This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Accept
Reject
  • RSA.com
  • Home
  • Advisories
    • SecurID
    • SecurID Governance & Lifecycle
  • Documentation
    • SecurID
      • Authentication Agents
        • API / SDK
        • Apache Web Server
        • Citrix StoreFront
        • IIS Web Server
        • MFA Agent for macOS
        • MFA Agent for Windows
        • Microsoft AD FS
        • Microsoft Windows
        • PAM
      • Authentication Engine
      • Authentication Manager
      • Cloud Authentication Service
      • Hardware Appliance
        Component Updates
      • Hardware Tokens
      • Integrations
      • SecurID App
      • SecurID Authenticator for macOS
      • SecurID SDK
      • Software Tokens
        • Android
        • iOS
        • macOS
        • Token Converter
        • Windows
    • SecurID Governance & Lifecycle
    • Technology Partners
  • Downloads
    • SecurID
      • Authentication Agents
        • API / SDK
        • Apache Web Server
        • Citrix StoreFront
        • IIS Web Server
        • MFA Agent for macOS
        • MFA Agent for Windows
        • Microsoft AD FS
        • Microsoft Windows
        • PAM
      • Authentication Engine
      • Authentication Manager
      • Cloud Authentication Service
      • Hardware Appliance
        Component Updates
      • Hardware Tokens
      • Integrations
      • SecurID Authenticator for macOS
      • Software Tokens
        • Android
        • iOS
        • macOS
        • Token Converter
        • Windows
    • SecurID Governance & Lifecycle
  • Community
    • SecurID
      • Blog
      • Discussions
      • Events
      • Idea Exchange
      • Knowledge Base
    • SecurID Governance & Lifecycle
      • Blog
      • Discussions
      • Events
      • Idea Exchange
      • Knowledge Base
  • Support
    • Case Portal
      • Create New Case
      • View My Cases
      • View My Team's Cases
    • Community Support
      • Getting Started
      • News & Announcements
      • Ideas & Suggestions
      • Community Support Articles
      • Community Support Forum
    • Product Life Cycle
    • Support Information
    • General Security Advisories
  • Education
    • Blog
    • Browse Courses
      • SecurID
      • SecurID Governance & Lifecycle
    • Certification Program
    • New Product Readiness
    • Student Resources
Sign In Register Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
Announcements

SecurID® Knowledge Base

Find answers to your questions and identify resolutions for known issues with knowledge base articles written by SecurID experts.
  • SecurID Community
  • :
  • Products
  • :
  • SecurID
  • :
  • Knowledge Base
  • :
  • How to resolve RSA ACE/Agent certificate issues in ACE NAP
  • Options
    • Subscribe to RSS Feed
    • Bookmark
    • Subscribe
    • Email to a Friend
    • Printer Friendly Page
    • Report Inappropriate Content

How to resolve RSA ACE/Agent certificate issues in ACE NAP

Article Number

000018179

Applies To

RSA ACE/Server
RSA ACE/Agent for Windows
RSA ACE/Agent certificate utility
Microsoft Windows

Issue

How to resolve RSA ACE/Agent certificate issues in ACE NAP
Error: "The currently installed root certificate did not issue the certificate you are importing"
Certificate is invalid

Cause

The user had several Server certificates on his ACE/Agent Certificate Utility. One of the Server certificates was selected as the root certificate, likely by clicking on Select Root Certificate button, and selecting a different *.CRT from the sdroot.crt. From this ?new root cert?  the customer made a new server certificate. When the other administrator returned and re-selected the correct root certificate, the new Server Certificates were invalid.

Resolution

1. Start RSA ACE/Agent certificate utility by navigating to Start Menu>Programs>Ace Agent>Ace Agent Certificate Utility)

2. Opening the Certificate utility will prompt you for a password.>Click Cancel.

3. Find the true root certificate (by default named sdroot.crt), click Select Root Certificate, browse to (by default) c:\Program Files\Sdti\ACE Agent Certificate Utility. Here you should find sdroot.crt. Double click <sdroot.crt > at the prompt, and enter the password.

4. Check the root certificate by highlighting sdroot.crt, click Verify Certificate. You should get the message Certificate is valid.

NOTE: If any other message appears, you may have to create a root certificate, and a key, then create all new server certificates and keys. Before doing this, call RSA Security Customer Support for assistance.

5. Make new Server Certificate and Keys. Click the Help button for instructions if necessary.

6. Import this new Certificate to the new BDC (deleting the current certificate and key if necessary). Test authentication should work correctly.
Tags (20)
  • Agent
  • Auth Agent
  • Authentication Agent
  • Customer Support Article
  • KB Article
  • Knowledge Article
  • Knowledge Base
  • Microsoft
  • Microsoft Windows
  • Microsoft Windows Agent
  • RSA SecurID
  • RSA SecurID Access
  • RSA SecurID Suite
  • SecurID
  • SecurID Access
  • SecurID Agent
  • SecurID Suite
  • Windows
  • Windows Agent
  • Windows Authentication Agent
0 Likes
Was this article helpful? Yes No
Share
No ratings

In this article

Version history
Last update:
‎2020-12-13 03:49 AM
Updated by:
Administrator RSA-KB-Sync Administrator

Related Content

Powered by Khoros
  • Blog
  • Events
  • Discussions
  • Idea Exchange
  • Knowledge Base
  • Case Portal
  • Community Support
  • Product Life Cycle
  • Support Information
  • Customer Success
  • About the Community
  • Terms & Conditions
  • Privacy Statement
  • Provide Feedback
  • Employee Login
© 2022 RSA Security LLC or its affiliates. All rights reserved.