000033205 - Citrix Netscaler Version 11 device is not able to process NEW PIN post migration from RSA Authentication Manager 7.1 to AM 8.1

Document created by RSA Customer Support Employee on Jun 14, 2016Last modified by RSA Customer Support Employee on Apr 21, 2017
Version 2Show Document
  • View in full screen mode

Article Content

Article Number000033205
Applies ToRSA Product Set: SecurID
RSA Product/Service Type: RSA Authentication Manager
RSA Version/Condition: 8.1 Service Pack 1
Platform: SUSE Enterprise Linux
O/S Version: 11 Service Pack 3
Product Description: SecurID Appliance
Issue1.  Citrix devices using RADIUS protocol are not able to accept NEW PIN after migration from AM 7.1 to AM 8.1
2.  Users unable to SET PIN
2.  Authentication Activity monitor logs the below message under the reason column
"passcode accepted, new pin required"

3.  But the agent will not accept the new pin and Citrix Netscaler fails with error "Invalid Credentials"
4.  Authentications work fine from Citrix for users who have PIN SET from the Self service console of RSA AM 8.1
Resolution1.  To Resolve the issue Restart the Citrix Netscaler 11 server.
2.  Post restart of the server, users with tokens in New Pin Mode can Set Pin from Citrix Netscaler 11
NotesContacting RSA Customer Support
TelephoneFor urgent issues use the telephone numbers listed here
EmailFor non-urgent issues email to support@rsa.com
For Case Management use RSA Online
   (requires access to RSA SecurCare Online)