---
title: Managing Digital Certs and CSR in RSA Authentication Manager
description: How to clean up CSR's
---

[Skip to content](https://thinking.net.nz/blog/managing-digital-certs-and-csr-in-rsa-authentication-manager#main-content)

![thinking_sideways_final](https://thinking.net.nz/hs-fs/hubfs/thinking_sideways_final.png?width=4977&height=1883&name=thinking_sideways_final.png)

- [Products](https://thinking.net.nz/blog/managing-digital-certs-and-csr-in-rsa-authentication-manager#products)
- [Services](https://thinking.net.nz/blog/managing-digital-certs-and-csr-in-rsa-authentication-manager#services)
- [Blog](https://thinking.net.nz/blog/managing-digital-certs-and-csr-in-rsa-authentication-manager#blog)
- [About](https://thinking.net.nz/blog/managing-digital-certs-and-csr-in-rsa-authentication-manager#about)

Open main navigation

Close main navigation

- [Products](https://thinking.net.nz/blog/managing-digital-certs-and-csr-in-rsa-authentication-manager#products)
- [Services](https://thinking.net.nz/blog/managing-digital-certs-and-csr-in-rsa-authentication-manager#services)
- [Blog](https://thinking.net.nz/blog/managing-digital-certs-and-csr-in-rsa-authentication-manager#blog)
- [About](https://thinking.net.nz/blog/managing-digital-certs-and-csr-in-rsa-authentication-manager#about)
- [Contact us](https://thinking.net.nz/blog/managing-digital-certs-and-csr-in-rsa-authentication-manager#contact)

[Contact us](https://thinking.net.nz/blog/managing-digital-certs-and-csr-in-rsa-authentication-manager#contact)

 Sep 3, 2024 1:31:10 PM

# Managing Digital Certs and CSR in RSA Authentication Manager

![Picture of JK](https://app.hubspot.com/settings/avatar/d07d287c41a806c015d4f2548c90ba4f) [JK](https://thinking.net.nz/blog/author/jk)

Share: [facebook-f icon](http://www.facebook.com/share.php?u=https://thinking.net.nz/blog/managing-digital-certs-and-csr-in-rsa-authentication-manager) [linkedin-in icon](http://www.linkedin.com/shareArticle?mini=true&url=https://thinking.net.nz/blog/managing-digital-certs-and-csr-in-rsa-authentication-manager) [Twitter icon](https://twitter.com/intent/tweet?url=https://thinking.net.nz/blog/managing-digital-certs-and-csr-in-rsa-authentication-manager) [pinterest-p icon](http://pinterest.com/pin/create/link/?url=https://thinking.net.nz/blog/managing-digital-certs-and-csr-in-rsa-authentication-manager) [envelope icon](mailto:?body=https://thinking.net.nz/blog/managing-digital-certs-and-csr-in-rsa-authentication-manager)

How to clean up CSR's

## You have created one or more CSR (certificate signing requests), not all can be fulfilled for numerous reasons and you want to clean them up

In the RSA Authentication Manager, creating Certificate Signing Requests (CSR) is a common task to ensure secure communication and authentication. However, not all CSR can be fulfilled due to a variety of reasons such as incorrect information, changes in security requirements, or even organizational policy updates. Over time, these unfulfilled requests can clutter your system, making it essential to clean them up to maintain an organized and efficient environment.

Cleaning up unfulfilled CSR involves identifying the requests that are no longer required and systematically removing them from the system. This process not only helps in keeping the system manageable but also enhances security by ensuring that outdated or incorrect requests do not pose any risk. The steps for cleaning up CSR typically include reviewing the pending requests, validating their necessity, and then using the RSA Authentication Manager's tools to delete or archive the unnecessary entries.

 

**Before You Begin**

Please take a backup or take a snapshot prior to any task.

**Solution**

1: SSH to the Primary AM appliance with PuTTy, logon with the Operating System Account, typically called rsaadmin.

The keytool is located in /opt/rsa/am/appserver/jdk/bin

The .jks keystores are located in /opt/rsa/am/server/security

The RSA Utility is located in /opt/rsa/am/utils

2: Get the SSL Server Identity Cert Keystore File Password – you need Operations Console OC Admin credentials to do this

/opt/rsa/am/utils/rsautil manage-secrets -a list

You have to highlight the whole password to copy and paste, and delete the spaces, so you get this MA8eMBMiDSWz6ApxEDLC2oeKWBhtZh as an example

Obviously your file password will be different.

