RSA Authentication Manager 8.x import of replacement certificate fails with the error This certificate is already imported
Originally Published: 2017-05-03
Article Number
Applies To
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.2, 8.2 SP1, 8.1 SP1
Issue
When importing a new web tier certificate, the following message is displayed:
There was a problem processing your request
This certificate is already imported
The /opt/rsa/am/server/logs/ops-console.log will also have the following message:
OC_CERT_IMPORT,26187,FAIL,UNEXPECTED_EXCEPTION,,,,,ocuser,,,,,,,,,"com.rsa.ims.security.tools.ssl.exception.InvalidCertificateException:
This certificate is already imported
Cause
- If the trust chain looks something like this, with the root CA at the top, any intermediary signing CA in the middle, and your server certificate at the bottom for a trust chain of three:
- And the response file you are trying to import looks something like this, with the same trust chain of three (i. e., the root CA at top, the intermediary signing CA in the middle, and your server certificate at the bottom):
Then it is not your server certificate that was already imported. It was one of the root certificates included in your server certificate response file that was already imported and is triggering the error that this certificate is already imported.
Resolution
- Right click on the remoteaccess.ws.loc certificate at the bottom of the list and select Open.
- This will bring up the General tab:
- Click on the Details tab and click Copy to File... in the lower right
- Click Next on the Certificate Export Wizard
- Select DER encoded binary X.509 (.CER) and click Next.
- Give your exported Certificate a file name, such as amserver2017.cer.
- Then Next and Finish.
- Import this file into the Operations Console. If that import says you need the Signing Root Certificate, then repeat the above process for the Intermediary Signing Certificate
Workaround
- Delete the root CA and intermediary files immediately before trying this solution, see KB 000035095 How to delete old or pending CSRs
OR
- Ask the Certificate Authority to provide you with separate root CA, intermediary and server certificate files.
Related Articles
Error: '** FIND FIRST/LAST failed for table replace-token-buffer.(565)' when unassigning replacement token and 'this token… 79Number of Views This certificate or its signing CA is not valid error when importing a certificate chain in RSA Authentication Manager 8.x… 936Number of Views Why do tokens disappear from RSA ACE/Server database when replacement token is activated? 32Number of Views Token seed import fails with 'Import Token failure' error for RSA Authentication Manager 604Number of Views How to import tokens into Authentication Manager 8.x 133Number of Views
Trending Articles
RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA Authentication Manager 8.9 Release Notes (January 2026) How to install the jTDS JDBC driver on WildFly for use with Data Collections in RSA Identity Governance & Lifecycle RSA Authentication Manager 8.8 Setup and Configuration Guide Artifacts to gather in RSA Identity Governance & Lifecycle
Don't see what you're looking for?