RSA Authentication Agent 8.0 for Web for Internet Information Services Generates HTTP Error 500.21
Originally Published: 2016-03-02
Article Number
Applies To
RSA Product/Service Type : RSA Authentication Agent for Web for IIS
RSA Version/Condition: 8.0
Platform : Windows
O/S Version : Microsoft Windows 2012 R2
Issue
NOTE: Default value upon installation is 'true' for the USEUDP_ENV_VAR system variable.
The error seen in the web browser is 'HTTP Error 500.21 - Internal Server Error | Handler "RSASecurIDHandlerMapping" has a bad module "SecurIDHandler" in its module list'
Example:
Cause
Resolution
Troubleshooting and Conversion from UDP to TCP Usage
The suggestion would be to get the RSA Authentication Agent 8.0 for Web for Internet Information Services working for UDP (default) protocol
RSA Authentication Agent icon in the Control Panel can be used to perform test authentications to the authentication manager 8.1 deployment. This in turn will use the configuration record (sdconf.rec) to confirm communication to the authentication manager 8.1 deployment and generate sdstatus.12 and node secret file (securid).
To change the protocol used by the RSA Authentication Agent 8.0 for Web for Internet Information Services to TCP
- Windows Control Panel > System and System > System > Advanced system settings > click Environment Variables... button > in system variable highlight USEUDP_ENV_VAR > click Edit > change Variable value from true to false > click OK > click OK > click OK (returning to 'Control Panel > System and System > System')
- Open File Explorer and navigate to C:\Program Files\RSA Security\RSAWebAgent
- Create a new folder called Logs
- Make a copy of rsa_api.properties so you end up with a file called rsa_api - Copy.properties
- Edit rsa_api.properties
uncomment RSA_AGENT_NAME, RSA_AGENT_TYPE, RSA_AGENT_VERSION, RSA_AGENT_PLATFORM, SDCONF_LOC, RSA_CONFIG_DATA_LOC, RSA_LOG_FILE_LOC, RSA_LOG_LEVEL, RSA_LOG_FILE_SIZE & RSA_LOG_FILE_COUNT
ensure these variables are set correctly (useful to have RSA_LOG_LEVEL set to verbose)
ensure these variables are set correctly (useful to have RSA_LOG_LEVEL set to verbose)
Example:
# RSA Authentication API Properties # Use of rsa_api.properties file is optional. If it’s not used then Agent will work with default configuration # Name of the agent. The same needs to be configured in AM. Default value is the Hostname of the machine RSA_AGENT_NAME = <fully_qualified_hostname> # Provide the Agent Type, default value is 'UnKnown' RSA_AGENT_TYPE = RSA_WEB_AGENT # Provide the Agent Version, default value is 'UnKnown' RSA_AGENT_VERSION = 8.0 # Provide the Agent Platform, default value is 'UnKnown' RSA_AGENT_PLATFORM = Windows_Server_2012_R2 # Path of the AM configuration file. # For Windows SDCONF_LOC = C:\Program Files\RSA Security\RSAWebAgent\sdconf.rec # For Non-Windows # SDCONF_LOC = /var/ace/RSA_AuthSDK/sdconf.rec # Path of configuration file used to configure Load Balancing. # For Windows # SDOPTS_LOC = C:\RSA_AuthSDK\sdopts.rec # For Non-Windows # SDOPTS_LOC = /var/ace/RSA_AuthSDK/sdopts.rec # Path of the Node Secret. # For Windows # SDNDSCRT_LOC = C:\RSA_AuthSDK\securid # For Non-Windows # SDNDSCRT_LOC = /var/ace/RSA_AuthSDK/securid # Folder location where "config.xml", "bootstrap.xml" and "root.cer" will be created. # For Windows RSA_CONFIG_DATA_LOC = C:\Program Files\RSA Security\RSAWebAgent\<fully_qualified_hostname> # For Non-Windows # RSA_CONFIG_DATA_LOC = /var/ace/RSA_AuthSDK # Specify the list of encryption algorithms to be used for encryption while communicating with AM. # RSA_ENC_ALGLIST = AES/24,AES/32,AES/16 # Specify the connection timeout for server connection in seconds. Default value will be taken from config.xml # RSA_CONNECTION_TIMEOUT=60 # Specify the timeout for server connection in seconds. Default value will be taken from config.xml # RSA_READ_TIMEOUT=60 # Folder name where the log files will be generated. # For Windows RSA_LOG_FILE_LOC = C:\Program Files\RSA Security\RSAWebAgent\Logs # For Non-Windows # RSA_LOG_FILE_LOC = /var/ace/RSA_AuthSDK/Logs # Set log level to either of these values “verbose”, "info","warn","error". RSA_LOG_LEVEL = verbose # Log file size in KB. Maximum size is 1MB. RSA_LOG_FILE_SIZE = 1024 # No. of log files to be created before log file rotation. Default value is 10. RSA_LOG_FILE_COUNT = 10
- Copy sdconf.rec & rsa_api.properties from C:\Program Files\RSA Security\RSAWebAgent into the C:\Windows\System32 folder
- Reset IIS with the command iisreset in Powershell
- Where the RSA Authentication Agent 8.0 for Web for Internet Information Services is protecting the web site does the local administrator get prompted for SecurID authentication when entering http://localhost into the local web browser?
NOTE: should the internal error still appear then the web agent is not happy about the rsa_api.properties file and an administrator is required to check the C:\Program Files\RSA Security\RSAWebAgent\Logs\aceclnt.txt log file for technical issues in the configuration.
Notes
Related Articles
Integrating Vormetric Data Security Manager with RSA Authentication Manager 8.x 73Number of Views Dynamic Seed provisioning using QR Code 733Number of Views Import Users with Tokens 75Number of Views RSA MFA Agent 9.0 for Microsoft IIS Installation and Administration Guide 270Number of Views Radius Authentication Failure after upgrading to 8.6 and above with UTF-8 Error seen in radius logs 610Number of Views
Trending Articles
RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA Authentication Manager 8.9 Release Notes (January 2026) RSA Release Notes for RSA Authentication Manager 8.8 RSA announces End of Life EOL dates for RSA MyAccessLive Service RSA Authentication Manager 8.9 Administrator's Guide
Don't see what you're looking for?