RSA Authentication Manager 8.1 SP1 On Demand Authentication requires that the initial PIN be set in the Self-Service Console fails because there is no PIN yet
Originally Published: 2016-08-02
Article Number
Applies To
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.1 SP1 and later
Issue
- Once the user is enabled for ODA, he cannot use the Self Service Console (SSC) to set his PIN because the SSC is prompting for a PIN after the user enters his password.
- As shown here, the Self-Service Console (SSC) logon screen requests Jay's user ID and password.
- The SSC then prompts Jay to enter an existing PIN rather than asking him to create a new PIN.
- Logon fails because a PIN is not set yet. Using a blank PIN or a PIN of 0000 also fails.
- In the Security Console, the enable ODA options show a choice between:
- Require user to setup the PIN through RSA Self-Service Console
- System generate initial PINs for selected users and export them to a file
- The option of system generated initial PIN only worked in Authentication Manager 7.1. All the Authentication Manager 8.1 systems here show that the option is:
Set initial PIN to [ ] (Pin needs to be communicated to user)
- This works if we use the System Generate PINs option. We download the file, logon to the SSC with a password, enter the PIN, then create a new PIN.
- If we select Require user to setup the PIN, and the user logs on to the Security Console, he is prompted to enter a PIN, even though Security Console says PIN not set. Nothing works and the user sees a message of either logon failed or if the PIN is blank, that the field is required
Cause
Resolution
- Manually set ODA user PINs in the Security Console or with the Authentication Manager Bulk Administration (AMBA) tool; or
- Change the Self-Service logon requirements to not enforce an ODA logon, either by removing it completely or by making it optional with the OR operator (that is, /).
Workaround
- Generate PINs for the users.
- Communicate the PINs in a secure manner to the end users.
Related Articles
Initial Troubleshooting Steps for CProfileUpdater Not Working in RSA Web Threat Detection 18Number of Views Set an Initial On-Demand Authentication PIN for a User 41Number of Views AFX Server on Windows fails to stop/start after initial successful start in RSA Governance & Lifecycle 153Number of Views How to reset table views to their original factory-set (OOTB) defaults in RSA Identity Governance & Lifecycle 33Number of Views RSA Cloud Authentication Service Initial Setup Videos 28Number of Views
Don't see what you're looking for?