To understand why the user count is different between the Event Viewer (or Syslog) message and the Reporting Tool within the Admin GUI.
The "user count" value differs between multiple product components in RSA CM
The Event Viewer message gives you the total number of certificates in the database, divided by the "license multiplier" contained within your license file. The result is displayed as "the user count" and is an accurate total based on all of the certificates active within the system.
The User Count Report within the Certificate Operations Workbench displays the number of unique Distinguished names (DNs) per CA. The intended usage of this tool is to count each CA individually, and not ALL of the CAs. It was not intended to be a "total system check" because the tool assumes that each DN is a unique user. So duplicate DNs are only counted as a single user. This works for a typical user-created jurisdiction, but the System CA it is different. Because this CA issues certificates for the local internal SSL connections, all which have the same DN, the "user count" will not be a precise indicator of total system usage.
This is why you will see different results between the system log (or event viewer) and the GUI reporting tool.
When judging your license usage the Event Viewer (or Syslog) message is the precise value used internally to check license usage.
For a count of per-Jurisdiction or per-CA users, the GUI Reporting Tool is an excellent indicator.
For more information in installation and administration see:
RSA Certificate Manager 6.7 Readme
https://knowledge.rsasecurity.com/docs/rsa_keon/rcm67/cm/RSACertificateManager67Readme.pdf
RSA Certificate Manager 6.7 Installation Guide
https://knowledge.rsasecurity.com/docs/rsa_keon/rcm67/cm/RSACMInstallationGuide.pdf
RSA Certificate Manager 6.7 Administrator?s Guide
https://knowledge.rsasecurity.com/docs/rsa_keon/rcm67/cm/RSACMAdministratorsGuide.pdf
Related Articles
Password Capture Tool is not creating password synchronization requests in RSA Governance & Lifecycle 81Number of Views Failing to open the invitation URL on the Prime Self Service Portal 29Number of Views User Picker ignores Include Terminated User flag in Via Lifecycle and Governance 7Number of Views RSA Identity Governance and Lifecycle Attribute change rule not detecting changes in terminated users 90Number of Views A website security scanning tool reports that the RSA SecurID Access Portal's server certificate cannot be trusted, even t… 206Number of Views
Trending Articles
RSA Authentication Manager 8.9 Setup and Configuration Guide RSA Authentication Manager 8.9 Release Notes (January 2026) RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide How to 'Trust' the RSA Authentication Manager Security Console Self-Signed Root CA certificate and prevent Cert warnings. RSA Authentication Manager Upgrade Process