3: Verify the Alias for your private key Next go to the security directory so you can access the Virtual Host keystores, which have the Virtual Host Key – seen in the Operations Console.

cd /opt/rsa/am/server/security/

This directory has two Virtual Host Keystores, one called vh-identity.jks which has the active Key/Cert, and vh-inactive.jks

Make a copy of those files.

sudo cp vh-identity.jks vh-identity.jks.ORIG

sudo cp vh-inactive.jks vh-inactive.jks.ORIG

 Here is the command to list the existing certificates.

/opt/rsa/am/appserver/jdk/jre/bin/keytool -list -keystore /opt/rsa/am/server/security/vh-identity.jks

/opt/rsa/am/appserver/jdk/jre/bin/keytool -list-keystore /opt/rsa/am/server/security/vh-inactive.jks

Revert back to the self-signed certificate and run the commands above again to see the alias “your-alias” in vh-inactive.jks file

Delete the “your-alias” alias.

/opt/rsa/am/appserver/jdk/jre/bin/keytool -delete -alias “your-alias” -keystore /opt/rsa/am/server/security/vh-inactive.jks

Go to the RSA Authentication Manager 8.1 Primary Operations Console -> Deployment Configuration ->Certificates -> Virtual Host Certificate Management and the certificate is removed

## Related posts

## [Checking the NTP status on RSA Authentication Manager](https://thinking.net.nz/blog/checking-the-ntp-status-on-rsa-authentication-manager)

![Picture of JK](https://app.hubspot.com/settings/avatar/d07d287c41a806c015d4f2548c90ba4f) [JK](https://thinking.net.nz/blog/author/jk) 

 Sep 3, 2024 1:33:50 PM

Discover the critical role of Network Time Protocol (NTP) in securing your RSA Authentication...

[Read more](https://thinking.net.nz/blog/checking-the-ntp-status-on-rsa-authentication-manager)

## [How to Detect MS17-010 Vulnerability in Your Systems](https://thinking.net.nz/blog/how-to-detect-ms17-010-vulnerability-in-your-systems)

![Picture of JK](https://app.hubspot.com/settings/avatar/d07d287c41a806c015d4f2548c90ba4f) [JK](https://thinking.net.nz/blog/author/jk) 

 Sep 3, 2024 1:25:16 PM

Uncover the critical steps to identify and mitigate the infamous MS17-010 vulnerability that...

[Read more](https://thinking.net.nz/blog/how-to-detect-ms17-010-vulnerability-in-your-systems)

[Checkpoint](https://thinking.net.nz/blog/tag/checkpoint)

## [Fun with routing VPNs on Checkpoint..](https://thinking.net.nz/blog/fun-with-vpns-on-checkpoint)

![Picture of JK](https://app.hubspot.com/settings/avatar/d07d287c41a806c015d4f2548c90ba4f) [JK](https://thinking.net.nz/blog/author/jk) 

 Oct 18, 2024 1:29:24 PM

Some useful notes from the field 2 ways of providing routes to a Checkpoint VPN. Lets focus on...

[Read more](https://thinking.net.nz/blog/fun-with-vpns-on-checkpoint)

[Follow us on Linkedin](https://www.linkedin.com/company/thinking2014limited) [Thinking Service Portal](https://thinking.myportallogin.com.au/) [Download our Terms of Business](https://thinking.net.nz/terms-of-business)

- [Products](https://thinking.net.nz/blog/managing-digital-certs-and-csr-in-rsa-authentication-manager#products)
- [Services](https://thinking.net.nz/blog/managing-digital-certs-and-csr-in-rsa-authentication-manager#services)
- [Blog](https://thinking.net.nz/blog/managing-digital-certs-and-csr-in-rsa-authentication-manager#blog)
- [About](https://thinking.net.nz/blog/managing-digital-certs-and-csr-in-rsa-authentication-manager#about)

---

[![thinking_sideways_final](https://thinking.net.nz/hs-fs/hubfs/thinking_sideways_final.png?width=4977&height=1883&name=thinking_sideways_final.png "thinking_sideways_final")](https://www.thinking.net.nz)

Postal: PO Box 26, Waimauku, Auckland 0842, New Zealand

Email:enquires@thinking.net.nz

Copyright © 2024

Thinking (2014) Limited

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "JK",
    "url" : "https://thinking.net.nz/blog/author/jk"
  },
  "dateModified" : "2024-09-03T01:31:10.585Z",
  "datePublished" : "2024-09-03T01:31:10.000Z",
  "headline" : "Managing Digital Certs and CSR in RSA Authentication Manager",
  "mainEntityOfPage" : {
    "@id" : "https://thinking.net.nz/blog/managing-digital-certs-and-csr-in-rsa-authentication-manager",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject"
    },
    "name" : "Thinking (2014) Limited"
  }
}
```