000036706 - Limiting users to one token per user ID in RSA Authentication Manager 8.x

Document created by RSA Customer Support Employee on Sep 17, 2018
Version 1Show Document
  • View in full screen mode

Article Content

Article Number000036706
Applies ToRSA Product Set: SecurID
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.1.1
IssueAn administrator has a requirement to limit one token per user in the Authentication Manager database, whether it is a user mapped from an external identity source or added to the internal database.
ResolutionThere is a method to limit one token per User ID in the Authentication Manager database and an administrator will require command line access with a restart of Authentication Manager services.

Before following the instructions below, it would be advisable to have a backup of the Authentication Manager database. Follow the instructions on How to create a Backup Using Back Up Now.


  1. If not already enabled, enable secure shell on the appliance.
  2. Login to the primary Authentication Manager server as rsaadmin and enter the operating system password.

Note that during Quick Setup another user name may have been selected. Use that user name to login.

  1. Navigate to the /opt/rsa/am/utils folder:

login as: rsaadmin
Using keyboard-interactive authentication.
Password: <enter operating system password>
Last login: Tue Aug 28 14:18:12 2018 from jumphost.vcloud.local
RSA Authentication Manager Installation Directory: /opt/rsa/am

  1. Navigate to /opt/rsa/am/utils:

rsaadmin@am82p:~> cd /opt/rsa/am/utils

  1. Carefully enter the following command and provide the Operations Console admin password when prompted:

rsaadmin@am82p:/opt/rsa/am/utils> ./rsautil store -o <enter Operations Console administrator name> -a add_config auth_manager.admin.maximum_usable_tokens 1 GLOBAL 501
Please enter OC Administrator password: <enter Operations Console administrator password>
psql.bin:/tmp/819c55ab-0e79-49cb-a420-5f4b4d9094ae3515872605838824841.sql:108: NOTICE:   Added the new configuration parameter
"auth_manager.admin.maximum_usable_tokens" with the value "1"

(1 row)


  1. Restart all Authentication Manager services on the primary server:

/opt/rsa/am/server/rsaserv restart all

  1. Repeat the service restart on all replicas.

The default value for auth_manager.admin.maximum_usable_tokens is 3.  The same procedure above can be used to set the usable token value to 3 or 2.

  1. After restarting the Authentication Manager services on the primary and replica(s), an administrator will get the following message on the primary's Security Console when trying to assign more than one token to a selected user.

Assign would have resulted in more than the maximum allowed number of tokens for at least one selected user.

User-added image