.
- Import this file into the Operations Console. If that import says you need the Signing Root Certificate, then repeat the above process for the Intermediary Signing Certificate
Workaround
- Delete the root CA and intermediary files immediately before trying this solution, see KB 000035095 How to delete old or pending CSRs
OR
- Ask the Certificate Authority to provide you with separate root CA, intermediary and server certificate files.
Related Articles
Error: '** FIND FIRST/LAST failed for table replace-token-buffer.(565)' when unassigning replacement token and 'this token… 82Number of Views How to import tokens into Authentication Manager 8.x 150Number of Views This certificate or its signing CA is not valid error when importing a certificate chain in RSA Authentication Manager 8.x… 952Number of Views How to import a Root CA or public key Certificate into an Authentication Manager (or AMIS) java key store .jks with keytool 259Number of Views Token seed import fails with 'Import Token failure' error for RSA Authentication Manager 610Number of Views
Trending Articles
RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide RSA Authentication Manager Upgrade Process Artifacts to gather in RSA Identity Governance & Lifecycle Form approval node shows exception caught during script evaluation error in RSA Via Lifecycle and Governance RSA Release Notes for RSA Authentication Manager 8.8
Don't see what you're looking for?