RSA Authentication Agent 8.6 API does not prompt for passcode with Epic Hyperspace 2016 on Windows Server
Originally Published: 2017-05-23
Article Number
Applies To
RSA Product/Service Type: Authentication Agent API
RSA Version/Condition: 8.5, 8.6
Issue
Cause
An older version of this problem might have been caused by not copying the aceclnt.dll and the sdmsgs.dll to the Windows Server with the Agent API 8.5 or 8.6, such as Epic Hyperspace.
Resolution
- Find the spelling mistake in the rsa_api.properties file. The rsa_api.properties file contains entries such as:
RSA_AGENT_NAME = <hostname> SDCONF_LOC = C:\ProgramData\Epic\RSA\sdconf.rec RSA_LOG_FILE_LOC = C:\scripts\Log
The sharp (#) in front marks the line not parsed or is a comment.
- If there is a spelling mistake or a path is wrong or non-existent, the RSA passcode prompt does not display, so you have to find the mistake. One easy trick is to comment out lines with the # until the RSA prompt finally displays. For example, if the following entry for SysWOW64 is in the file, but you are on a 32-bit system, \Windows\SysWOW64 does not exist, and will prevent the RSA prompt from displaying, so comment this line out as a test. Change from:
RSA_BSAFE_LIBRARY_PATH = C:\Windows\SysWOW64
to
#RSA_BSAFE_LIBRARY_PATH = C:\Windows\SysWOW64
- When done, save the changes and test.
- Repeat steps above until the passcode prompt displays.
Notes
- Copy the following files to C:\Program Files (x86)\Epic\v8.3\Shared Files:
- aceclnt.dll
- aceclnt_tcp.dll
- ccme_asym.dll
- ccme_base.dll
- cryptocme.dll
- cryptocme.sig
- sdmsg.dll
- xeres-c_3_1_vc80.dll
- Add RSA_BSAFE_LIBRARY_PATH = C:\Program Files (x86)\Epic\v8.3\Shared Files to the rsa_api.properties file.
One customer was using Citrix VDI desktops to deploy their Epic Hyperspace servers, but these were 32-bit VDIs, and did not have a C:\Program Files (x86)\Epic\v8.3\Shared Files, so this line was the cause of the missing RSA prompt, and needed to be customized in this case to C:\Program Files\Epic\v8.3\Shared Files
Also, because these VDIs were deployed in large numbers from a standard or gold image, the gold image commented out the #RSA_AGENT=<hostname> even though the implementation guide said to change it to the FQDN. However autoregistration worked with TCP to read the system FQDN and use that for logging and to register.
Related Articles
RSA Authentication Agent 8.0 for Web for Internet Information Services Generates HTTP Error 500.21 24Number of Views Integrating Vormetric Data Security Manager with RSA Authentication Manager 8.x 73Number of Views RSA Governance & Lifecycle EPIC EMR Implementation Blueprint 9Number of Views Risk-Based Authentication from Cisco ASA 9.3.1 redirects to wrong URL for RSA Authentication Manager 8.1 186Number of Views Service cannot start after Patch upgrade or reboot 95Number of Views
Trending Articles
RSA Authentication Manager Upgrade Process RSA Release Notes for RSA Authentication Manager 8.8 RSA RADIUS Server service failed to start in the RSA Authentication Manager 8.1 Operations Console Microsoft Entra ID External MFA - Relying Party Configuration Using OIDC - RSA Ready Implementation Guide RSA Release Notes: Cloud Access Service and RSA Authenticators
Don't see what you're looking for?