Found the answer for the SSO cleanup myself....
- Make a backup of the RSA DB
- Delete obsolete services from both LS_SERVICE and LS_SERVICE_ENDPOINT tables (be careful with the 1:n relationship)
Maybe not an official way, so be warned, I did not search for further related records!