Citrix Netscaler failing to properly handle New PIN Mode and On-Demand Authentication (ODA) when using RADIUS with RSA Authentication Manager 8.x
Originally Published: 2015-06-29
Article Number
Applies To
RSA Product/Service Type: Authentication Manager
Issue
In the On-Demand Authentication (ODA) scenario, the user is not getting the email or SMS with the tokencode after entering the correct PIN. Below is a detailed description of the issue:
- The user connects to the Citrix portal, and is prompted for his user ID, tokencode or PIN (if using ODA).
- The user is asked to create a new PIN then prompted to re-enter the PIN.
- Citrix responds that the new PIN has been accepted and to wait for the tokencode to change, then enter the new passcode (PIN + tokencode) and click Submit.
- When the user enters the next passcode, an Access Denied message displays.
Cause
Resolution
Workaround
Option 1
The securid.ini file that handles the messaging can be edited so that the steps users need to take are more clear. Editing this file will change the messaging seen by users to all RADIUS clients. Citrix article CTX124374 on how to modify the RSA token prompts displayed by NetScaler Gateway has information on how to make the required changes to the securid.ini directly on a Windows server. RSA Authentication Manager admins can make the change through the Operations Console using the steps below.- Login to the Operations Console.
- Select Deployment Configuration > RADIUS Servers.
- Click on the drop-down next to the RADIUS primary and choose Manage Server Files.
- Click on the arrow next to the securid.ini file and select Edit.
- Following the steps in the Citrix article above, edit the ExtInputNextCode value, the ExtOutputChange value or both. Note that there is a 255-character maximum for the message.
- When done, click Save and Restart RADIUS Server.
- Repeat steps 1 through 6 for any replicas in the deployment.
Option 2
Refresh the Citrix webpage after setting the new PIN. The user can typically authenticate normally with the passcode (PIN+tokencode).
Option 3
In the case of ODA, refreshing the page will trigger a new email or SMS that will be sent to the user.Notes
Related Articles
Replica RADIUS not accepting authentication requests in RSA Authentication Manager 8.0 and 8.1 291Number of Views Citrix NetScaler to Cisco ACS to RSA AM 8.X Authentication Method Fails. 515Number of Views To allow automatic vetting of Sentry CA 3R1-3R4 certificate requests. 3Number of Views How to failover a Citrix NetScaler to an Authentication Manager RADIUS Replica Server 306Number of Views Troubleshooting RSA Authentication Manager 8.1 native SecurID and RADIUS authentication issues 4.72KNumber of Views
Trending Articles
RSA Authentication Manager 8.7 SP2 Setup and Configuration Guide RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide How to Upgrade Internal SHA-1 Certificates to SHA-256 in Authentication Manager Using rsautil RSA Release Notes for RSA Authentication Manager 8.8 RSA Authentication Manager 8.9 Setup and Configuration Guide
Don't see what you're looking for?