Troubleshooting RSA SecurID Software Token for BlackBerry deployment by CT-KIP
Originally Published: 2010-03-01
Article Number
Applies To
RSA Product/Service Type: RSA Software Token for BlackBerry
RSA Version/Condition: 3.5.1
Issue
Cause
You cannot use Dynamic Seed Provisioning to distribute software tokens to devices running the VPN version of the RSA SecurID Token application.
The IT policy requirement is as follows:
| IT Policy Name | IT Policies for Automating a Token Import Through CT-KIP |
| Values | RSASecurIDCTKIPURL |
| Description | Null (default) |
| Type | Server URL |
Specify a server URL for downloading tokens through Dynamic Seed Provisioning (CT-KIP) so that users do not have to enter the URL in their BlackBerry devices to import a token. Strings can contain up to 200 characters. For example, below are the CT-KIP credentials (for the last token distribution by CT-KIP):
| Activation Code | 24B5849B |
| Token Generation URL | https://rsaserver.mycompany.com:7004/ctkip/trigger.jsp?authcode=24B5849B&url=https://fbrsa1.faegre.com:7004/ctkip/services/CtkipService |
| Service Address | https://rsaserver.mycompany.com:7004/ctkip/services/CtkipService |
| Activation Code Date | Fri Feb 26 14:31:34 CST 2010 |
- The RSA Software Token for BlackBerry token import fails during the first attempt using the CT-KIP download and works fine the second time. The release notes for RSA Software Token 3.0.2 for BlackBerry describes this behavior in the 8700 model. However, this has been noted in other newer models too. This has been resolved in RSA Software Token 3.5 for BlackBerry.
- Download RSA Software Token 3.5.1 for BlackBerry. You can download RSA Software Token 3.5 for BlackBerry devices directly to the BlackBerry device by clicking here.
- Automatic download of a token to a device using CT-KIP works only one time. If a token is deleted and you try to import the new token, the RSA token application must be launched and the Import Token option should be used.
- If there is a problem in downloading application, verify you can launch www.google.com and www.yahoo.com from the same device. Verify that the third-party software installation is allowed on the device. This is disabled on BES server in IT policy.
- CT-KIP requests can be configured with http as well. (default request URL works with https). The http URL can be mentioned on BES server IT policy.
- The Service Address URL should be sent to end users by email.
Related Articles
Reporting on SecurID software tokens with software token lifetime extension in RSA Authentication Manager 8.x 950Number of Views Deploying customized configurations in Soft ID v1.x. 28Number of Views SQL Server data collectors in RSA Identity Governance & Lifecycle periodically fail with connection timed out errors 168Number of Views Software Token Distribution 231Number of Views How to automatically distribute a soft token to Android with AMBA via CT-KIP 496Number of Views
Trending Articles
RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA Authentication Manager 8.9 Release Notes (January 2026) How to install the jTDS JDBC driver on WildFly for use with Data Collections in RSA Identity Governance & Lifecycle RSA Authentication Manager 8.8 Setup and Configuration Guide Artifacts to gather in RSA Identity Governance & Lifecycle
Don't see what you're looking for?