|Applies To||RSA Product Set: SecurID|
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.x
|Issue||The error following message shows in the Self-Service Console when requesting a token:|
The <hostname>_server.log is located in /opt/rsa/am/server/logs. It will show the following error while creating a self-service request for enrollment with hardware token:
com.rsa.command.exception.InvalidArgumentException: This token type is not allowed in UCM
at com.rsa.command.CommandServer_qt4u4w_EOImpl_1000_WLStub.executeFrameworkManagedTx(Unknown Source)
at weblogic.security.service.SecurityManager.runAs(Unknown Source)
|Cause||Before using the self-service-request samples you must first configure the desired setting for how your self-service system will work. |
The file in question come with the RSA Authentication Manager 8.x SDK that is available in the extras.zip. Review 000034558 - How to download RSA Authentication Manager 8.x full kits and service packs from RSA Link for steps to download.
These settings are found in the Security Console under Setup > Self Service Settings > Manage Authenticators in RSA Authentication Manager 8.x and above
This error can also happen when not using the SDK. A customer can set up Credential Manager > Manage Tokens to allow users to request one type of token (for example, Desktop PC 4.0) but when the user goes to the Self-Service Console he selects Generic AES. Since this is not an approved token type, the error message of "This token type is not allowed in UCM" will display. To resolve the issue simply add the correct token type.
|Resolution||This specific error is cause because the sample code generates a request for a hardware token but the self-service system (Credential Manager) has not been configured to enable hardware tokens to be requested. This option is handled on the Manage Tokens link under the Token Provisioning section and the option to allow users to Allow users to request Standard Cards should be enabled.|
|Workaround||A workaround would be to run the SDK example code CreateSelfServiceRequest.class.|
|Legacy Article ID||a50271|