Multiple RADIUS Requests Result in LDAP Authentication Failure
2 months ago
Article Number
000067988
Applies To
RSA Product Set:  SecurID Access
RSA Product/Service Type:  Identity Router
RADIUS Client: Any
Issue

When the user enters the username and password and then waits for the additional authentication according to the policy applied on this RADIUS client:
1. The user event monitor on the cloud side shows "LDAP password authentication succeeded", followed a the successful authentication flow: Multifactor authentication initiated > Approve authentication succeeded > Multifactor authentication succeeded
3. After that an error is shown "LDAP password authentication failed - Logon failure: Unknown username or invalid password"

The user is subsequently logged out despite successful authentication.

Cause
This happens because the timeout at the RADIUS client is less than 60 seconds.
Resolution

Refer to the RADIUS client integration guide specific to your configuration.
1. Open the RADIUS configurations on the client side.
2. Search for a timeout field.
3. Make sure that the timeout is set to 60 seconds or you can check the default value if you find an integration guide from the previous link.

For example:
User-added image

Notes

The timeout should be adjusted from the RADIUS client side, not from the RSA side.