This website uses cookies. By clicking OK, you consent to the use of cookies. Click Here to learn more about how we use cookies.
OK
  • RSA.com
  • Products
    • Archer®
      • Archer®
      • Advisories
      • Blog
      • Discussions
      • Documentation
      • Downloads
      • Ideas
      • Knowledge Base
      • Archer® Exchange
      • Training
      • Upcoming Events
      • Videos
    • RSA® Fraud & Risk Intelligence Suite
      • RSA® Fraud & Risk Intelligence Suite
      • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication On-Premise
      • RSA® Adaptive Authentication On-Premise (Cassandra)
      • RSA® Adaptive Authentication for eCommerce
      • RSA® FraudAction Services
      • RSA® Web Threat Detection
      • Upcoming Events
      • Videos
    • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication Cloud
      • Advisories
      • Blog
      • Discussions
      • Documentation
      • Downloads
      • Events
      • Ideas
      • Knowledge Base
      • Training
      • Upcoming Patch Content
      • Videos
    • RSA® Adaptive Authentication Mobile SDK
      • RSA® Adaptive Authentication Mobile SDK
      • Advisories
      • Events
      • Ideas
      • Knowledge Base
      • Request Access
      • Training
    • RSA® Adaptive Authentication On-Premise
      • RSA® Adaptive Authentication On-Premise
      • Advisories
      • Blog
      • Discussions
      • Documentation
      • Downloads
      • Events
      • Ideas
      • Knowledge Base
      • Training
      • Videos
    • RSA® Adaptive Authentication On-Premise (Cassandra)
      • RSA® Adaptive Authentication On-Premise (Cassandra)
      • Advisories
      • Blog
      • Discussions
      • Documentation
      • Downloads
      • Events
      • Ideas
      • Knowledge Base
      • Training
      • Videos
    • RSA® Adaptive Authentication for eCommerce
      • RSA® Adaptive Authentication for eCommerce
      • Advisories
      • Blog
      • Discussions
      • Documentation
      • Ideas
      • Knowledge Base
      • Training
      • Videos
    • RSA® FraudAction Services
      • RSA® FraudAction Services
      • Advisories
      • Discussions
      • Documentation
      • Ideas
      • Videos
    • RSA® Web Threat Detection
      • RSA® Web Threat Detection
      • Advisories
      • Blog
      • Discussions
      • Documentation
      • Downloads
      • Ideas
      • Knowledge Base
      • Videos
    • RSA NetWitness® Platform
      • RSA NetWitness® Platform
      • Advisories
      • Blog
      • Discussions
      • Documentation
      • Downloads
      • Ideas
      • Integrations
      • Knowledge Base
      • Training
      • Upcoming Events
      • Videos
    • RSA NetWitness® Detect AI
      • RSA NetWitness® Detect AI
      • Documentation
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
    • RSA NetWitness® Investigator
      • RSA NetWitness® Investigator
      • Documentation
      • Download the Client
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
    • RSA NetWitness® Orchestrator
      • RSA NetWitness® Orchestrator
      • Overview
      • Documentation
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
    • RSA SecurID® Suite
      • RSA SecurID® Suite
      • Advisories
      • Blog
      • Discussions
      • Documentation
      • Downloads
      • Knowledge Base
      • Ideas
      • Integrations
      • Training
      • Videos
    • RSA® Identity Governance & Lifecycle
      • RSA® Identity Governance & Lifecycle
      • Advisories
      • Blog
      • Community Exchange
      • Discussions
      • Documentation
      • Downloads
      • Ideas
      • Knowledge Base
      • Training
      • Upcoming Events
      • Videos
    • RSA SecurID® Access
      • RSA SecurID® Access
      • Advisories
      • Blog
      • Discussions
      • Documentation
      • Downloads
      • Ideas
      • Integrations
      • Knowledge Base
      • Training
      • Upcoming Events
      • Videos
    • Other RSA® Products
      • Other RSA® Products
      • RSA® Access Manager
      • RSA® Data Loss Prevention
      • RSA® Digital Certificate Solutions
      • RSA enVision®
      • RSA® Federated Identity Manager
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
  • Resources
    • Advisories
      • Product Advisories on RSA Link
      • Archer®
      • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication Hosted
      • RSA® Adaptive Authentication On-Premise
      • RSA® Adaptive Authentication On-Premise (Cassandra)
      • RSA® Adaptive Authentication for eCommerce
      • RSA® FraudAction Services
      • RSA® Identity Governance & Lifecycle
      • RSA NetWitness® Platform
      • RSA SecurID® Access
      • RSA® Web Threat Detection
      • All Product Advisories
    • Blogs
      • Blogs on RSA Link
