Certificate Authority Certificate Files
A certificate authority may send certificates in one or more files. There are three possible combinations:
One file. One certificate file that contains the entire chain of certificates from the parent trusted root certificate, to possible intermediate signing certificates, to the host certificate. This is the most convenient scenario, because everything is in one file. You may lose some flexibility because you cannot unbundle the certificates.
When you import the certificate file, the system warns you that it is not trusted because the imported root certificate is not yet saved in the trusted root store. After the import, the warning no longer appears.
Two files. A certificate file and a separate root certificate file containing the signed Virtual Host server certificate. This provides the following benefits:
A trusted root certificate against which all future certificates are verified.
A trusted root certificate that you can import into the trusted root stores of web browsers that do not trust the RSA default root certificate by default.
You must import the root certificate first.
Two or more files. Multiple files, each containing a separate certificate. This allows you to establish a trusted root and gives you the most flexibility. When you replace both the web-tier and virtual host certificates, and they are signed by the same trusted certificate authority, you only need to import the trust certificates once. You must import each certificate in the following order:
Parent trusted root certificate
Intermediate signing certificates
Host certificate
Related Articles
How to replace the RSA Authentication Manager self signed console certificate with a signed certificate from Microsoft Act… 1.69KNumber of Views How to 'Trust' the RSA Authentication Manager Security Console Self-Signed Root CA certificate and prevent Cert warnings. 859Number of Views Authentication Manager How to Retrieve the LDAPS Certificate and Configure an External Identity Source to Use LDAPS 4.27KNumber of Views Authentication Manager Security Console and Operations Console Inaccessible After Certificate Update 2.63KNumber of Views How to create and configure certificates for HTTPS access when using intermediate CA certs in RSA Identity Governance & Li… 1.08KNumber of Views
Trending Articles
RSA Authentication Manager Upgrade Process Workflows stuck in AFX fulfillment and/or Provisioning nodes in RSA Identity Governance & Lifecycle Change Requests stuck in the AFX Fulfillment Handler Workflow Node and Workflows Stalled in RSA Identity Governance & Life… Collector Stuck in Data Collection Phase with "Sent Request to Agent Hosting the Collector" RSA Authentication Manager 8.9 Patches and Hotfixes Readme