Resyncing RSA SecurID tokens using RSA Authentication Manager 8.1 Self-Service Console
Originally Published: 2015-03-24
Article Number
Applies To
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.1
Issue
Resolution
To resynchonize the token,
- Login to the Self-Service Console .
- For the token serial number you want to synchronize , click Troubleshoot.
- On the Troubleshoot Your Token Page, choose Other or Not Sure and then click OK.
- On the Confirmation Required page, click Yes to confirm that the token is not damaged and can still generate tokencodes.
- On the Resynchronize Token page:
- Enter the tokencode currently showing on the token.
- Wait for the tokencode to change (typically 30 or 60 seconds) and enter the new tokencode. Please be sure to enter successive tokencodes.
- Click OK.
- Test authentication again
Notes
With this process, the Authentication Manager server determines how fast or slow the clock in the token is as compared to the server clock, which is assumed to be connected to NTP and accurate. If the server determines that the tokencodes provided during the synchronization process are correct but either for a time in the past or the future, the token offset table is updated with the offset value. The next time the token is used for authentication the offset value is used to find the correct tokencode value for that minute to determine if authentication is successful.
A token synchronization will fail for one or more of the following reasons:
- The server time is fast or slow by more than 12 hours compared to the token time. Be sure to also confirm that the server date and timezone are correct.
- The token time is fast or slow by more than 12 hours compared to the server time. Mobile devices with RSA SecurID software tokens installed typically get very accurate time information from the service provider, while RSA SecurID Software Tokens installed on desktops and laptops get their time from the BIOS, which may be incorrect or drifting.
- The token that was synchronized is not the one assigned to the user.
- An Authentication Manager administrator distributed a software token serial number again to this user or another user without the original token being replaced on the device. When a software token is redistributed, a new hash is used that invalidates the first distribution of the token.
Related Articles
Deploying RSA SecurID Tokens 28Number of Views Logout Error on the Self-Service Console in the Web Tier 16Number of Views Can RSA SecurID tokens exist in more than one RSA Authentication Manager deployment? 34Number of Views Export information regarding RSA SecurID tokens 80Number of Views BEA WebLogic 8.1 xfire.typeMappingRegistry fix 11Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide RSA Authentication Manager Upgrade Process Download RSA SecurID Access Cloud Administration audit logs using Cloud Administration REST API CLU
Don't see what you're looking for?