000021538 - How to run RSA ACE/Agent Authentication API client on Windows

Document created by RSA Customer Support Employee on Jun 16, 2016Last modified by RSA Customer Support Employee on Apr 21, 2017
Version 2Show Document
  • View in full screen mode

Article Content

Article Number000021538
Applies ToRSA ACE/Server 5.x
aceclnt.dll
Microsoft Windows 2000 SP4
IssueHow to run RSA ACE/Agent Authentication API client on Windows
Running API client from console works correctly, but attempting to run as a different user (via Windows Scheduler for example) results in failed authentication and Node verification failure in ACE/Server log
CauseThe 2nd user does not have permission to access the node secret stored in the registry at HKLM\Software\SDTI\ACECLIENT
ResolutionTo correct this issue, use regedt32 (Security\Permissions menu) to grant access to the appropriate group and/or user to the HKLM\Software\SDTI\ACECLIENT registry key. For example, if IIS is performing the SecurID authentication on Windows 2000, Full Control to the above registry key would be needed by user IWAM_<MACHINENAME>. For Windows Server 2003, Full Control permission would be needed by the IIS_WGP group.
Legacy Article IDa23628

Attachments

    Outcomes