How to Restrict users from using certain PIN's that are less secure
Originally Published: 2018-08-01
Article Number
Applies To
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.X
Issue
Tasks
Create a password dictionary. Create a text file and enter each dictionary entry on a separate line. When you save the file, verify that the file is not larger than 20 MB.
Example
1111 2222 3333 1234 5678
Resolution
Section 1:
- In the Security Console, click Setup > System Settings.
- Under Authentication Settings, click Password Dictionary.
- Under Password Dictionary, make sure that the status is No password dictionary found. If the status is Password dictionary imported, you must first delete the existing password dictionary before adding a new one. For instructions, see Delete a Password Dictionary.
- In the Password Dictionary Name list, click Import Password Dictionary File.
- Under Password Dictionary Basics, enter the name of the password dictionary that you are importing in the Password Dictionary Name field.
- Under Password Dictionary File, browse to the password dictionary file that you are importing.
- When prompted, select the password dictionary filename, and click Open.
- Click Import File and the import process can take several minutes.
- Click Update Status to refresh. When the status shows Password dictionary imported, the name of the new password dictionary is displayed in the Password Dictionary Name list.
- Click Done.
- In the Security Console, click Authentication > Policies > Token Policies > Manage Existing.
- Use the search fields to find the token policy that you want to edit.
- From the search results, click the token policy that you want to edit.
- Click edit on the token policy dropdown.
- Navigate to section SecurID PIN Format
- Change Excluded Words Dictionary from "none" to the dictionary file imported earlier.
- Click Save.
Notes
Error: PIN change failed dictionary check
Related Articles
SecurID IIS Agent cookies rsa-csrf and rsa-local are not marked as Secure 30Number of Views Secure Connection Between Identity Router and Identity Source (AD/LDAP) Fails When DHE Cipher Suites are Used 27Number of Views Validation URI JSP files do not work when uploaded to the secured JSP Pages section in RSA Identity Governance & Lifecycle 198Number of Views Enable Secure Shell on the Appliance 47Number of Views Third-party products using RSA Authentication Agents to send authentications are failing to authenticate 67Number of Views
Don't see what you're looking for?