Citrix Netscaler failing to properly handle New PIN Mode and On-Demand Authentication (ODA) when using RADIUS with RSA Authentication Manager 8.x
Originally Published: 2015-06-29
Article Number
Applies To
RSA Product/Service Type: Authentication Manager
Issue
In the On-Demand Authentication (ODA) scenario, the user is not getting the email or SMS with the tokencode after entering the correct PIN. Below is a detailed description of the issue:
- The user connects to the Citrix portal, and is prompted for his user ID, tokencode or PIN (if using ODA).
- The user is asked to create a new PIN then prompted to re-enter the PIN.
- Citrix responds that the new PIN has been accepted and to wait for the tokencode to change, then enter the new passcode (PIN + tokencode) and click Submit.
- When the user enters the next passcode, an Access Denied message displays.
Cause
Resolution
Workaround
Option 1
The securid.ini file that handles the messaging can be edited so that the steps users need to take are more clear. Editing this file will change the messaging seen by users to all RADIUS clients. Citrix article CTX124374 on how to modify the RSA token prompts displayed by NetScaler Gateway has information on how to make the required changes to the securid.ini directly on a Windows server. RSA Authentication Manager admins can make the change through the Operations Console using the steps below.- Login to the Operations Console.
- Select Deployment Configuration > RADIUS Servers.
- Click on the drop-down next to the RADIUS primary and choose Manage Server Files.
- Click on the arrow next to the securid.ini file and select Edit.
- Following the steps in the Citrix article above, edit the ExtInputNextCode value, the ExtOutputChange value or both. Note that there is a 255-character maximum for the message.
- When done, click Save and Restart RADIUS Server.
- Repeat steps 1 through 6 for any replicas in the deployment.
Option 2
Refresh the Citrix webpage after setting the new PIN. The user can typically authenticate normally with the passcode (PIN+tokencode).
Option 3
In the case of ODA, refreshing the page will trigger a new email or SMS that will be sent to the user.Notes
Related Articles
How to remove endpoint agents from RSA Data Loss Prevention 9.6 and later that have been inactive for a long time from Ent… 10Number of Views RSA Identity Governance & Lifecycle menus do not display correctly in Internet Explorer (IE) 11 when using Compatibility V… 132Number of Views RSA MFA Agent for Windows logs a warning that "System cannot access location data for this computer" 35Number of Views User cannot change password with an error Read ONLY external database. 40Number of Views Active Directory ADCs intermittently fail with 'LDAP response read timed out' errors in RSA Identity Governance & Lifecycle 171Number of Views
Trending Articles
Download RSA SecurID Access Cloud User Event audit logs using Cloud Administration REST API CLU RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory Authentication Manager Security Console and Operations Console Inaccessible After Certificate Update Authentication Manager How to Retrieve the LDAPS Certificate and Configure an External Identity Source to Use LDAPS
Don't see what you're looking for?