New PIN Mode and Next Tokencode Mode fail after Cisco ASA upgrade to 9.1.7 in RSA Authentication Manager 8.x
Originally Published: 2016-04-07
Last Modified: 2026-06-09
Article Number
Applies To
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.x
Platform (Other): Cisco ASA
O/S Version: ASA 9.1.7
Issue
- Users are unable to set PINs for tokens.
- Authentication failures when the next tokencode is entered.
Passcode format error and authentication failure
On the Cisco client, the error is:
Session operation failure processing request from agent
Resolution
This is Cisco bug CSCuy89425 (AAA: RSA/SDI unable to set new PIN), and it occurs with the RSA SecurID_Native protocol.
Possible workarounds include:
- Switch to RADIUS protocol (as per the RSA SecurID Access Implementation Guide for the Cisco Adaptive Security Appliance (ASA).
- Authenticate from the Self-Service Console when a token is in New PIN Mode or Next Tokencode Mode.
For more details on how to resolve the issue for a Cisco VPN client or iPhone, review documentation for CSCuy89425 (AAA: RSA/SDI unable to set new PIN).
Related Articles
Error "PIN change failed dictionary check" and authentication fails for a user in new PIN mode in RSA Authentication Manag… 97Number of Views New feature for RSA Identity Governance & Lifecycle 7.1: Workflow System Status 321Number of Views Radius Client Authentication failed For PIN+Token profile (New PIN Mode) with Cisco Anyconnect VPN 605Number of Views Cisco ASA - RSASecurID Access Implementation Guide 193Number of Views Radius Client Authentication failed For PIN+Token profile (New PIN Mode) with Cisco Anyconnect VPN 126Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Unable to login to RSA Authentication Manager Security Console as super admin Manual synchronization introduced in RSA Authentication Manager 8.2 Service Pack 1 patch 6 Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory How to verify NTP server synchronization is not working in RSA Authentication Manager 8.x
Don't see what you're looking for?