      • Archer®
      • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication On-Premise
      • RSA® Adaptive Authentication On-Premise (Cassandra)
      • RSA® Adaptive Authentication for eCommerce
      • RSA® Identity Governance & Lifecycle
      • RSA NetWitness® Platform
      • RSA SecurID® Access
      • RSA® Web Threat Detection
      • All Blogs on RSA Link
    • Discussion Forums
      • Discussion Forums
      • Archer®
      • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication On-Premise
      • RSA® Adaptive Authentication On-Premise (Cassandra)
      • RSA® Adaptive Authentication for eCommerce
      • RSA® FraudAction Services
      • RSA® Identity Governance & Lifecycle
      • RSA NetWitness® Platform
      • RSA SecurID® Access
      • RSA® Web Threat Detection
      • All Discussion Forums on RSA Link
    • Documentation
      • Product Documentation
      • Archer®
      • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication Mobile SDK
      • RSA® Adaptive Authentication On-Premise
      • RSA® Adaptive Authentication On-Premise (Cassandra)
      • RSA® Adaptive Authentication for eCommerce
      • RSA® FraudAction Services
      • RSA® Identity Governance & Lifecycle
      • RSA NetWitness® Platform
      • RSA SecurID® Access
      • RSA® Web Threat Detection
      • All Documentation on RSA Link
    • Downloads
      • Product Downloads
      • Archer®
      • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication On-Premise
      • RSA® Adaptive Authentication On-Premise (Cassandra)
      • RSA® Identity Governance & Lifecycle
      • RSA NetWitness® Platform
      • RSA SecurID® Access
      • RSA® Web Threat Detection
      • All Downloads on RSA Link
    • Ideas
      • Idea Exchange
      • Archer®
      • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication Mobile SDK
      • RSA® Adaptive Authentication On-Premise
      • RSA® Adaptive Authentication On-Premise (Cassandra)
      • RSA® Adaptive Authentication for eCommerce
      • RSA® FraudAction Services
      • RSA® Identity Governance & Lifecycle
      • RSA NetWitness® Platform
      • RSA SecurID® Access
      • RSA® Web Threat Detection
      • All Documentation on RSA Link
    • Knowledge Base
      • Knowledge Base
      • Archer®
      • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication Mobile SDK
      • RSA® Adaptive Authentication On-Premise
      • RSA® Adaptive Authentication On-Premise (Cassandra)
      • RSA® Adaptive Authentication for eCommerce
      • RSA® Identity Governance & Lifecycle
      • RSA NetWitness® Platform
      • RSA SecurID® Access
      • RSA® Web Threat Detection
      • All Knowledge Base Pages on RSA Link
    • Upcoming Events on RSA Link
      • Upcoming Events
    • Videos
      • Videos on RSA Link
      • Archer®
      • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication On-Premise
      • RSA® Adaptive Authentication On-Premise (Cassandra)
      • RSA® Adaptive Authentication for eCommerce
      • RSA® Identity Governance & Lifecycle
      • RSA NetWitness® Platform
      • RSA SecurID® Access
      • RSA® Web Threat Detection
      • All Videos on RSA Link
  • Support
    • RSA Link Support
      • RSA Link Support
      • News & Announcements
      • Getting Started
      • Support Forum
      • Support Knowledge Base
      • Ideas & Suggestions
    • RSA Product Support
      • RSA Product Support
      • General Security Advisories and Statements
      • Product Life Cycle
      • Support Information
      •  
      •  
      •  
      •  
      •  
  • RSA Ready
  • RSA University
    • Certification Program
      • Certification Program
    • Course Catalogs
      • Course Catalogs
      • Archer®
      • RSA NetWitness® Platform
      • RSA SecurID® Suite
    • On-Demand Subscriptions
      • On-Demand Subscriptions
      • Archer®
      • RSA NetWitness® Platform
      • RSA SecurID® Suite
    • Product Training
      • Product Training
      • Archer®
      • RSA® Fraud & Risk Intelligence Suite
      • RSA® Identity Governance & Lifecycle
      • RSA NeWitness® Platform
      • RSA SecurID® Access
    • Student Resources
      • Student Resources
      • Access On-Demand Learning
      • Access Virtual Labs
      • Contact RSA University
      • Enrollments & Transcripts
      • Frequently Asked Questions
      • Getting Started
      • Learning Modalities
      • Payments & Cancellations
      • Private Training
      • Training Center Locations
      • Training Credits
      • YouTube Channel
    • Upcoming Events
      • Upcoming Events
      • Full Calendar
      • Conferences
      • Live Classroom Training
      • Live Virtual Classroom Training
      • Webinars
Sign In Register Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
Announcements

