Passcode format error when trying to set a PIN thru a Cisco ASA
2 years ago
Originally Published: 2015-08-14
Article Number
000063167
Applies To
RSA Product Set: SecurID
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.1.0
Platform: N/A
Platform (Other): ESX
O/S Version: null
Product Name: RSA-0010810
Product Description: RSA-0010810
Issue
Customer upgraded his Cisco ASA 5545 to IOS 9.1 (we have also seen the same thing happen in 9.3).  This is only a problem when the ASA is configured to use SDI protocol
We have seen the following:

Passcode Format error when a user tries to set a PIN or Next token code

Unable to create a Node Secret on the ASA (the .SDI file)
Cause
The issue is with the Cisco ASA 9.X upgrade. The built in agent API don't handle challenges when using teh Cisco SDI protocol
Resolution
Changing the Authentication Protocol to Radius fixes the problem

Cisco IOS needs to upgraded to 9.3.3 or newer.