Event-based Flex Token
SAE version 2.3 now support event-based tokens in addition to the traditional time-based SecurID tokens.
The acceptable range of event-based tokencodes is variable.
The "window" or range of valid authentication codes varies depending on the state of the token and values in the token's seed record. For example seed records often contain the following windowing parameters:
Small Window: 3
Medium Window: 7
Large Window: 100
Max Counter: 50000
SAE authenticates codes found inside the ?Accept Window? and rejects values outside the ?Reject Window?. Codes that fall between the accept and reject windows (where accept != reject) causes next tokencode mode.
State Accept Window Reject Window
-------- ---------------------- ---------------------
1st login Large-1 Large-1
Normal small medium
Waiting for PIN small medium
Next Tokencode Mode 2 2
Resynch (1st) max counter max counter
Resynch (2nd) 2 2
Related Articles
Authentication Manager Log Messages (26151-26185) 23Number of Views The display sequence of custom User Attribute Separators is incorrectly and unpredictably modified after making edits to U… 42Number of Views Error message "Error: java.lang.IllegalArgumentException: Window boundary must be positive" in the RSA SecurID Authenticat… 120Number of Views Monitor System Events in the Cloud Administration Console 32Number of Views OAuth 2.0-Based Permissions for the Cloud Administration APIs 77Number of Views
Trending Articles
RSA Authentication Manager 8.9 Setup and Configuration Guide How to 'Trust' the RSA Authentication Manager Security Console Self-Signed Root CA certificate and prevent Cert warnings. RSA Authentication Manager 8.9 Release Notes (January 2026) Configure RSA Authentication Manager as a Secure Proxy Server for Cloud Access Service RSA Authentication Manager Upgrade Process