User password not saved when password integration is implemented with RSA Authentication Agent for Citrix StoreFront when logging with Risk Based Authentication in RSA Authentication Manager 8.4
Originally Published: 2019-10-08
Article Number
Applies To
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.4.0
Issue
Enable verbose logging on RSA Authentication Manager and perform a RBA authentication.
You will notice below errors in opt/rsa/am/server/logs/imsTrace.log.
2019-04-11 10:58:56,440, [OARequestHandler1], (DataObjectAccessSql.java:552), trace.com.rsa.authmgr.internal.admin.common.dal.sql.DataObjectAccessSql, ERROR, sprsaam.saintpetersuh.com,,,,failed to lookup domain object of class:class com.rsa.authmgr.internal.admin.principalmgt.dal.AMPrincipal by GUID:e4263e071500cb0a1b2f26efd6e2c7a6
2019-04-11 10:58:56,441, [OARequestHandler1], (OAProcessor.java:1), trace.com.rsa.authmgr.internal.oa.engine.OAProcessor, WARN, sprsaam.saintpetersuh.com,,,,Unexpected exception during processing: PW_UPDATE_NOT_ALLOWED
com.rsa.authmgr.internal.oa.OAException: User 'venjbeverly' or agent '10.200.48.46' could not be found.
at com.rsa.authmgr.internal.oa.engine.PasswordProcessor$1.doOperation(PasswordProcessor.java:14)
at com.rsa.authmgr.internal.oa.engine.db.OACallback.doInTransaction(OACallback.java:5)
at org.springframework.transaction.support.TransactionTemplate.execute(TransactionTemplate.java:131)
at com.rsa.authmgr.internal.oa.engine.db.DBUtil.doInTransaction(DBUtil.java:13)
at com.rsa.authmgr.internal.oa.engine.PasswordProcessor.doRun(PasswordProcessor.java:13)
at com.rsa.authmgr.internal.oa.engine.OAProcessor.run(OAProcessor.java:47)
at com.rsa.authmgr.internal.oa.RequestReceiver.a(RequestReceiver.java:45)
at com.rsa.authmgr.internal.oa.RequestReceiver$1.run(RequestReceiver.java:4)
at com.rsa.ims.security.spi.SimpleSecurityContextImpl.doAs(SimpleSecurityContextImpl.java:80)
at com.rsa.security.SecurityContext.doAs(SecurityContext.java:412)
at com.rsa.authmgr.internal.oa.RequestReceiver.handleConnection(RequestReceiver.java:98)
at com.rsa.authmgr.internal.common.server.TCPServer$TCPServerTask.run(TCPServer.java:689)
at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1149)
at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:624)
at java.lang.Thread.run(Thread.java:748)
at com.rsa.authmgr.internal.common.server.TCPServer$TCPServerThread.run(TCPServer.java:764)
2019-04-11 10:58:56,442, [OARequestHandler1], (RequestReceiver.java:44), trace.com.rsa.authmgr.internal.oa.RequestReceiver, ERROR, sprsaam.saintpetersuh.com,,,,Error handling OA request
com.rsa.authmgr.internal.oa.OAException: User 'venjbeverly' or agent '10.200.48.46' could not be found.
at com.rsa.authmgr.internal.oa.engine.PasswordProcessor$1.doOperation(PasswordProcessor.java:14)
at com.rsa.authmgr.internal.oa.engine.db.OACallback.doInTransaction(OACallback.java:5)
Cause
Resolution
To do this,
- Login to the Security Console on the primary.
- Navigate to Identity > Users > Manage Existing.
- Search for your user(s).
- From the context arrow, click Edit.
- Without making changes, click Save.
Workaround
- Click the user name again.
- In the drop down menu click User Authentication Settings.
- Put a check in Clear cached copy of selected user's Windows credentials then click Save.
Doing this creates the additional user data in the am_principal table and password integration works. Simply, if a user record is edited and closed it also helps.
Related Articles
Replace Users' Windows Password with an RSA SecurID Passcode 106Number of Views Clear the Cached Copy of a User's Windows Password 45Number of Views Deployment Considerations for Risk-Based Authentication 15Number of Views RSA Authentication Manager 8.2 Patch 4 Readme 20Number of Views Unexpected additional authentication methods displayed by the RSA MFA Agent or a custom RSA Authentication API client 11Number of Views
Trending Articles
RSA Authentication Manager 8.9 Setup and Configuration Guide How to 'Trust' the RSA Authentication Manager Security Console Self-Signed Root CA certificate and prevent Cert warnings. RSA Authentication Manager 8.9 Release Notes (January 2026) Configure RSA Authentication Manager as a Secure Proxy Server for Cloud Access Service RSA Authentication Manager Upgrade Process
Don't see what you're looking for?