RSA Product Set: SecurID
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.x
When attempting to activate a wildcard certificate in the RSA Authentication Manager Operations Console, the activation fails immediately with an error dialog. The certificate is rejected and cannot be activated.
Observable Symptoms:
- Wildcard certificate activation fails in the Operations Console
- The following error dialog appears on screen:
The certificate subject name does not match the hostname of this solution. Select another certificate to activate.
RSA Authentication Manager does not support wildcard certificates — it requires the certificate's Common Name (CN) to exactly match the fully qualified hostname (FQHN) of the server instance.
A wildcard certificate (e.g., *.domain.com) is designed to secure multiple subdomains under a single certificate. However, Authentication Manager enforces a strict one-to-one match between the certificate CN and the server's FQHN as a security requirement for SSL certificate activation. When the CN contains a wildcard (*) instead of an exact hostname, AM immediately rejects the certificate with the subject name mismatch error.
This commonly happens when an organization attempts to reuse an existing wildcard certificate — typically issued for web or load balancer use — for the Authentication Manager server instead of requesting a dedicated certificate for the AM instance.
Wildcard certificates are not supported in Authentication Manager. You must generate a new Certificate Signing Request (CSR) using the exact fully qualified hostname (FQHN) of the AM server and obtain a dedicated certificate from your Certificate Authority (CA).
- Log in to the Operations Console.
- Navigate to Deployment Configuration > Certificates > Console Certificate Management.
- Click Generate Certificate Signing Request (CSR).
- In the Alias field, choose an Alias for your certificate.
- Complete the remaining fields and click Generate. Save the CSR file.
- Submit the CSR to your Certificate Authority (CA) and request a dedicated certificate — confirm with your CA that the CN will not contain a wildcard.
- Once you receive the signed certificate, return to Deployment Configuration > Certificates > Console Certificate Management, click Import Certificate, and import the signed certificate.
- Click Activate to activate the new certificate.
-
Related Article — Certificate Chain Import Error: If after obtaining your new dedicated certificate you encounter the error
"This certificate or its signing CA is not valid"during import, refer to This Certificate or Its Signing CA Is Not Valid Error When Importing a Certificate Chain in RSA Authentication Manager 8.x Operations Console (Article 000063154). That article covers how to split a.p7bcertificate chain file and import each certificate individually. -
Related Article — "This Certificate Is Already Imported" Error: If you encounter the error
"This certificate is already imported"when importing your new certificate, refer to RSA Authentication Manager 8.x Import of Replacement Certificate Fails with 'This Certificate Is Already Imported' (Article 000064368). That article covers how to extract and import only the server certificate when the root CA is already present in the trust chain.
Related Articles
Unable to import CRL in Firefox 6Number of Views Accessing the raw data tabs for collector runs is very slow in RSA Identity Governance & Lifecycle 26Number of Views CT-KIP activation using Admin API does not display the tokens as activated on Self-service portal 20Number of Views RSA Authentication Manager 8.5 Azure Virtual Appliance Getting Started 8Number of Views How to resolve ORA-22285 error thrown in the Data Archiving process of RSA Identity Governance & Lifecycle 29Number of Views
Trending Articles
RSA Authentication Manager 8.9 Setup and Configuration Guide RSA Authentication Manager 8.9 Release Notes (January 2026) RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide How to 'Trust' the RSA Authentication Manager Security Console Self-Signed Root CA certificate and prevent Cert warnings. RSA Authentication Manager Upgrade Process