Update an existing RSA Cloud Authentication Service Integrated Windows Authentication (IWA) Connector Identity Provider SAML certificate
Originally Published: 2017-04-07
Article Number
Applies To
Issue
Tasks
- Generate a new IWA identity provider certificate as described in Generate and Download a Certificate Bundle for Service Providers and Identity Providers . The Common Name chosen before generating and downloading the certificate bundle can be any value for this certificate. That is, it is not required that it match the IWA server's hostname.
- Once the contents of the certificate bundle .zip file have been extracted, create a .pfx file consisting of the new certificate and its corresponding private key. For example, using the openssl utility:
openssl pkcs12 -export -out IWASAML.pfx -inkey private.key -in cert.pem Export password: <press Enter>
- Copy the .pfx file to the target IWA server.
- Configure the Integrated Windows Authentication Connector to use the new .pfx file for signing identity assertions:
- On the IWA server, click Start > Configure RSA SecurID Access IWA Connector.
- Set the Issuer Signing Certificate to point to the new PFX file path. For example: C:\inetpub\wwwroot\RSASecurIDAccessIWAConnector\config\IWASAML.pfx. Alternatively, backup the existing IWA .pfx file being replaced and then copy the new .pfx file into same/existing IWA .pfx file path.
- Configure the IDRs to use the new IWA certificate for identity assertion verifications:
- In the Administration Console menu, select Users > Identity Providers.
- Edit the IWA identity provider as in step 1 above.
- At the bottom of the Connection Profile tab, use the Select File button to load the new cert.pem IWA SAML certificate.
- Finish the wizard and then publish the changes.
Resolution
Related Articles
Integrate Citrix NetScaler with RSA Authentication Manager 8.x 179Number of Views Signature cryptographic validation not successful error for all RSA SecurID Access integrated Windows Authentication (IWA)… 128Number of Views SecurID Access Prime: Replacing SAML Response Certificate of a SAML Identity Provider integrated with the Self-Service Portal 205Number of Views How to integrate SWIFT Alliance Access with RSA Authentication Manager using RADIUS protocol 106Number of Views Users cannot authenticiate to the RSA SecurID Access Portal or protected applications using Microsoft Integrated Windows A… 188Number of Views
Trending Articles
Downloading RSA Authentication Manager license files or RSA Software token seed records RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory Mandatory Certificate Upgrade Required by 6th October 2025 for RSA MFA Agent for PAM, RSA MFA Agent for Apache, and Third … RSA Authentication Manager 8.9 Release Notes (January 2026)
Don't see what you're looking for?