000034834 - RSA Card Reset Utility unable to unlock/reset SmartCard PIN

Document created by RSA Customer Support Employee on May 1, 2017
Version 1Show Document
  • View in full screen mode

Article Content

Article Number000034834
Applies ToRSA Product Set: SecurID
RSA Product/Service Type: RSA Card Reset Utility 
RSA Version/Condition:  1.9.3
IssueAttempting to utilize the RSA Card Reset Utility to clear the SmartCard PIN results in the following error
The token serial number XXXXXXXXXXX was not found in the specified file.
The file in use is <batchnumber>PUK_KEYSET.XML.

You can verify the issue by viewing the PUK_KEYSET.XML in a text editor.  Look at the SmarChipSN value for a trailing space between the last number and the closing quote, as shown,  If there is a trailing space, this file is affected.
<?xml version='1.0' encoding='UTF-8'?>
<scms:TokenDescription xmlns:scms="http://www.rsasecurity.com/schema/2003/07/Passage/scms.xsd" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" Name="SID800" ATR="3B5F9502802215E15A00230021033121030000 " FormatVersion="1.0">
<Token SerialNumber="000403874443" SmartChipSN="3534103077042250 ">
     <Token SerialNumber="000403874444" SmartChipSN="3534103077042450 ">
CauseThere was a defect in the manufacturing process that affected a small number of customers.  Customers were notified via email.
Your originally delivered token <Batch Number>_PUK_KEYSET.XML will work as normal and can be deployed. However, if an administrator attempts to use the Card Reset Utility that references the <Batch Number>_PUK_KEYSET.XML, it will fail to successfully reset the PIN.  This utility is used if a user forgets their Smart Card PIN or if a token gets reassigned to another user.  The Card Reset Utility invoked by the token administrator using the original <Batch Number>_PUK_KEYSET.XML will result in a failure.  Using the new <Batch Number>_PUK_KEYSET.XML on this new CD will remediate this issue. There is no need to re-import either the PUK or the token seed record file into Authentication Manager.
Further details regarding the Card Reset Utility can be found in the Card Reset Utility User Guide.
Do not reimport the new token seed file into Authentication Manager
RSA regrets any inconvenience this may cause.  We will be available to assist with any questions or support you may need to help with this situation.  Please contact technical support or call (800) 995 5095, and select option 3 for technical support.
ResolutionIf you experience this error please use the new <Batch Number>_PUK_KEYSET.XML provided to you by .
WorkaroundA workaround to the issue is to use a text editor and do a find/replace on finding the blank"> and replace with ">

<?xml version='1.0' encoding='UTF-8'?><scms:TokenDescription xmlns:scms="http://www.rsasecurity.com/schema/2003/07/Passage/scms.xsd" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" Name="SID800" ATR="3B5F9502802215E15A00230021033121030000 " FormatVersion="1.0"><Token SerialNumber="000403874443" SmartChipSN="3534103077042250 "><KeySetVersion>1</KeySetVersion><SecurityDomainAID>A000000003000000</SecurityDomainAID><AuthenticationKey>ab1e43a24ad13139680557573532b377</AuthenticationKey><MACKey>15eadd75391975c58700f2396df9a4ba</MACKey><KeyEncryptionKey>10c24df4a659e529f4c210de5e65e823</KeyEncryptionKey><DefaultPUK>ac75300d0661d6e9</DefaultPUK></Token><Token SerialNumber="000403874444" SmartChipSN="3534103077042450 "><KeySetVersion>