Announcements

SecurID® Discussions

Browse the SecurID discussion board to get product help and collaborate with other SecurID users.
RICKBOYAJIAN
Beginner
Beginner

Maximum 3 Tokens per user

Jump to solution

In the RSA Secure ID Console, Can I override the 3 tokens maximum per user rule ?

 

thank you, Rick

Labels (1)
0 Likes
1 Solution

Accepted Solutions
EdwardDavis
Employee
Employee

no. you can add a fixed passcode (not very secure) for a fourth way, and on-demand for a fifth, but the

3-tokens is not changeable. 

View solution in original post

4 Replies
EdwardDavis
Employee
Employee

no. you can add a fixed passcode (not very secure) for a fourth way, and on-demand for a fifth, but the

3-tokens is not changeable. 

Thanks Edward

0 Likes

If you think about it Rick, the Auth Manager server has to calculate the current tokencode based on the current time and the Token Seed.  But AM needs to calculate at least three TokenCodes as a buffer, the previous minute, the right now minute, and the next minute.  But wait, if this is the first logon since RSA services were started, the AM server needs to calculate every tokenCode plus or minus 10 minutes, a 21 minute or TokenCode Window, and any correct tokenCode in that Window will be accepted, as a way to determine if the Token Time is slightly different from the server time.

With 3 Tokens, that means calculating 63 unique tokencodes.  Add a 4th token that goes to 84 tokencodes, so I believe the 3 Token limit was both a Security feature, more tokens means more chances to lose a token, and a performance preserving feature in Authentication Manager or ACE back in the day of 32 bit processors

Thank you Jay

0 Likes