RSA Authentication Manager 8.x import of replacement certificate fails with the error This certificate is already imported
Originally Published: 2017-05-03
Article Number
Applies To
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.2, 8.2 SP1, 8.1 SP1
Issue
When importing a new web tier certificate, the following message is displayed:
There was a problem processing your request
This certificate is already imported
The /opt/rsa/am/server/logs/ops-console.log will also have the following message:
OC_CERT_IMPORT,26187,FAIL,UNEXPECTED_EXCEPTION,,,,,ocuser,,,,,,,,,"com.rsa.ims.security.tools.ssl.exception.InvalidCertificateException:
This certificate is already imported
Cause
- If the trust chain looks something like this, with the root CA at the top, any intermediary signing CA in the middle, and your server certificate at the bottom for a trust chain of three:
- And the response file you are trying to import looks something like this, with the same trust chain of three (i. e., the root CA at top, the intermediary signing CA in the middle, and your server certificate at the bottom):
Then it is not your server certificate that was already imported. It was one of the root certificates included in your server certificate response file that was already imported and is triggering the error that this certificate is already imported.
Resolution
- Right click on the remoteaccess.ws.loc certificate at the bottom of the list and select Open.
- This will bring up the General tab:
- Click on the Details tab and click Copy to File... in the lower right
- Click Next on the Certificate Export Wizard
- Select DER encoded binary X.509 (.CER) and click Next.
- Give your exported Certificate a file name, such as amserver2017.cer.
- Then Next and Finish.
- Import this file into the Operations Console. If that import says you need the Signing Root Certificate, then repeat the above process for the Intermediary Signing Certificate
Workaround
- Delete the root CA and intermediary files immediately before trying this solution, see KB 000035095 How to delete old or pending CSRs
OR
- Ask the Certificate Authority to provide you with separate root CA, intermediary and server certificate files.
Related Articles
Error: '** FIND FIRST/LAST failed for table replace-token-buffer.(565)' when unassigning replacement token and 'this token… 82Number of Views How to import tokens into Authentication Manager 8.x 151Number of Views How to import a Root CA or public key Certificate into an Authentication Manager (or AMIS) java key store .jks with keytool 264Number of Views This certificate or its signing CA is not valid error when importing a certificate chain in RSA Authentication Manager 8.x… 956Number of Views Token seed import fails with 'Import Token failure' error for RSA Authentication Manager 612Number of Views
Trending Articles
RSA Authentication Manager 8.9 Release Notes (January 2026) RSA announces the availability of the RSA SecurID Hardware Appliance 230 based on the Dell PowerEdge R240 Server How to troubleshoot Oracle database ORA-04030 errors in RSA Identity Governance & Lifecycle RSA Authentication Manager Upgrade Process Microsoft SQL Server Collectors can no longer connect to the SQL Server database after upgrade to Microsoft SQL Server 201…
Don't see what you're looking for?