Radius agent uses old shared secret even after new shared secret is updated in Authentication Manager database
Last Modified: 2023-10-06
Article Number
Applies To
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.x
Issue
Explanation:
When changing radius shared secret, it will be updated in Authentication Manager database. To verify this point, access database following article https://community.rsa.com/t5/securid-knowledge-base/how-to-run-a-sql-query-for-authentication-manager-8-0-or-8-1-and/ta-p/8449
Then run command: < select client_name, ip_address, shared_secret from am_radius_clients; >
The old shared secret would still be used for an amount of time that can be configured using option “lifetime” in radius configuration file “dynamic-clients”.
This option is responsible on refreshing radius agents every certain time. (Default 600 seconds)
Resolution
Change “lifetime” to smaller value for IPv4. (This could be done for ipv6 if needed) > Save & Restart RADIUS Server.
For more information about “dynamic-clients” configuration file, please check the corresponding RSA Authentication Manager RADIUS Reference Guide.
Workaround:
Restarting radius service from CLI would refresh radius agent with new shared secret.
https://community.rsa.com/t5/securid-knowledge-base/how-to-stop-start-and-restart-rsa-authentication-manager-8-x/ta-p/5136
Related Articles
Grouping Users By Business Unit shows the old Business Unit name in RSA Identity Governance & Lifecycle 7.0.2 25Number of Views Old Radius Shared Secret is still in use even after changing it in agent record from Security Console 101Number of Views Save Review Items count is not matching the selected items in RSA Identity Management and Governance 24Number of Views Replaced default Web Tier certificate but old certificate is presented in RSA Authentication Manager 8.x 425Number of Views Information on Authentication Manager 8.x and the use of OpenSSL (old) 297Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Reporting on RSA Authentication Manager 8.x users with On-Demand Token, a fixed passcode or a hardware/software token assi… How to Download OTP Token Seed Files from myRSA Anomalix idGenius - SAML Relying Party Configuration - RSA Ready Implementation Guide RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide
Don't see what you're looking for?