How to export root certificates for RSA Authentication Manager, Identity Router, or Cloud Authentication Service
Originally Published: 2018-08-21
Article Number
Applies To
RSA Product Set: SecurID
RSA Product/Service Type: Authentication Manager, Identity Router, Cloud Authentication Service
Version(s): All supported versions
Issue
Resolution
These specific instructions are for Chrome. If you cannot use Chrome in your environment search the internet for export root certificate from <browser vendor name>. Other browser types use similar steps.
The images below show the steps for obtaining the Cloud Authentication Service root certificate.
- For an RSA Authentication Manager root certificate, browse to https://<Authentication Manager server fully qualified domain name>/sc.
- For an Identity Router root certificate, browse to https://<IDR Management IP>/setup.jsp.
- For the Cloud Authentication Service root certificate, browse to any valid Administration Console URL, such as https://<company subdomain>-<baseAccessDNSName>.securid.com.
Refer to the following table for baseAccessDNSName.
| Deployment | baseAccessDNSName |
| US | access |
| GOV | access |
| ANZ | access-anz |
| EMEA | access-eu |
| India | access-in |
| Japan | access-jp |
| Canada | access-ca |
| Singapore | access-sg |
- Browse to your RSA Authentication Manager Security Console, to the Identity Router setup.jsp page, or to the Cloud Administration Console, as appropriate.
- Click the lock icon in the browser address bar:
- Click Certificate:
- Click the Certification Path tab.
- Double-click the top-level (root) certificate in the list.
- Click the Details tab.
- Click Copy to File...
- Click Next.
- Choose Base-64 encoded X.509 output format.
- Click Next.
- Specify the filename for the export.
- Click Next.
- Click Finish.
- The certificate should now be available in the specified file.
Notes
Note that for certain versions of Authentication Manager and associated agents (e.g., MFA agents like the MFA Agent 9.0 for PAM, etc.) that a SHA256 certificate is required.
Related Articles
Add an Identity Router to Cloud Access Service for Authentication Manager 19Number of Views How to troubleshoot an RSA Identity Router that is in a Distressed state 963Number of Views How to obtain the bundle logs from an RSA Cloud Authentication Service Identity Router 620Number of Views How to delete and reinstall a virtual RSA Identity Router 644Number of Views Identity router (IDR) registration fails with error cannot connect to Cloud Authentication Service for RSA SecurID Access 765Number of Views
Trending Articles
RSA Authentication Manager Upgrade Process RSA Release Notes for RSA Authentication Manager 8.8 RSA RADIUS Server service failed to start in the RSA Authentication Manager 8.1 Operations Console Microsoft Entra ID External MFA - Relying Party Configuration Using OIDC - RSA Ready Implementation Guide RSA Release Notes: Cloud Access Service and RSA Authenticators
Don't see what you're looking for?