000036584 - RSA Authentication Manager 8.2 SP1 offline authentication fails for users with multiple tokens

Document created by RSA Customer Support Employee on Aug 6, 2018Last modified by RSA Customer Support Employee on Aug 6, 2018
Version 2Show Document
  • View in full screen mode

Article Content

Article Number000036584
Applies ToRSA Product Set: SecurID
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.2 SP1
 
IssueThe user is using two tokens for authentication.
  • A user logs in with Token 1, authentication is successful and offline day file data for that token is downloaded.
  • Offline Authentication with Token 1 works properly.
  • The user logs off, then logs on and authenticates with Token 2.  Offline day files are downloaded. 
  • The next day the user is off the corporate network and tries to authenticate wit Token 1 but authentication fails. 
  • They then try to authenticate using Token 2 and it works.
The sequence of the tokens does not matter.

It was observed that the problem is that the offline days of Token 1 get renamed then deleted.

The following error appears in the Authentication Manager server's /opt/rsa/am/server/imsTrace.log, which shows purged dayfiles as true, as shown in bold:
 

2018-03-06 11:15:40,052, [OARequestHandler2], (Download.java:57), trace.authmgr.oa.download, DEBUG, baesvlodc175v.greenlnk.net,,,,Sending: PolicyData [DA warning days: 7]
[Version: 1][DA failed auth limit: 20][Log DA events: true][DA days: 90][DA enabled: true][EAPC enabled: true][EATC enabled: true][Login password integration enabled: false]
[Verbose logging: false][Purge day files: true][Agent ID: -121361833][Server time: 1015413340][Agent DB name: glklag716606.greenlnk.net]
CauseThe issue is on the Authentication Manager server and not on the RSA Authentication Agent. This issue has been reported as defect AM-31997.
ResolutionThis issue has been reported in defect AM-31997.  Please contact RSA Customer Support to learn about the fix, which is resolved in Authentication Manager 8.3 patch 3.
 

On replicas running Authentication  Manager 8.2 at any patch level, you must replace the oa-8.2.1.6.0.jar file with the updated version of oa-8.2.1.6.0.jar.


 

The hot fix needs to be applied on the replica servers first, then to the primary. 




Instructions for applying hot fix



  1. Request the hotfix from RSA Customer Support.
  2. Using WinSCP or FileZIlla, place the file on the appliance in /tmp.
  3. Navigate to cd /opt/rsa/am/server/servers/biztier/tmp/_WL_user/am-app/mxboc6/APP-INF/lib.
  4. Backup oa-8.2.1.6.0.jar: 


cd /opt/rsa/am/server/servers/biztier/tmp/_WL_user/am-app/mxboc6/APP-INF/lib
cp oa-8.2.1.6.0.jar oa-8.2.1.6.0.jar.BAK


  1. Copy the oa-8.2.1.6.0.jar file obtained from /tmp to this directory.  Please note the dot at the end of the command (used if the file is copied and saved in /tmp )


cp /tmp/oa-8.2.1.6.0.jar .


  1. Confirm that this directory contains the backup file and the one copied from /tmp:


ls -al oa*.jar*
-rw------- 1 rsaadmin rsaadmin 180744 Jul 27  2016 oa-8.2.1.6.0.jar
-rw------- 1 rsaadmin rsaadmin 180744 Jul 28  2016 oa-8.2.1.6.0.jar.BAK


  1. Replace in other directories:


cd /opt/rsa/am/server/servers/console/tmp/_WL_user/console-shared-library/t5l98w/WEB-INF/lib
cp /tmp/oa-8.2.1.6.0.jar .
cd /opt/rsa/am/server/servers/AdminServer/tmp/_WL_user/console-shared-library/8hkrcb/WEB-INF/lib
cp /tmp/oa-8.2.1.6.0.jar .
cd /opt/rsa/am/server/servers/radiusoc/tmp/_WL_user/am-radius-app/cbsd0y/APP-INF/lib
cp /tmp/oa-8.2.1.6.0.jar .


  1. Restart all Authentication Manager services


cd /opt/rsa/am/server
./rsaserv restart all

 

To revert the replacement file



  1. Copy the backup file to the /tmp directory


cp /opt/rsa/am/server/servers/biztier/tmp/_WL_user/am-app/mxboc6/APP-INF/lib/ oa-8.2.1.6.0.jar.BAK /tmp/oa-8.2.1.6.0.jar


  1. Use the same command to replace the new file with old one:


cd /opt/rsa/am/server/servers/biztier/tmp/_WL_user/am-app/mxboc6/APP-INF/lib
cp /tmp/oa-8.2.1.6.0.jar .
cd /opt/rsa/am/server/servers/console/tmp/_WL_user/console-shared-library/t5l98w/WEB-INF/lib
cp /tmp/oa-8.2.1.6.0.jar .
cd /opt/rsa/am/server/servers/AdminServer/tmp/_WL_user/console-shared-library/8hkrcb/WEB-INF/lib
cp /tmp/oa-8.2.1.6.0.jar .
cd /opt/rsa/am/server/servers/radiusoc/tmp/_WL_user/am-radius-app/cbsd0y/APP-INF/lib
cp /tmp/oa-8.2.1.6.0.jar .


  1. Restart all Authentication Manager services


cd /opt/rsa/am/server
./rsaserv restart all

Attachments

    Outcomes