Citrix Netscaler failing to properly handle New PIN Mode and On-Demand Authentication (ODA) when using RADIUS with RSA Authentication Manager 8.x
Originally Published: 2015-06-29
Article Number
Applies To
RSA Product/Service Type: Authentication Manager
Issue
In the On-Demand Authentication (ODA) scenario, the user is not getting the email or SMS with the tokencode after entering the correct PIN. Below is a detailed description of the issue:
- The user connects to the Citrix portal, and is prompted for his user ID, tokencode or PIN (if using ODA).
- The user is asked to create a new PIN then prompted to re-enter the PIN.
- Citrix responds that the new PIN has been accepted and to wait for the tokencode to change, then enter the new passcode (PIN + tokencode) and click Submit.
- When the user enters the next passcode, an Access Denied message displays.
Cause
Resolution
Workaround
Option 1
The securid.ini file that handles the messaging can be edited so that the steps users need to take are more clear. Editing this file will change the messaging seen by users to all RADIUS clients. Citrix article CTX124374 on how to modify the RSA token prompts displayed by NetScaler Gateway has information on how to make the required changes to the securid.ini directly on a Windows server. RSA Authentication Manager admins can make the change through the Operations Console using the steps below.- Login to the Operations Console.
- Select Deployment Configuration > RADIUS Servers.
- Click on the drop-down next to the RADIUS primary and choose Manage Server Files.
- Click on the arrow next to the securid.ini file and select Edit.
- Following the steps in the Citrix article above, edit the ExtInputNextCode value, the ExtOutputChange value or both. Note that there is a 255-character maximum for the message.
- When done, click Save and Restart RADIUS Server.
- Repeat steps 1 through 6 for any replicas in the deployment.
Option 2
Refresh the Citrix webpage after setting the new PIN. The user can typically authenticate normally with the passcode (PIN+tokencode).
Option 3
In the case of ODA, refreshing the page will trigger a new email or SMS that will be sent to the user.Notes
Related Articles
Enabled and Disabled Tokens 13Number of Views On-Demand Authentication with an Authentication Agent or a RADIUS Client 17Number of Views Access Denied when trying to log in to KMS administration panel 40Number of Views How to exclude RSA Authentication Manager 8.x from picking up disabled user account data from the Microsoft LDAP directory 161Number of Views Disable On-Demand Authentication for a User 9Number of Views
Trending Articles
Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory RSA Authentication Manager 8.9 Release Notes (January 2026) Artifacts to gather in RSA Identity Governance & Lifecycle RSA Governance & Lifecycle 8.0.0 Administrators Guide RSA Governance & Lifecycle 8.0.0 Installation Guide
Don't see what you're looking for?