Move users and tokens from one RSA Authentication Manager 8.x server to another
Originally Published: 2016-03-04
Article Number
Applies To
RSA Product/Service Type: RSA Authentication Manager
RSA Version/Condition: 8.x
Issue
There was a problem processing your request.
An error occurred while decrypting data. The import file is corrupt.
An error occurred while decrypting data. The import file is corrupt.
Resolution
Before continuing, please take a backup of the database from the Operations Console (Maintenance > Backup and Restore > Backup Now) or take a snapshot of the virtual server.
The steps below provide information on how to export users from one Authentication Manager 8.x deployment to another.
1. Download the encryption key from Security Console of the Authentication Manager 8.x target deployment
- In the Security Console of the target deployment, click Administration > Export/ Import Tokens and Users > Download Encryption Key.
- Click Download Now.
- Use the File Download dialog box to select a location for the encryption key, and click Save.
- Complete the save operation to your local directory, as required by your browser.
- Click Done.
- In the Security Console of the source deployment, click Administration > Export/Import Tokens and Users > Export Tokens and Users.
- In the Encryption Key Location field, browse to the encryption key that you downloaded from the target deployment.
- In the Export Job Name field, specify the name of the export job. RSA recommends you keep the default job name. If you edit the job name, the new name must be unique.
- In the Export Type field, select Users with Tokens.
- Click Next.
- In the Security Console of the target deployment, click Administration > Export/Import Tokens and Users > Import Tokens and Users.
- In the Import Job Name field, specify the name of the import job.
- Select the import file location.
- Click Next.
Notes
- If the RSA Authentication Manager 8.x source server uses an external identity source but the target does not, imported users will be saved to the internal database.
- The encryption key is the public key corresponding to an RSA public-private key pair. The key ensures the following:
- Token and user records being exported can be imported only to the target deployment.
- The exported data is encrypted, thus preventing the data from being read or tampered with in transit.
- The source and target deployments communicate only with each other.
- You must download the encryption key from the target deployment before exporting users or tokens from a source deployment.
Related Articles
Moving the RSA Authentication Manager 8.x virtual appliance from one ESX host to another 572Number of Views Migrating users from one identity source to another in Authentication Manager 28Number of Views Migrating an RSA Authentication Manager deployment from one environment to another 443Number of Views Moving users across security domains using RSA Authentication Manager Bulk Administration (AMBA) 173Number of Views Limiting users to one token per user ID in RSA Authentication Manager 8.x 114Number of Views
Trending Articles
RSA Authentication Manager 8.9 Release Notes (January 2026) RSA announces the availability of the RSA SecurID Hardware Appliance 230 based on the Dell PowerEdge R240 Server How to troubleshoot Oracle database ORA-04030 errors in RSA Identity Governance & Lifecycle RSA Authentication Manager Upgrade Process Microsoft SQL Server Collectors can no longer connect to the SQL Server database after upgrade to Microsoft SQL Server 201…
Don't see what you're looking for?