User password not saved when password integration is implemented with RSA Authentication Agent for Citrix StoreFront when logging with Risk Based Authentication in RSA Authentication Manager 8.4
Originally Published: 2019-10-08
Article Number
Applies To
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.4.0
Issue
Enable verbose logging on RSA Authentication Manager and perform a RBA authentication.
You will notice below errors in opt/rsa/am/server/logs/imsTrace.log.
2019-04-11 10:58:56,440, [OARequestHandler1], (DataObjectAccessSql.java:552), trace.com.rsa.authmgr.internal.admin.common.dal.sql.DataObjectAccessSql, ERROR, sprsaam.saintpetersuh.com,,,,failed to lookup domain object of class:class com.rsa.authmgr.internal.admin.principalmgt.dal.AMPrincipal by GUID:e4263e071500cb0a1b2f26efd6e2c7a6
2019-04-11 10:58:56,441, [OARequestHandler1], (OAProcessor.java:1), trace.com.rsa.authmgr.internal.oa.engine.OAProcessor, WARN, sprsaam.saintpetersuh.com,,,,Unexpected exception during processing: PW_UPDATE_NOT_ALLOWED
com.rsa.authmgr.internal.oa.OAException: User 'venjbeverly' or agent '10.200.48.46' could not be found.
at com.rsa.authmgr.internal.oa.engine.PasswordProcessor$1.doOperation(PasswordProcessor.java:14)
at com.rsa.authmgr.internal.oa.engine.db.OACallback.doInTransaction(OACallback.java:5)
at org.springframework.transaction.support.TransactionTemplate.execute(TransactionTemplate.java:131)
at com.rsa.authmgr.internal.oa.engine.db.DBUtil.doInTransaction(DBUtil.java:13)
at com.rsa.authmgr.internal.oa.engine.PasswordProcessor.doRun(PasswordProcessor.java:13)
at com.rsa.authmgr.internal.oa.engine.OAProcessor.run(OAProcessor.java:47)
at com.rsa.authmgr.internal.oa.RequestReceiver.a(RequestReceiver.java:45)
at com.rsa.authmgr.internal.oa.RequestReceiver$1.run(RequestReceiver.java:4)
at com.rsa.ims.security.spi.SimpleSecurityContextImpl.doAs(SimpleSecurityContextImpl.java:80)
at com.rsa.security.SecurityContext.doAs(SecurityContext.java:412)
at com.rsa.authmgr.internal.oa.RequestReceiver.handleConnection(RequestReceiver.java:98)
at com.rsa.authmgr.internal.common.server.TCPServer$TCPServerTask.run(TCPServer.java:689)
at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1149)
at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:624)
at java.lang.Thread.run(Thread.java:748)
at com.rsa.authmgr.internal.common.server.TCPServer$TCPServerThread.run(TCPServer.java:764)
2019-04-11 10:58:56,442, [OARequestHandler1], (RequestReceiver.java:44), trace.com.rsa.authmgr.internal.oa.RequestReceiver, ERROR, sprsaam.saintpetersuh.com,,,,Error handling OA request
com.rsa.authmgr.internal.oa.OAException: User 'venjbeverly' or agent '10.200.48.46' could not be found.
at com.rsa.authmgr.internal.oa.engine.PasswordProcessor$1.doOperation(PasswordProcessor.java:14)
at com.rsa.authmgr.internal.oa.engine.db.OACallback.doInTransaction(OACallback.java:5)
Cause
Resolution
To do this,
- Login to the Security Console on the primary.
- Navigate to Identity > Users > Manage Existing.
- Search for your user(s).
- From the context arrow, click Edit.
- Without making changes, click Save.
Workaround
- Click the user name again.
- In the drop down menu click User Authentication Settings.
- Put a check in Clear cached copy of selected user's Windows credentials then click Save.
Doing this creates the additional user data in the am_principal table and password integration works. Simply, if a user record is edited and closed it also helps.
Related Articles
RBA logon through RSA Authentication Agent for Citrix StoreFront 1.0 fails with "Cannot complete request" 88Number of Views How to copy and paste text into workflow nodes on RSA Identity Management & Governance 6.9.1 2Number of Views How to increase the chances of successfully configuring Citrix Delegated Forms Authentication (DFA) with the RSA Authentic… 158Number of Views RSA MFA Agent 3.0 for Citrix StoreFront Release Notes 44Number of Views Entitlements Server error when logging into or starting the RSA Access Manager Administration Console 8Number of Views
Trending Articles
RSA Authentication Manager Upgrade Process RSA Release Notes for RSA Authentication Manager 8.8 RSA RADIUS Server service failed to start in the RSA Authentication Manager 8.1 Operations Console Microsoft Entra ID External MFA - Relying Party Configuration Using OIDC - RSA Ready Implementation Guide RSA Release Notes: Cloud Access Service and RSA Authenticators
Don't see what you're looking for?