Intermittent failure of AA to post challenge questions.
Originally Published: 2013-03-18
Article Number
Applies To
RSA Access Manager 6.1.3 (SP3)
Issue
The ct_challenge.jsp page is intercepting the HTTP_AAQUESTIONCOUNT server variable but it has no value. This causes the challenge page to redirect the user to the logon page.
Agent log file in debug mode shows an invalid challenge credential instead of a result "Challenge credential: QUESTION"
2013-03-09 09:10:56 -0600 - [2392740192] - <Debug> - Invalid challenge credential.
Agent displays the ct_logon.jsp page instead of the ct_challenge.jsp page
The http header is missing the request variable
The aserver debug output reports a value for SC_AA_RISK_SCORE=QUESTION, when risk score should be a string representation of an integer.
207 aserverb: 2013/03/09 09:10:56:863 [*] [MuxWorker-11 (sirrus.authserver.TCPServerAPIAdaptor.getTokenValues)] - TCPServerAPIAdaptor.getTokenValues( AAAAAgABAKDlYtCCmUU0l25rWo3OnJDQM6dZAzJ819Rnz9O2kCapBAH3Am69xRA7ZKtb8wIM4iTo5Wcw+1fkz2d4OOoc/QcgX74TO+t1zzRngaOHU0g9OJCNGyUtwWqN3g4F+4QLalJRN4JFRUSayItX7SkbNL5LVUqYQKNebCNoRdHuotCKtJILz5sBJvql2CL8Xzz8yOF4lLrsOiJvUFo7T/QwL5fe, {CLIENT_IP=172.16.100.57, CLIENT_PORT=58856, CLIENT_VERSION=11, tokens=true, groups=false, props=false} ) returning {SC_CUSTOM_DATA= , SC_IS_VALID=true, SC_AA_REQD_CREDENTIAL=, SC_USER_ID=user, SC_NT_PASSWORD=, SC_AA_PHONE_TOKEN=, SC_CLIENT_IP=192.168.0.1, SC_SECURID_PROVIDED_PIN=, SC_NT_DOMAIN=, SC_CREATION_TIME=1362841855000, SC_SECURID_STATUS=0, SC_END_USER_IP=172.16.100.1, SC_AA_SESSION_ID=-4b724558:13d4fafcb3a:-7ff1, SC_AA_STATE=AA_CHALLENGE, SC_TOUCH_TIME=1362841855000, SC_IMPERSONATED_ID=, SC_AUTH_STATE=, SC_BASIC=true, SC_AA_BIND_DEVICE=false, SC_AA_RISK_SCORE=QUESTION, SC_AA_TRANSACTION_ID=TRX_-4b724558:13d4fafcb3a:-7ff0}
Cause
Resolution
Also see a61890 "RSA Access Manger CERTIFICATE authentication does not work after idle timeout."
Workaround
Related Articles
Install SC and Grid Worker on a different drive (Not the C: drive) 40Number of Views Deleting data from Workflow tables throws error in Identity Governance & Lifecycle 28Number of Views What format is the time stored in the SC_TOUCH_TIME and SC_CREATION_TIME variables of the token within the CTSESSION cookie? 16Number of Views RSA Authentication Manager 8.2 False Positive Security Vulnerabilities 584Number of Views RSA Identity Governance and Lifecycle IDC Unification is slow in "Step 8/10: Post-Processing: Populate Role Metrics" after… 115Number of Views
Trending Articles
Downloading RSA Authentication Manager license files or RSA Software token seed records RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory Mandatory Certificate Upgrade Required by 6th October 2025 for RSA MFA Agent for PAM, RSA MFA Agent for Apache, and Third … RSA Authentication Manager 8.9 Release Notes (January 2026)
Don't see what you're looking for?