Citrix Netscaler failing to properly handle New PIN Mode and On-Demand Authentication (ODA) when using RADIUS with RSA Authentication Manager 8.x
Originally Published: 2015-06-29
Article Number
Applies To
RSA Product/Service Type: Authentication Manager
Issue
In the On-Demand Authentication (ODA) scenario, the user is not getting the email or SMS with the tokencode after entering the correct PIN. Below is a detailed description of the issue:
- The user connects to the Citrix portal, and is prompted for his user ID, tokencode or PIN (if using ODA).
- The user is asked to create a new PIN then prompted to re-enter the PIN.
- Citrix responds that the new PIN has been accepted and to wait for the tokencode to change, then enter the new passcode (PIN + tokencode) and click Submit.
- When the user enters the next passcode, an Access Denied message displays.
Cause
Resolution
Workaround
Option 1
The securid.ini file that handles the messaging can be edited so that the steps users need to take are more clear. Editing this file will change the messaging seen by users to all RADIUS clients. Citrix article CTX124374 on how to modify the RSA token prompts displayed by NetScaler Gateway has information on how to make the required changes to the securid.ini directly on a Windows server. RSA Authentication Manager admins can make the change through the Operations Console using the steps below.- Login to the Operations Console.
- Select Deployment Configuration > RADIUS Servers.
- Click on the drop-down next to the RADIUS primary and choose Manage Server Files.
- Click on the arrow next to the securid.ini file and select Edit.
- Following the steps in the Citrix article above, edit the ExtInputNextCode value, the ExtOutputChange value or both. Note that there is a 255-character maximum for the message.
- When done, click Save and Restart RADIUS Server.
- Repeat steps 1 through 6 for any replicas in the deployment.
Option 2
Refresh the Citrix webpage after setting the new PIN. The user can typically authenticate normally with the passcode (PIN+tokencode).
Option 3
In the case of ODA, refreshing the page will trigger a new email or SMS that will be sent to the user.Notes
Related Articles
RSA Authentication Manager 8.5 Bulk Administration Utility (AMBA) Guide 16Number of Views RSA Authentication Manager 8.4 Bulk Administration Utility (AMBA) Guide 32Number of Views Adding a Palo Alto RADIUS dictionary to RSA RADIUS for RSA Authentication Manager 8.x 788Number of Views Radius Client Authentication failed For PIN+Token profile (New PIN Mode) with Cisco Anyconnect VPN 117Number of Views How to configure an RSA Authentication Manager 8.1 server to accept a system-generated PIN when a token is in new PIN mode… 290Number of Views
Trending Articles
Downloading RSA Authentication Manager license files or RSA Software token seed records RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory Mandatory Certificate Upgrade Required by 6th October 2025 for RSA MFA Agent for PAM, RSA MFA Agent for Apache, and Third … RSA Authentication Manager 8.9 Release Notes (January 2026)
Don't see what you're looking for?