AM 8.6 RADIUS Pre-Migration Script FAILURES: Error while exporting the trusted root certificate
Article Number
Applies To
See
UPDATE: SecurID Recommends Waiting for a RADIUS Pre-Migration Script Before Upgrading to RSA Authentication Manager 8.6
February 11, 2022
https://community.securid.com/t5/securid-product-advisories/update-securid-recommends-waiting-for-a-radius-pre-migration/ta-p/667206
Issue
The RADIUS Pre-Migration Script released February 18, 2022, rsa_am_preupgrade_check-1.0.sh, reports finding a FAILURE that there was an Error while exporting the trusted root certificate.
There are two causes for this finding, which is a false flag finding
1. The AM 8.5 appliance that this script was run against has restored a backup from a different AM 8.5 appliance
2. The RADIUS Pre-Migration Script released February 18, 2022 was used
The RADIUS Pre-Migration Script released February 18, 2022 is only 7KB while the March 3rd script is 9Kb. Both were named rsa_am_preupgrade_check-1.0.sh and were included inside rsa-am-pre-upgrade-check-1.0.zip
This FAILURE is a script failure, not a potential migration error. The RADIUS Pre-Migration Script released March 3rd, 2022 does not find this FAILURE, because this version of the script changes file permissions on the trusted root certificate file so that it can read this Certificate and decrypt the RADIUS database.
Cause
The updated rsa_am_preupgrade_check-1.0.sh changes the permissions on this Root CA file by elevating priv with sudo
Tasks
If you see this finding, "Error while exporting the trusted root certificate" do not attempt to fix it, and DO NOT import a copy of the default console Root CA certificate into the Operations Console - Deployment Configuration - RADIUS Servers - EAP Trusted Root CA certificates. This particular fix would break replication on the updated AM 8.6 server appliances.
====ReplicaReplication.log file====
Caused by: org.postgresql.util.PSQLException: ERROR: duplicate key value violates unique constraint "uk_ims_certificates"
Detail: Key (name, purpose, ref_id)=(<Root_CA_filename>.der, RADIUS_TRUST_CERT, NULL) already exists.
Resolution
Do not try to fix this false finding.
Workaround
Related Articles
Warnings that are safe to ignore when running the RSA Authentication Manager 8.6 Pre-Upgrade Check Tool 263Number of Views RSA Identity Governance and Lifecycle MigrationReports.zip fails to install Migration Reports with ORA-04063: package body… 149Number of Views RSA Authentication Manager 8.6 Pre-Upgrade Check Tool Readme 755Number of Views Pre-Upgrade Script Information 900Number of Views RSA Authentication Manager 8.6 Patch 2 Web-Tier Readme 25Number of Views
Trending Articles
Passwordless Authentication in Windows MFA Agent for Active Directory – Quick Setup Guide RSA Authentication Manager 8.9 Release Notes (January 2026) RSA Authentication Manager Upgrade Process RSA Authentication Manager 8.7 SP2 Setup and Configuration Guide An example of SSO using SAML and ADFS with RSA Identity Management and Governance 6.9.x
Don't see what you're looking for?