Visit the Known Issues dashboard if you are experiencing issues on RSA Link

View Dashboard

RSA® Authentication Manager Documentation

Browse the official RSA Authentication Manager documentation for helpful tutorials, step-by-step instructions, and other valuable resources.
  • RSA Link
  • :
  • Products
  • :
  • RSA SecurID Suite
  • :
  • RSA SecurID Access
  • :
  • RSA Authentication Manager
  • :
  • Documentation
  • :
  • Manage the Node Secret
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
  • Options
    • Subscribe to RSS Feed
    • Bookmark
    • Subscribe
    • Email to a Friend
    • Printer Friendly Page
    • Report Inappropriate Content
Versions
Collections
All Downloads

Table of Contents

  •   Getting Started
    •   How RSA Authentication Manager Protects Your Resources
  •   Administrative Accounts
    •   System Administrator Accounts
  •   General Configuration
    •   System Settings
  •   Authentication Agents
    •   RSA Authentication Agents
  •   RSA SecurID Authentication API for Authentication Agents
    •   Configure the RSA SecurID Authentication API for Authentication Agents
  •   Identity Sources
    •   RSA Authentication Manager Identity Sources
  •   Security Domains
    •   Security Domains
  •   Administrative Roles
    •   Administrative Role Overview
  •   Users
    •   RSA Authentication Manager Users
  •   User Groups
    •   RSA Authentication Manager User Groups
  •   User Dashboard
    •   User Dashboard
  •   Policies
    •   RSA Authentication Manager Policies
  •   Identity Attributes
    •   User Attributes
  •   RSA SecurID Authenticate Tokencode Integration
    •   RSA SecurID Authenticate Tokencodes
  •   RSA SecurID Tokens
    •   RSA SecurID Tokens
  •   Password-Only Authentication
    •   Password-Only Authentication
  •   On-Demand Authentication
    •   On-Demand Authentication
  •   Emergency Access
    •   Emergency Online Authentication
  •   Self-Service
    •   Self-Service Settings
  •   Licenses
    •   RSA Authentication Manager License Support
  •   Password Dictionary
    •   Password Dictionary
  •   RADIUS
    •   RSA RADIUS Overview
  •   Logging
    •   Log Messages
  •   SNMP
    •   RSA Authentication Manager SNMP
  •   Security Questions
    •   Managing Security Questions
  •   Trusted Realms
    •   Trusted Realms
  •   Trusted Users
    •   Trusted Users and Trusted User Groups
  •   Trusted User Groups
    •   Add a Trusted User Group
  •   Batch Jobs
    •   Batch Jobs
  •   Risk-Based Authentication
    •   Risk-Based Authentication
  •   Export and Import Tokens and Users Between Deployments
    •   Exporting and Importing Users and Tokens Between Deployments
  •   Reports
    •   Reports
  •   Provisioning
    •   Provisioning Overview
  •   Activity Monitor
    •   Real-time Monitoring Using Activity Monitors
  •   User Sessions
    •   Close an Active User Session
  •   Network Settings
    •   Verify an IP Address or Hostname
  •   Appliance Maintenance
    •   Appliance Logs
  •   Product Updates
    •   RSA Authentication Manager Updates
  •   Certificates
    •   Certificate Management for Secure Sockets Layer
  •   Troubleshooting
    •   Troubleshooting Common Error Messages
  •   Viewing Troubleshooting Files
    •   Download Troubleshooting Files
  •   Replication
    •   Replica Instance
  •   Promotion for Maintenance
    •   Promotion for Maintenance
  •   Disaster Recovery
    •   Disaster Recovery Situations
  •   Backup and Restore
    •   Create a Backup Using Back Up Now
  •   Web Tiers
    •   Web-Tier Deployments
  •   System Date and Time
    •   Accurate System Date and Time Settings
  •   Application Trust
    •   Setting Up an Application Trust
  •   Custom Logon Banners
    •   Custom Logon Banners
  •   Custom Self-Service Console Web Pages
    •   Customize Self-Service Console Web Pages
  •   Cache Maintenance
    •   Flush the Cache
  •   Operating System Access
    •   System Administrator Accounts
  •   RSA Authentication Manager Glossary

