Troubleshooting RSA SecurID Software Token for BlackBerry deployment by CT-KIP
Originally Published: 2010-03-01
Last Modified: 2023-10-06
Article Number
Applies To
RSA Product/Service Type: RSA Software Token for BlackBerry
RSA Version/Condition: 3.5.1
Issue
Cause
You cannot use Dynamic Seed Provisioning to distribute software tokens to devices running the VPN version of the RSA SecurID Token application.
The IT policy requirement is as follows:
| IT Policy Name | IT Policies for Automating a Token Import Through CT-KIP |
| Values | RSASecurIDCTKIPURL |
| Description | Null (default) |
| Type | Server URL |
Specify a server URL for downloading tokens through Dynamic Seed Provisioning (CT-KIP) so that users do not have to enter the URL in their BlackBerry devices to import a token. Strings can contain up to 200 characters. For example, below are the CT-KIP credentials (for the last token distribution by CT-KIP):
| Activation Code | 24B5849B |
| Token Generation URL | https://rsaserver.mycompany.com:7004/ctkip/trigger.jsp?authcode=24B5849B&url=https://fbrsa1.faegre.com:7004/ctkip/services/CtkipService |
| Service Address | https://rsaserver.mycompany.com:7004/ctkip/services/CtkipService |
| Activation Code Date | Fri Feb 26 14:31:34 CST 2010 |
- The RSA Software Token for BlackBerry token import fails during the first attempt using the CT-KIP download and works fine the second time. The release notes for RSA Software Token 3.0.2 for BlackBerry describes this behavior in the 8700 model. However, this has been noted in other newer models too. This has been resolved in RSA Software Token 3.5 for BlackBerry.
- Download RSA Software Token 3.5.1 for BlackBerry. You can download RSA Software Token 3.5 for BlackBerry devices directly to the BlackBerry device by clicking here.
- Automatic download of a token to a device using CT-KIP works only one time. If a token is deleted and you try to import the new token, the RSA token application must be launched and the Import Token option should be used.
- If there is a problem in downloading application, verify you can launch www.google.com and www.yahoo.com from the same device. Verify that the third-party software installation is allowed on the device. This is disabled on BES server in IT policy.
- CT-KIP requests can be configured with http as well. (default request URL works with https). The http URL can be mentioned on BES server IT policy.
- The Service Address URL should be sent to end users by email.
Related Articles
How to troubleshoot CT-KIP failures in Authentication Manager 8.x 187Number of Views Importing a token via CT-KIP fails indicating that the token already exists 94Number of Views RSA SecurID token import via CT-KIP URL does not work using Authentication Manager Bulk Admin 1.6 on Authenitcation Manage… 67Number of Views RSA SecurID Authenticator 6.0 and 6.1 for Windows fails to import aCT-KIP URL 72Number of Views Deployment Manager request for a token results in Auth Manager looping message 'Listed one token' and 'Listed range of tok… 2Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Reporting on RSA Authentication Manager 8.x users with On-Demand Token, a fixed passcode or a hardware/software token assi… How to Download OTP Token Seed Files from myRSA Anomalix idGenius - SAML Relying Party Configuration - RSA Ready Implementation Guide RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide
Don't see what you're looking for?