Node secret issues after setting up RSA SecurID Authentication Agent 8.0 for Web for Internet Information Services (IIS)
Originally Published: 2016-05-22
Article Number
Applies To
RSA Product/Service Type: Authentication Agent 8.0 Web for IIS
RSA Version/Condition: 8.0
Issue
- The node secret is not bring created.
- Test authentication fails after setting up the agent.
- After protecting the website/OWA through the agent, the test authentication fails from the website/OWA .
- On the RSA Authentication Manager, the Authentication Activity Monitor shows the following error:
Node secret mismatch: Cleared on the agent but not on the server
Cause
The items above are due to a permissions issue on the Windows server where the web agent is installed.
Resolution
- Login to the Windows Server as a local administrator where the web agent is installed.
- Disable User Account Control (UAC) settings.
- On the taskbar click Start.
- In the search field, type Change User Account Control settings.
- Click Open Change User Account Control settings.
- Pull the bar down to the bottom so the options for Never notify me when is set to Programs try to install software or make changes to my computer.
- Click OK.
- Disable the Windows firewall.
- Disable antivirus software, if enabled with IPS/IDS or Enabled with Enhanced Security.
- On the Control Panel, select and right click on the RSA Authentication Agent icon andchoose run as administrator.
- On the Advanced tab, set the IP Address Override. Change the default IP of 255.255.255.255 to the IP address of the Windows server where the RSA web agent is installed.
- Go back to the Main tab and do the test authentication from the RSA web agent by clicking Test Authentication with RSA Authentication Manager.
- The node secret will be sent from the RSA Authentication Manager to the web agent on the first successful authentication.
Look for the file named securid (with no file extension) in C:\Program Files\RSA Security\RSAWebAgent.
- While the node secret file is sent to the agent on the first authentication attempt, it is not used until subsequent authentications. To make sure the node secret is working correctly, repeat the test authentication four or five more times.
- Open a command prompt and run an iisreset.
- Do the test authentication from the protected website/OWA.
- If the test authentication from the protected website/OWA fails with the message below, check the node secret location on the IIS which the agent is protecting. This error happens because the protected website/OWA is looking for the node secret file in an incorrect location or where the file does not exist.
Node secret mismatch: Cleared on the agent but not on the server
- Copy the sdconf.rec, sdstatus.12 and securid files from C:\Program Files\RSA Security\RSAWebAgent to C:\Program Files (x86)\RSA Security\RSAWebAgent.
- Launch a command prompt and run iisreset.
- Now the test authentication will be successful from the protected website/OWA.
Related Articles
Quick Setup hangs forever at setting up operating system for RSA Authentication Manager 8.x 133Number of Views How to ensure Agent Hosts for RADIUS clients are not required when setting up RSA RADIUS / RSA Authentication Manager 6.1 44Number of Views Setting Up an Application Trust 14Number of Views Setting up the RSA Authentication Agent API 8.5 on a Linux operating system 1.42KNumber of Views How to set up the REST RSA SecurID Authentication API for Authentication Manager 8.2 SP1 1.65KNumber of Views
Trending Articles
RSA Release Notes for RSA Authentication Manager 8.8 RSA MFA Agent 2.4.3 for Microsoft Windows Group Policy Object Template Guide RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA Authentication Manager 8.9 Release Notes (January 2026) RSA MFA Agent 2.4.3 for Microsoft Windows Installation and Administration Guide
Don't see what you're looking for?