Single sign-on with RSA SecurID Access is failing intermittently
Originally Published: 2017-06-01
Last Modified: 2022-06-20
Article Number
Applies To
RSA Product/Service Type: Identity Router
Issue
The error following error is displayed when this occurs:
Application appears to be improperly configured. Contact your Administrator for assistance.
Retrying the login attempt eventually works.Cause
Intermittent SSO failures are typically caused when session persistence is not being done by the load balancer. This could be due to a load balancer configuration problem or some other reason.
Resolution
- Check your load balancer configuration to ensure it is set for session persistence, as described in Load Balancer Requirements. If you have a NetScaler load balancer, see Netscaler Load Balancing Configuration for RSA Via Access IDR Cluster.
- Check that your IDRs and the load balancer as well, all have their time synchronized to an NTP server. Depending on the method used by your load balancer for session persistence, a time of day discrepancy between it and the IDRs could hinder it from recognizing existing sessions. See How to check if NTP is working on your RSA SecurID Access Identity Router.
- If session duration is too short, it can also force users to re-authenticate frequently. Check how to Configure Session and Authentication Method Settings to set Session Duration for User Sessions.
Related Articles
How to SecurID-protect OWA using single sign-on (SSO) when OWA is in a cluster 207Number of Views User Session and Single Sign-On 45Number of Views XML Parsing Error when attempting SP-initiated Single Sign-On with RSA SecurID Cloud Authentication Service 226Number of Views RSA Identity Governance and Lifecycle7.0.2 installation with remote database fails with "Invalid Username/Password" in the… 210Number of Views Scheduled custom reports are intermittently failing and generating blank reports in RSA Identity Governance & Lifecycle 173Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Manual synchronization introduced in RSA Authentication Manager 8.2 Service Pack 1 patch 6 Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory How to verify NTP server synchronization is not working in RSA Authentication Manager 8.x RSA Governance & Lifecycle 8.0.0 Installation Guide
Don't see what you're looking for?