Certificate Authority Certificate Files
A certificate authority may send certificates in one or more files. There are three possible combinations:
One file. One certificate file that contains the entire chain of certificates from the parent trusted root certificate, to possible intermediate signing certificates, to the host certificate. This is the most convenient scenario, because everything is in one file. You may lose some flexibility because you cannot unbundle the certificates.
When you import the certificate file, the system warns you that it is not trusted because the imported root certificate is not yet saved in the trusted root store. After the import, the warning no longer appears.
Two files. A certificate file and a separate root certificate file containing the signed Virtual Host server certificate. This provides the following benefits:
A trusted root certificate against which all future certificates are verified.
A trusted root certificate that you can import into the trusted root stores of web browsers that do not trust the RSA default root certificate by default.
You must import the root certificate first.
Two or more files. Multiple files, each containing a separate certificate. This allows you to establish a trusted root and gives you the most flexibility. When you replace both the web-tier and virtual host certificates, and they are signed by the same trusted certificate authority, you only need to import the trust certificates once. You must import each certificate in the following order:
Parent trusted root certificate
Intermediate signing certificates
Host certificate
Related Articles
How to replace the RSA Authentication Manager self signed console certificate with a signed certificate from Microsoft Act… 1.6KNumber of Views Get the external Identity Source LDAPS certificate using openssl for RSA Authentication Manager 8.x 4.11KNumber of Views Delete unwanted Certificate Signing Requests (CSR) from the RSA Authentication Manager Operations Console Certificate Mana… 2.54KNumber of Views Authentication Manager Security Console and Operations Console Inaccessible After Certificate Update 2.42KNumber of Views How to 'Trust' the RSA Authentication Manager Security Console Self-Signed Root CA certificate and prevent Cert warnings. 760Number of Views
Trending Articles
RSA Authentication Manager 8.9 Release Notes (January 2026) RSA announces the availability of the RSA SecurID Hardware Appliance 230 based on the Dell PowerEdge R240 Server How to troubleshoot Oracle database ORA-04030 errors in RSA Identity Governance & Lifecycle RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA Authentication Manager Upgrade Process