Upgrading an RSA Authentication Manager deployment that started at Authentication Manager 8.1 or 8.2
Originally Published: 2023-12-11
Article Number
Applies To
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.x
Issue
A deployment of Authentication Manager that began life at 8.4 or earlier and has been upgraded over time to 8.6 then to 8.7 with or without service packs and patches has a lot of extraneous files and data data cruft that can affect system performance. This article provides steps to create a new 8.7 replica, promote it to primary then add new 8.7 replica servers and remove the old ones. In addition this article will cover h0ow to handle web tiers, CT-KIP URLs an REST agent URLs.
Tasks
Steps to take
- Download the appropriate .ova file(s) from my.rsa.com and Authentication Manager Setup and Configuration Guides for Authentication Manager. You must install every version and service pack (but not patches). See this article for a quick overview of upgrading Authentication Manager and a deeper step-by-step walk through in the .pdf attached to the article on the RSA Authentication Manager Upgrade Process.
- Confirm that replication is healthy.
- Stand up new virtual server, either with the current FQDN and IP of old primary or create new FQDN and IP address.
- Generate a new replica package from the current primary.
- Run Authentication Manager Quick Setup to create a new replica.
- Attach the new replica server to the current primary.
- Promote the new replica to primary.
- Update your web tier, CT-KIP strings, and servers for your REST agents.
- Remove the old primary server. See notes below about reusing the server's name and IP address before deleting this server.
- Check replication health again. Follow the steps to manually resynchronize the servers if you see an internal replication failure.
- Repeat steps 2 through 10 until all old servers are replaced.
Resolution
Download installation software
- Go to https://my.rsa.com.
- Enter your user ID and password. Note: To download the files, you must log in to myRSA as the user whose name is on the purchase order. If you log in as another user, you cannot see the files.
- Next to the myRSA logo, there is a search bar/dropdown menu that has company information, including address and site ID. Select the correct account.
- Click on hyperlink under the RSA SecurID Suite icon.
- Click on the hyperlink for the RSA SID Access Virtual Appliance.
- From the Select Version dropdown, select the correct software version.
- A list of available files appears. Select the correct file(s). For example, for Authentication Manager 8.7 SP1, download the rsa-am-vmware-virtual-appliance-8.7.1.0.0.ova for VMware or rsa-am-hyper-v-virtual-appliance-8.7.1.0.0.zip for Hyper-V. If you need the AWS SecurID AMI files, please create a case with Support and the files will be made available to you.
- Check the box in front of the End User License Agreement.
- Click Download on the bottom-right corner of the page.
- Download the file and extract the contents.
Confirm replication is healthy
- From the Home tab on the Operations Console, click Replication Status Report.
Stand up new virtual server
- Review steps in the RSA Authentication Manager Setup and Configuration Guide for the your version for information on standing up a new replica server. If you are currently at Authentication Manager 8.7 for example, review the RSA Authentication Manager 8.7 Setup and Configuration Guide.
- Follow the steps in the RSA Authentication Manager 8.7 Setup and Configuration Guide to deploy a new replica. This includes:
- Generating and downloading a replica package.
- Configuring the appliance with Quick Setup.
- Attaching the replica instance to the primary.
- Confirming replication is working. It is expected that there may be issues with replication as you attach new servers or upgrade software. If that is the case, please contact Technical Support for assistance.
To use the FQDN and IP address of the current primary on the new primary
Reusing the old primary's FQDN and IP address means than you do not need to update CT-KIP configuration or REST agent URLs.
- Promote the new replica to be the primary server.
- From the primary's Operations Console, navigate to Deployment Configuration > Web Tier Deployments > Manage Existing.
- Reselect the preferred RBA instance to be itself. Click Save. You must do this before removing the old primary from the deployment.
To use a different FQDN and IP address for the new primary
- Promote an existing replica to be the temporary primary server.
- From the primary's Operations Console, navigate to Deployment Configuration > Web Tier Deployments > Manage Existing.
- Update the preferred RBA instance. You must do this before removing the old primary from the deployment.
- From the Security Console, navigate to Settings > System Settings.
- Update settings for E-Mail (SMTP),
- Click Tokens to update token provisioning information.
- Click RSA SecurID Authentication API and click Apply Settings.
- Follow the steps in the online help available in the Security and Operations Console on tasks to complete after changing the name and/or IP address of the primary server.
Remove the former primary
- From the primary's Operations Console, navigate to Deployment Configuration > Instances > Status Report.
- Click on the drop down next to the old replica and choose Delete.
- Go back to the Status report and confirm that replication is healthy amongst all servers in the deployment.
- Delete the virtual machine, if needed.
Related Articles
RSA Announces Availability of RSA Authentication Manager 8.5 Language Packs 7Number of Views Drop down menus display extra characters in Console after upgrading to AM 8.1 6Number of Views RSA Announces the Redistribution of RSA Authentication Manager 8.7 SP2 196Number of Views Replica instances are removed after migrating RSA Authentication Manager 7.1 data to RSA Authentication Manager 8.1 56Number of Views Replica attachment fails on Authentication Manager 8.1 with an error related to the relation testmode_on 12Number of Views
Trending Articles
RSA Authentication Manager 8.9 Release Notes (January 2026) RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide How to install the jTDS JDBC driver on WildFly for use with Data Collections in RSA Identity Governance & Lifecycle RSA Authentication Manager 8.8 Setup and Configuration Guide Artifacts to gather in RSA Identity Governance & Lifecycle
Don't see what you're looking for?