RSA SecurID Authenticator 6.0 and 6.1 for Windows fails to import aCT-KIP URL
Originally Published: 2024-08-29
Article Number
Applies To
RSA Product/Service Type: Authentication Manager, SecurID Authenticator 6.0, 6.1 for Microsoft Windows
Issue
- When importing the RSA SecurID tokens via CT-KIP URL through an email, the link is not recognized.
- The Submit button in the RSA SecurID Authenticator application is greyed out and unclickable. The token cannot be imported.
Cause
https://<Your_AM_Server_FQDN>:7004/ctkip/services/CtkipService or http://<Your_AM_Server_FQDN>:7004/ctkip/services/CtkipService
However, the RSA SecurID Authenticator for Windows 6.0 and 6.1 accepts only the auto launch URL that starts with the string securidauthenticator, as shown:
securidauthenticator://ctkip?scheme=https&url=<Your_AM_Server_FQDN>:7004/ctkip/services/CtkipService
Resolution
RSA SecurID Authenticator 6.2 and later releases of the Authenticator Application for Microsoft Windows have a fix to the issue so that it successfully imports the CT-KIP URL that was distributed using the legacy Desktop PC 4.x device type Software Token Profile
Workaround
- Download the SecurID Authenticator 6.0.1 Microsoft Windows Device Definition File.
- Extract the contents of the file.
- In the Security Console, navigate to Authentication > Software Token Profiles > Add New.
- Enter the Profile Name and click Import Device Definition File.
- Import the Desktop-Windows-SecurID-Authenticator-swtd.xml from the extracted file in step 2.
- Click Save.
- Now when distributing a token using the new Software Token Profile via CT-KIP URL, the URL will be in the format accepted by SecurID Authenticator 6.0 and 6.1 for Windows, and that the SecurID token will be imported successfully.
Notes
Related Articles
Is RSA AA compliant with Federal Act 508 54Number of Views CT-KIP activation using Admin API does not display the tokens as activated on Self-service portal 20Number of Views Configure Token Settings 28Number of Views How to query a public database schema table for Segregation of Duties (SOD) violations in RSA Identity Governance & Lifecycle 101Number of Views In RSA Identity Governance & Lifecycle, a SQL exception error in the UI is encountered when saving Delay node on a Workflow 118Number of Views
Trending Articles
RSA Authentication Manager Upgrade Process RSA Release Notes for RSA Authentication Manager 8.8 RSA RADIUS Server service failed to start in the RSA Authentication Manager 8.1 Operations Console Microsoft Entra ID External MFA - Relying Party Configuration Using OIDC - RSA Ready Implementation Guide RSA Release Notes: Cloud Access Service and RSA Authenticators
Don't see what you're looking for?