- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Recent Authentication Activity
Hello Team,
token authentication is happening fine and for some authentications ,in the activity details i can see the node IP of replica.
does it mean replica performed the token authentication for that transaction?
because as per documents i read that replica is read only instance.
Please confirm.
Thanks,
Sumit
- Tags:
- AM
- Auth Manager
- Authentication Manager
- Community Thread
- Discussion
- Forum Thread
- recent authentication activity
- RSA Authentication Manager
- RSA SecurID
- RSA SecurID Access
- SecurID
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes, the authentication was addressed by the replica.
Replica is read only for any administrative activities.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Okay,
administrative activities like token assign, admin role assign etc will only be done by Primary?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes, that is correct. Replica can do administrative activities if it has been promoted to a primary under the condition if the original primary is unavailable or offline.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Replica is considered read-only for administrative work (adding tokens or managing users) but as it sits there it will authenticate traffic that hits it, the same as a primary. It is read-only in the sense that all changes you make occur on the primary, and the primary copies those changes to the replica database so all systems have identical users and tokens.
The replica will log activity it processes, and send the logs to the primary where you can run reports on the events. If you set a replica to send logs to syslog, then the replica will directly send those events to your SIEM tool, as well as send the RSA logs to the primary for the reporting.
