Users cannot authenticate successfully when the RSA SecurID token is in either Next Tokencode Mode or New PIN Mode when authentications originate from an IBM WebSeal in RSA Authentication Manager 8.x
Originally Published: 2015-10-21
Article Number
Applies To
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.x
Platform: IBM WebSEAL 6.1.1.x
Platform (Other): IBM Security Access Manager (formerly called IBM Tivoli Access Manager)
Issue
- Users cannot authenticate successfully when the RSA SecurID token is in either Next Tokencode Mode or New PIN Mode when authentications originate from an IBM WebSeal in RSA Authentication Manager 8.x.
- If the token is not in Next Tokencode Mode or New Pin Mode, authentication is successful.
- Underlying the IBM WebSeal is the RSA Authentication Agent for PAM.
- Both Next Tokencode Mode and New PIN Mode work as expected with the PAM acetest utility.
- Therefore, the problem is specific to using WebSEAL.
Cause
Resolution
- Create a new setting in the WebSEAL configuration.
create-unauth-sessions = yes
- Restart the WebSEAL application.
This will allow for successful authentications when a token is in either Next Tokencode Mode or New PIN Mode.
Notes
If consulting with IBM Support, reference IBM PMR 40092,122,000 for more information.
Related Articles
IBM Security Verify - RSA Ready Implementation Guide 10Number of Views RSA Identity Governance and Lifecycle - IBM RACF Collector Datasheet 16Number of Views RSA Governance & Lifecycle IBM Tivoli Directory Server (ITDS) Connector Datasheet Guide 5Number of Views How to disable SecurID Tokens before they go into Next Token Mode 149Number of Views RSA Identity Governance and Lifecycle - IBM RACF SSH Connector Datasheet 12Number of Views
Trending Articles
Passwordless Authentication in Windows MFA Agent for Active Directory – Quick Setup Guide RSA Authentication Manager 8.9 Release Notes (January 2026) RSA Authentication Manager Upgrade Process RSA Authentication Manager 8.7 SP2 Setup and Configuration Guide An example of SSO using SAML and ADFS with RSA Identity Management and Governance 6.9.x
Don't see what you're looking for?