Repair an RSA Trusted Realm
In RSA Authentication Manager, you can use the repair feature to enter new information about an RSA trusted realm. For example, you can update the hostname or IP address used to contact the Cloud Access Service.
If RSA AM has a new IP address or netmask, then you must provide this information to a Cloud Access Service administrator.
Before you begin
- This procedure requires the rsaadmin password.
- You must be a Super Admin or a Trust Administrator.
Procedure
- Log on to the appliance with the User ID rsaadmin and the operating system password that you defined during Quick Setup.
- Change directories to /opt/rsa/am/utils. Type:
cd /opt/rsa/am/utils/
and press ENTER.
- Modify the trusted realm. Type:
./rsautil manage-securid-access-trusts -a repair -t trusted_realm
where trusted_realm is the name of the RSA trusted realm that needs to be modified.
and press ENTER. You are prompted for the required information.
Note: Although it is possible to enter the administrator password on the command line along with the other options, this creates a potential security vulnerability. RSA recommends that you enter passwords only when prompted.
- When prompted, enter the Super Admin or Trust Administrator username, and press ENTER.
- When prompted, enter the Super Admin or Trust Administrator password, and press ENTER.
- When the RSA trusted realm is located, you are prompted to enter updated values for the following items:
- RSA REST API URL Prefix used to contact the Cloud Access Service. You might want to update the hostname or IP address.
- The Access ID and Access Key provided by the Cloud Access Service Super Admin.
- Trusted realm name.
- Whether the trusted realm is enabled.
- Whether the trusted realm is enabled for authentication.
- Optional notes.
Press ENTER for each item that you do not want to update.
- After the trusted realm is updated, RSA Authentication Manager tests the connection to the trusted realm. After 30 seconds, a message indicates whether the connection test succeeded or failed.
If the connection test fails, you can view the details in the imsTrace.log file in the /opt/rsa/am/server/logs directory.
- To verify the changed details in the Security Console, click Administration > Trusted Realms > Manage Existing.
Related Articles
AADSTS50107: Requested federation realm object 'http:/<Identity Router FQDN>/' does not exist when trying to access the Mi… 64Number of Views RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide 311Number of Views RSA Authentication Manager 8.8 upgrade fails with ERROR: auth_manager.rest_service.old_access_key is not found 2.23KNumber of Views
Trending Articles
RSA Authentication Manager 8.9 Setup and Configuration Guide RSA Authentication Manager 8.9 Release Notes (January 2026) RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide How to 'Trust' the RSA Authentication Manager Security Console Self-Signed Root CA certificate and prevent Cert warnings. RSA Authentication Manager Upgrade Process