RSA Product Set: SecurID
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.x
When attempting to activate a wildcard certificate in the RSA Authentication Manager Operations Console, the activation fails immediately with an error dialog. The certificate is rejected and cannot be activated.
Observable Symptoms:
- Wildcard certificate activation fails in the Operations Console
- The following error dialog appears on screen:
The certificate subject name does not match the hostname of this solution. Select another certificate to activate.
RSA Authentication Manager does not support wildcard certificates — it requires the certificate's Common Name (CN) to exactly match the fully qualified hostname (FQHN) of the server instance.
A wildcard certificate (e.g., *.domain.com) is designed to secure multiple subdomains under a single certificate. However, Authentication Manager enforces a strict one-to-one match between the certificate CN and the server's FQHN as a security requirement for SSL certificate activation. When the CN contains a wildcard (*) instead of an exact hostname, AM immediately rejects the certificate with the subject name mismatch error.
This commonly happens when an organization attempts to reuse an existing wildcard certificate — typically issued for web or load balancer use — for the Authentication Manager server instead of requesting a dedicated certificate for the AM instance.
Wildcard certificates are not supported in Authentication Manager. You must generate a new Certificate Signing Request (CSR) using the exact fully qualified hostname (FQHN) of the AM server and obtain a dedicated certificate from your Certificate Authority (CA).
- Log in to the Operations Console.
- Navigate to Deployment Configuration > Certificates > Console Certificate Management.
- Click Generate Certificate Signing Request (CSR).
- In the Alias field, choose an Alias for your certificate.
- Complete the remaining fields and click Generate. Save the CSR file.
- Submit the CSR to your Certificate Authority (CA) and request a dedicated certificate — confirm with your CA that the CN will not contain a wildcard.
- Once you receive the signed certificate, return to Deployment Configuration > Certificates > Console Certificate Management, click Import Certificate, and import the signed certificate.
- Click Activate to activate the new certificate.
-
Related Article — Certificate Chain Import Error: If after obtaining your new dedicated certificate you encounter the error
"This certificate or its signing CA is not valid"during import, refer to This Certificate or Its Signing CA Is Not Valid Error When Importing a Certificate Chain in RSA Authentication Manager 8.x Operations Console (Article 000063154). That article covers how to split a.p7bcertificate chain file and import each certificate individually. -
Related Article — "This Certificate Is Already Imported" Error: If you encounter the error
"This certificate is already imported"when importing your new certificate, refer to RSA Authentication Manager 8.x Import of Replacement Certificate Fails with 'This Certificate Is Already Imported' (Article 000064368). That article covers how to extract and import only the server certificate when the root CA is already present in the trust chain.
Related Articles
Unable to import CRL in Firefox 6Number of Views Specops Software uReset - SecurID Authentication API with AM Configuration - RSA Ready SecurID Access Implementation Guide 13Number of Views RSA Identity Governance and Lifecycle error "The selected file does not match the required CSV format" when importing Loca… 76Number of Views RSA Authentication Manager 8.5 Azure Virtual Appliance Getting Started 8Number of Views Problem importing metadata from into RSA FIM 17Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide RSA Authentication Manager Upgrade Process Running out of disk space when using RMAN in RSA Identity Governance & Lifecycle