Citrix Netscaler failing to properly handle New PIN Mode and On-Demand Authentication (ODA) when using RADIUS with RSA Authentication Manager 8.x
Originally Published: 2015-06-29
Article Number
Applies To
RSA Product/Service Type: Authentication Manager
Issue
In the On-Demand Authentication (ODA) scenario, the user is not getting the email or SMS with the tokencode after entering the correct PIN. Below is a detailed description of the issue:
- The user connects to the Citrix portal, and is prompted for his user ID, tokencode or PIN (if using ODA).
- The user is asked to create a new PIN then prompted to re-enter the PIN.
- Citrix responds that the new PIN has been accepted and to wait for the tokencode to change, then enter the new passcode (PIN + tokencode) and click Submit.
- When the user enters the next passcode, an Access Denied message displays.
Cause
Resolution
Workaround
Option 1
The securid.ini file that handles the messaging can be edited so that the steps users need to take are more clear. Editing this file will change the messaging seen by users to all RADIUS clients. Citrix article CTX124374 on how to modify the RSA token prompts displayed by NetScaler Gateway has information on how to make the required changes to the securid.ini directly on a Windows server. RSA Authentication Manager admins can make the change through the Operations Console using the steps below.- Login to the Operations Console.
- Select Deployment Configuration > RADIUS Servers.
- Click on the drop-down next to the RADIUS primary and choose Manage Server Files.
- Click on the arrow next to the securid.ini file and select Edit.
- Following the steps in the Citrix article above, edit the ExtInputNextCode value, the ExtOutputChange value or both. Note that there is a 255-character maximum for the message.
- When done, click Save and Restart RADIUS Server.
- Repeat steps 1 through 6 for any replicas in the deployment.
Option 2
Refresh the Citrix webpage after setting the new PIN. The user can typically authenticate normally with the passcode (PIN+tokencode).
Option 3
In the case of ODA, refreshing the page will trigger a new email or SMS that will be sent to the user.Notes
Related Articles
RSA Announces the Release of RSA Authentication Agent 2.0.2 for Citrix StoreFront 3Number of Views On-Demand Authentication with an Authentication Agent or a RADIUS Client 17Number of Views How to troubleshoot On-Demand Authentication (ODA) login failures in RSA Authentication Manager 8.x 1.18KNumber of Views Get Java Auth API sample code to authenticate consistently with 'Requires Name Lock' enabled 35Number of Views Access Denied when trying to log in to KMS administration panel 40Number of Views
Trending Articles
Passwordless Authentication in Windows MFA Agent for Active Directory – Quick Setup Guide RSA Authentication Manager 8.9 Release Notes (January 2026) RSA Authentication Manager Upgrade Process RSA Authentication Manager 8.7 SP2 Setup and Configuration Guide An example of SSO using SAML and ADFS with RSA Identity Management and Governance 6.9.x
Don't see what you're looking for?