Offline emergency tokencode and passcodes have to be entered twice to allow a user to login
2 years ago
Originally Published: 2015-07-13
Article Number
000055085
Applies To
RSA Product Set: SecurID
RSA Product/Service Type: Authentication Agent for Windows
RSA Version/Condition: 7.2.1 build 63
Platform: Windows
Platform (Other): Windows 7 enterprise
O/S Version: Windows 7 and 8
Product Name: RSA-0010810
Product Description: RSA-0010810
Issue
When users get locked out due to incorrect passcode entry when not connected to the network, the offline emergency token and passcodes have to be entered twice to allow a user to log in. This issue is reported in Windows Agent 7.2.1.63 authenticating to AM 8.1 SP4 Patch 1.
Cause
The customer has greatly reduced the number of offline authentication failures before the user is required to provide an emergency access code down to six failures
and then deliberately entered six invalid codes so that an emergency access code is required to log in. However, this is also a sufficient number of invalid authentications
to have also locked out the user.
The Offline Authentication Service accepts both emergency access codes. However, the SecurID Authentication Code appears to consume the first code
to clear the RSA_DA_NOT_ALLOWED condition created by the customer's chosen method of testing. That is why in this scenario requires that the emergency access code be entered twice.
Resolution
This issue has been reported in defect AAWIN-2194. It has been resolved in RSA Authentication Agent 7.2.1 build 94. Contact RSA Security Technical Support to obtain the most recent build of RSA Authentication Agent 7.2.1 build 94 or greater.