JohnMcKellep (Customer) asked a question.

our province is moving permanently to daylight savings time so we will not be adjusting our clocks this fall. my date/time setting source is our ntp servers. is there anything internally in the rsa software that makes the time adjustment?

  • @JohnMcKellep (Customer)​ ,

     

    Authentication Manager doesn't have its own setting for daylight saving time. It uses the time zone configured on the appliance's operating system, NTP and time zone rules built into the OS.

     

    How the time adjustment works

    • NTP servers only supply UTC time. They don't send any daylight saving information. The one-hour shift is applied locally, based on the time zone chosen in the Operations Console under Administration > Date & Time.
    • If your time zone observes daylight saving, the Location field shows two UTC offsets, for example "(UTC-06/UTC-05) Winnipeg." That means the appliance will change its clock twice a year.
    • What to expect if no changes are made. If the appliance's time zone rules haven't been updated for your province's change, it will still fall back one hour at 2:00 AM. on November 1, 2026.
    • You can check timezone values in the Operations Console or by running timedatectl show -p Timezone --value on the server.

     

    SecurID tokencodes are calculated from UTC, so authentication itself should not be affected. However, the local time shown in logs, reports, the administrative consoles and scheduled jobs would be off by one hour.

     

    You can switch to a fixed-offset time zone before November 1. Choose a time zone that doesn't observe daylight saving and matches your province's new permanent offset:

     

    • British Columbia (UTC-7): America/Whitehorse or America/Phoenix
    • Alberta (UTC-6): America/Regina
    • Manitoba (UTC-5): America/Panama or America/Bogota

     

    To change the time zone:

    Services will restart, so plan a maintenance window to complete this work:

    1. Go to Administration > Date & Time in the Operations Console.
    2. Click Edit, select the new Region and Location.
    3. Click Save & Restart.
    4. Repeat this on each primary and replica instance.

     

    IMPORTANT NOTE: Only the time zone changes, not the actual system time. The zone name shown in logs and reports will also change.

    Expand Post
    Selected as Best
  • @JohnMcKellep (Customer)​ ,

     

    Authentication Manager doesn't have its own setting for daylight saving time. It uses the time zone configured on the appliance's operating system, NTP and time zone rules built into the OS.

     

    How the time adjustment works

    • NTP servers only supply UTC time. They don't send any daylight saving information. The one-hour shift is applied locally, based on the time zone chosen in the Operations Console under Administration > Date & Time.
    • If your time zone observes daylight saving, the Location field shows two UTC offsets, for example "(UTC-06/UTC-05) Winnipeg." That means the appliance will change its clock twice a year.
    • What to expect if no changes are made. If the appliance's time zone rules haven't been updated for your province's change, it will still fall back one hour at 2:00 AM. on November 1, 2026.
    • You can check timezone values in the Operations Console or by running timedatectl show -p Timezone --value on the server.

     

    SecurID tokencodes are calculated from UTC, so authentication itself should not be affected. However, the local time shown in logs, reports, the administrative consoles and scheduled jobs would be off by one hour.

     

    You can switch to a fixed-offset time zone before November 1. Choose a time zone that doesn't observe daylight saving and matches your province's new permanent offset:

     

    • British Columbia (UTC-7): America/Whitehorse or America/Phoenix
    • Alberta (UTC-6): America/Regina
    • Manitoba (UTC-5): America/Panama or America/Bogota

     

    To change the time zone:

    Services will restart, so plan a maintenance window to complete this work:

    1. Go to Administration > Date & Time in the Operations Console.
    2. Click Edit, select the new Region and Location.
    3. Click Save & Restart.
    4. Repeat this on each primary and replica instance.

     

    IMPORTANT NOTE: Only the time zone changes, not the actual system time. The zone name shown in logs and reports will also change.

    Expand Post
    Selected as Best
  • JohnMcKellep (Customer)

    thank you for the information. You say that the token function should not be affected, is that true for the physical SecurID 700 tokens and ODA tokens as well as the MFA app tokens?