How to set a new PIN for RSA SecurID Tokens in RSA Authentication Manager 8.6 or later using NTRadPing Utility
Originally Published: 2022-01-18
Article Number
Issue
This article explains how to use NTRadPing, a third-party RADIUS test utility, to set a New PIN in new Authentication Manager 8.6 or later.
Resolution
NOTE: The Access-Challenge STATE values shown below may be different when you use NTRadPing.
Pre-requites:
1. Download, install NTRadPing 1.5 and test authentications.
- Please refer a KB article 000014905 for details
2. Create a RADIUS client.
- Please review Online Help Topic, "Add a RADIUS Client"
Steps to set in a new PIN in New PIN Mode with NTRadPing
1. Launch the NTRadPing executable.
2. For the RADIUS Server, enter the FQDN or IP address of the Authentication Manager server and for the RADIUS port, enter 1812
3. For RADIUS Secret Key, enter the Shared Secret you created when defining your new RADIUS client.
4. For User Name, enter the user ID of a test user.
5. For Password, enter the tokencode of your test token. Note: This token should be in New PIN Mode.
6. When done, click Send.
Since the token is in New PIN Mode, the response we get is Access-Challenge, as shown here:
7. Copy the string and add it to State string similar to below:
RSA|3a50b645-45ab-4727-ba37-9916197781f8|0c41e795-eb94-406e-86ea-08c997ee8185|SECURID_NEWPIN
8. Enter a new PIN in Password field and click Send.
The response will be to re-enter new PIN.
9. Remove the 1st State string by highlighting it and clicking the Remove button.
10. Copy the New string and add it to the State string similar to below:
RSA|3a50b645-45ab-4727-ba37-9916197781f8|aa9154b0-ff23-4868-aea0-80c34af168ba|SECURID_NEWPIN_CONFIRM
11. Re-enter a new PIN in Password field and click Send.The response will be, "PIN Accepted. Wait for the token code to change, then enter the new passcode:"
12. Remove the 2nd State string by highlighting it and clicking the Remove button.
13. Copy the New string and add it to the State string similar to below:
RSA|3a50b645-45ab-4727-ba37-9916197781f8|ee53afe8-d9ae-417b-b58f-b32d5a2bfe83|SECURID
14. Enter a PIN+Tokencode or Passcode in the Password field and click Send.The response will be, "Access-Accept" for successful authentication.
Notes
See details of how to turn on debugging in Online Help Topic, "RADIUS Server Log Files"
Note the string in the example below:
Related Articles
How to set PINs and navigate Next Tokencode Mode for RSA SecurID Tokens using NTRadPing on SecurID Authentication Manager … 156Number of Views How to use SearchFilterForAccounts when configuring an RSA Via Lifecycle & Governance Authentication Source 15Number of Views How to set PINs and navigate Next Tokencode Mode for RSA SecurID Tokens using NTRadPing 707Number of Views RSA RSA SecurID - Force all tokens to be in New PIN mode without clearing PIN 308Number of Views High CPU usage in Juniper VPN - RSA Authentication Manager 12Number of Views
Trending Articles
How to recover the Application and AFX after an unexpected database failure in RSA Identity Governance & Lifecycle Troubleshooting AFX Connector issues in RSA Identity Governance & Lifecycle RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA Release Notes for RSA Authentication Manager 8.8 RSA Authentication Manager Upgrade Process
Don't see what you're looking for?