Authentication Agent, AAWin v. 7.4.4 on Citrix Windows non-persistent VDI node secret mismatch
Originally Published: 2021-06-07
Article Number
Applies To
RSA Product/Service Type: Authentication Agent for Windows
RSA Version/Condition: 7.4.x
Platform: Windows
Platform (Other): authentication failures
O/S Version: 10, Server 20xx
Product Name: null
Product Description: null
Issue
1. Windows Agent auto-registers and creates Node secret (which will be used to encrypt all subsequent authentications). Node secret created on agent C:\ disk drive.
2. User logs out but does not shutdown and VDI destroys the write-cache including the agents node secret which is on the disk.
3. Testing shows failed authentications after write-cache cleared, node secret mismatch - cleared agent not server
Cause
Resolution
The RSA Authentication Agent for Windows was not designed to function in this Use Case.
Workaround
To resolve this issue, you wouls need to reset the node secret by clearing the node secret on the AM server.
You could reboot the Windows agent to allow auto-registration to create a new node secret on both the agent and the AM server
The ReST agent API could be used instead of the UDP agent, MFA agent for windows v.2.0.x, which does not use a node secret.
A daily AMBA job to clear Server node secrets on auto-registered node secrets would probably not be practical nor good enough to work all the time.
Notes
Related Articles
A few tips for export/import database 52Number of Views A few questions on generating weekly and monthly reports 44Number of Views User Picker ignores Include Terminated User flag in Via Lifecycle and Governance 7Number of Views Character string buffer too small when access view V_AV_DB_TIMEZONE in RSA Identity Governance and Lifecycle 68Number of Views Delete a Persistent IPv4 or IPv6 Static Route 8Number of Views
Trending Articles
Passwordless Authentication in Windows MFA Agent for Active Directory – Quick Setup Guide RSA Authentication Manager 8.9 Release Notes (January 2026) RSA Authentication Manager Upgrade Process RSA Authentication Manager 8.7 SP2 Setup and Configuration Guide An example of SSO using SAML and ADFS with RSA Identity Management and Governance 6.9.x
Don't see what you're looking for?