What is process to change the nCipher Operator Card Set (OCS) in RSA Certificate Manager?
Originally Published: 2010-12-23
Last Modified: 2023-10-06
Article Number
Applies To
RSA Certificate Manager 6.7
nCipher Hardware Security Module (HSM)
nCipher NetHSM
Issue
Attempting to replace the current card set for RCM so we can create a remotely enabled set of cards. The previous card set was working properly but was not remotely enabled. Keysafe shows everything converted correctly. It shows the key recover count moved from the old cardset to the new cardset. Named the new cardset CA Systems OCS ? QA whereas the old cardset was named CA Systems OCS. The key files in kmdata/local show the new date.
Resolution
The OCS name is stored with the objects referring to nCipher based keys.
When you replace an OCS, the new OCS name should be the same as the original one. Let's say the original one was called OCS-1, you would created a new OCS called OCS-temp to replace OCS-1 and move all keys to OCS-temp, then remove the original OCS-1, and then create a new OCS called OCS-1 to replace OCS-temp and move all keys to the new OCS-1, and finally remove OCS-temp as it is no longer needed.
Related Articles
How to report OC admin activity immediately and forward it to Syslog? 16Number of Views What is the range of tokencodes accepted by RSA ACE/Server or RSA Authentication Manager? 153Number of Views What is the aveksa_watchdog service in RSA Identity Governance & Lifecycle? 99Number of Views What are the custom attribute data type limits in RSA Identity Governance & Lifecycle 115Number of Views What is the Return Merchandise Authorization (RMA) process for SID800 tokens? 144Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Unable to login to RSA Authentication Manager Security Console as super admin Manual synchronization introduced in RSA Authentication Manager 8.2 Service Pack 1 patch 6 Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory How to verify NTP server synchronization is not working in RSA Authentication Manager 8.x
Don't see what you're looking for?