Product Resources

  •   Advisories
    •   Product Advisories
    •   Security Advisories
    •   Service Notifications
    •   Technical Advisories
  •   Blog
  •   Discussions
  •   Documentation
    •   Authentication Agents
      •   API / SDK
      •   Apache Web Server
      •   Citrix StoreFront
      •   IIS Web Server
      •   Microsoft AD FS
      •   Microsoft Windows
      •   PAM
    •   Authentication Engine
    •   Authentication Manager
    •   Cloud Authentication Service
    •   Hardware Tokens
    •   MFA Agents
      •   macOS
      •   Microsoft Windows
    •   Software Tokens
      •   Android
      •   Blackberry
      •   Blackberry 10
      •   iOS
      •   macOS
      •   Token Converter
      •   Windows
      •   Windows Phone
  •   Downloads
    •   Authentication Agents
      •   API / SDK
      •   Apache Web Server
      •   Citrix StoreFront
      •   IIS Web Server
      •   Microsoft AD FS
      •   Microsoft Windows
      •   PAM
    •   Authentication Engine
    •   Authentication Manager
    •   Cloud Authentication Service
    •   MFA Agents
      •   macOS
      •   Microsoft Windows
    •   Software Tokens
      •   Android
      •   Blackberry
      •   Blackberry 10
      •   iOS
      •   macOS
      •   Token Converter
      •   Windows
      •   Windows Phone
  •   Events
  •   Ideas
  •   Integrations
  •   Knowledge Base
  •   RSA SecurID Access Prime
  •   Training
  •   Videos

To ensure a secure transaction the first time a user attempts to authenticate with a SecurID passcode, the authentication agent and Authentication Manager automatically communicate using a hashed value of the unique node secret and store it on the agent computer.

​​

The node secret is a shared secret is known only to the authentication agent and RSA Authentication Manager. Authentication agents and Authentication Manager use the node secret as a symmetric encryption key to encrypt and decrypt packets of data as they travel across the network. For example, authentication agents use the node secret to encrypt authentication requests that they send to Authentication Manager. For an authentication agent that uses the UDP protocol, the authentication agent and the Authentication Manager server must agree on the state of the node secret.

For agents that are based upon the UDP protocol, the node secret is stored in both the Authentication Manager database and in a file on the Web Agent host. For agents that are based upon the TCP/IP protocol, a node secret file is optional, and the location is specified in the rsa_api.properties file. Instead of a node secret, a dynamically negotiated key is used to encrypt the channel along with a strong encryption algorithm.

Authentication Manager automatically creates and sends the unique node secret to the agent in response to the first successful authentication on the agent.

In most deployments, automatically delivering the node secret is sufficient. However, you can choose to manually deliver the node secret for increased security. When you manually deliver the node secret to the agent, you must use the Node Secret Load utility to load the node secret on to the agent.

The Node Secret Load utility does the following:

  • Decrypts the node secret file.
  • Renames the file after the authentication service name, usually securid.
  • Stores the renamed file on your machine. For more information on where the renamed node secret file is stored, see your authentication agent documentation.

Procedure 

  1. In the Security Console, click Access > Authentication Agents > Manage Existing.

  2. Click the Restricted or Unrestricted tab, depending on whether the authentication agent that you want to search for is restricted or unrestricted.

  3. Use the search fields to find the authentication agent with the node secret that you want to manage.

  4. Click the agent, and click Manage Node Secret.

  5. If you want to clear the node secret from the Authentication Manager server, do the following:

    1. Select the Clear Node Secret checkbox.
    2. To allow the authentication agent to authenticate to the server, you must also clear the node secret on the authentication agent. For instructions, see your authentication agent documentation.
  6. (Optional) If you want to create a new node secret, instead of generating one automatically, select the Create Node Secret checkbox.

    Enter and confirm a password to encrypt the node secret file. The maximum length is 16 characters. The minimum length, required characters, and excluded characters are determined by the default password policy for the deployment.

  7. Click Save.

  8. Click Download Now.

After you finish 

When you manually deliver the node secret, take the following security precautions:

  • Make sure that all personnel involved in the node secret delivery are trusted personnel.
  • Deliver the node secret on external electronic media to the agent administrator, and verbally deliver the password. Do not write down the password. If you deliver the node secret through e-mail, deliver the password separately.

 

 

Related Concepts

RSA Authentication Agents

Related Tasks

Refresh the Node Secret

 

 

 

Previous Topic:Contact Lists for Authentication Requests
Next Topic:Refresh the Node Secret
You are here
Table of Contents > Authentication Agents > Manage the Node Secret
Labels (2)
Labels:
  • Administration

  • Version 8.5

Tags (17)
  • 8.2
  • 8.5
  • Administration
  • AM
  • am 8.4
  • Auth Manager
  • Authentication Manager
  • Docs
  • Documentation
  • help
  • Product Docs
  • Product Documentation
  • RSA Authentication Manager
  • RSA SecurID
  • RSA SecurID Access
  • SecurID
  • Version 8.5
0 Likes
Was this article helpful? Yes No
Share
No ratings

On this page

Powered by Khoros
  • Products
  • Resources
  • Solutions
  • RSA University
  • Support
  • RSA Labs
  • RSA Ready
  • About RSA Link
  • Terms & Conditions
  • Privacy Statement
  • Provide Feedback
© 2020 RSA Security LLC or its affiliates.
All rights reserved.