RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.x
This-token-type-is-not-allowed-in-UCM
The <hostname>_server.log is located in /opt/rsa/am/server/logs. It will show the following error while creating a self-service request for enrollment with hardware token:
at weblogic.rjvm.ResponseImpl.unmarshalReturn(ResponseImpl.java:217)
at weblogic.rmi.cluster.ClusterableRemoteRef.invoke(ClusterableRemoteRef.java:338)
at weblogic.rmi.cluster.ClusterableRemoteRef.invoke(ClusterableRemoteRef.java:252)
at com.rsa.command.CommandServer_qt4u4w_EOImpl_1000_WLStub.executeFrameworkManagedTx(Unknown Source)
at com.rsa.command.EJBRemoteTargetBase$CommandExecutor.run(EJBRemoteTargetBase.java:219)
at com.rsa.command.EJBRemoteTargetBase$CommandExecutor.run(EJBRemoteTargetBase.java:168)
at weblogic.security.acl.internal.AuthenticatedSubject.doAs(AuthenticatedSubject.java:363)
at weblogic.security.service.SecurityManager.runAs(Unknown Source)
at weblogic.security.Security.runAs(Security.java:61)
Before using the self-service-request samples you must first configure the desired setting for how your self-service system will work.
The file in question come with the RSA Authentication Manager 8.x SDK that is available in the extras.zip. Review 000065842 - How to download RSA Authentication Manager 8.x full kits and service packs from RSA Community for steps to download.
These settings are found in the Security Console under Setup > Self Service Settings > Manage Authenticators in RSA Authentication Manager 8.x and above
This error can also happen when not using the SDK. A customer can set up Credential Manager > Manage Tokens to allow users to request one type of token (for example, Desktop PC 4.0) but when the user goes to the Self-Service Console he selects Generic AES. Since this is not an approved token type, the error message of "This token type is not allowed in UCM" will display. To resolve the issue simply add the correct token type.
Related Articles
Offline lockout does not get cleared by online authentication using RSA Authentication Agent 7.2.1 for Windows 49Number of Views CSV Format for User Group Membership Requests Input File 8Number of Views RSA Identity Management and Governance Activity is not created for a change item in a Change Request 51Number of Views Custom Account Attribute mapped to the Active Directory accountExpires attribute no longer collects a value after upgradin… 97Number of Views Database ID Mismatch being reported in the alert log for RSA Identity Governance & Lifecycle 42Number of Views
Trending Articles
RSA Authentication Manager 8.9 Setup and Configuration Guide How to 'Trust' the RSA Authentication Manager Security Console Self-Signed Root CA certificate and prevent Cert warnings. RSA Authentication Manager 8.9 Release Notes (January 2026) Configure RSA Authentication Manager as a Secure Proxy Server for Cloud Access Service RSA Authentication Manager Upgrade Process