RSA Product/ Service Type: Authentication Manager
RSA Version/Condition: 8.x
When RSA Authentication Manager 8.x services are down, direct SSH access to the server may be needed to copy files for investigation (e.g., log files or debug scripts). Normally, SSH is enabled through the Operations Console — but if the Operations Console is unavailable (for example, due to unknown credentials), SSH cannot be enabled through the standard UI method. This article describes how to enable SSH directly from the appliance console as an alternative.
Prerequisites:
- Physical or virtual console access to the Authentication Manager server (hardware keyboard/monitor, or hypervisor VM console such as VMware vSphere)
rsaadminoperating system account credentials- TCP port 22 must not be blocked by a firewall between your SSH client and the Authentication Manager server
| Task | Method | Key Detail |
|---|---|---|
| Task 1: Enable SSH | Appliance Console + configureSSH.sh | Enables the SSH daemon and saves iptables configuration |
| Task 2: Disable SSH | Appliance Console + configureSSH.sh | Disables the SSH daemon when SSH access is no longer needed |
Task 1: Enable SSH
- Open a console connection to the Authentication Manager server:
- Hardware appliance: Connect a keyboard and monitor directly to the server.
- Virtual machine: Open the VM console from your hypervisor client (e.g., VMware vSphere Console).
- Log in as
rsaadminand enter the operating system password when prompted - Escalate to root:
sudo su -Enter the
rsaadminoperating system password when prompted. - Run the following command to enable SSH:
Expected output:/opt/rsa/am/utils/bin/appliance/configureSSH.sh enableShutting down the listening SSH daemon done Checking for missing server keys in /etc/ssh Starting SSH daemon done Saving iptables configuration done Saving iptables configuration done
Verification: Open an SSH client (e.g., PuTTY) and connect to the appliance IP address. Confirm you can log in successfully as rsaadmin.
Task 2: Disable SSH
-
From the appliance console (or via SSH if still connected), ensure you are logged in as root. If not, repeat Steps 2–3 from Task 1.
-
Run the following command to disable SSH:
/opt/rsa/am/utils/bin/appliance/configureSSH.sh disableExpected output:
Shutting down the listening SSH daemon done Saving iptables configuration done Saving iptables configuration done
Verification: Attempt to connect to the appliance via SSH. Confirm the connection is refused, confirming SSH has been successfully disabled.
Standard Method — Enable SSH via the Operations Console: Once Authentication Manager services are restored and the Operations Console is accessible again, SSH can be enabled and disabled through the standard UI method: log in to the Operations Console and navigate to Administration > Operating System Access > Enable SSH Access. This is the recommended method for routine SSH management.
Related Articles
Enable SSH debug logs for RSA Authentication Manager 8.x 192Number of Views Collecting logs in RSA Authentication Manager 8.x via SSH 467Number of Views How to SSH to an RSA Authentication Manager version 8.x server 111Number of Views Download an RSA Authentication Manager Server Certificate 40Number of Views Enable SSH using the command line on RSA Authentication Manager 8.1 up to 8.3 1.15KNumber of Views
Trending Articles
Download RSA SecurID Access Cloud User Event audit logs using Cloud Administration REST API CLU RSA Authentication Manager 8.9 Release Notes (January 2026) AFX Server Fails to Start with 'Could Not Build a Validated Path' and 'Timed Out Waiting for AFX Applications to Start' in… AFX Server stuck in 'Not running' State, with error 'timed out waiting for AFX applications to start' Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory