Troubleshooting RSA SecurID Software Token for BlackBerry deployment by CT-KIP
Originally Published: 2010-03-01
Article Number
Applies To
RSA Product/Service Type: RSA Software Token for BlackBerry
RSA Version/Condition: 3.5.1
Issue
Cause
You cannot use Dynamic Seed Provisioning to distribute software tokens to devices running the VPN version of the RSA SecurID Token application.
The IT policy requirement is as follows:
| IT Policy Name | IT Policies for Automating a Token Import Through CT-KIP |
| Values | RSASecurIDCTKIPURL |
| Description | Null (default) |
| Type | Server URL |
Specify a server URL for downloading tokens through Dynamic Seed Provisioning (CT-KIP) so that users do not have to enter the URL in their BlackBerry devices to import a token. Strings can contain up to 200 characters. For example, below are the CT-KIP credentials (for the last token distribution by CT-KIP):
| Activation Code | 24B5849B |
| Token Generation URL | https://rsaserver.mycompany.com:7004/ctkip/trigger.jsp?authcode=24B5849B&url=https://fbrsa1.faegre.com:7004/ctkip/services/CtkipService |
| Service Address | https://rsaserver.mycompany.com:7004/ctkip/services/CtkipService |
| Activation Code Date | Fri Feb 26 14:31:34 CST 2010 |
- The RSA Software Token for BlackBerry token import fails during the first attempt using the CT-KIP download and works fine the second time. The release notes for RSA Software Token 3.0.2 for BlackBerry describes this behavior in the 8700 model. However, this has been noted in other newer models too. This has been resolved in RSA Software Token 3.5 for BlackBerry.
- Download RSA Software Token 3.5.1 for BlackBerry. You can download RSA Software Token 3.5 for BlackBerry devices directly to the BlackBerry device by clicking here.
- Automatic download of a token to a device using CT-KIP works only one time. If a token is deleted and you try to import the new token, the RSA token application must be launched and the Import Token option should be used.
- If there is a problem in downloading application, verify you can launch www.google.com and www.yahoo.com from the same device. Verify that the third-party software installation is allowed on the device. This is disabled on BES server in IT policy.
- CT-KIP requests can be configured with http as well. (default request URL works with https). The http URL can be mentioned on BES server IT policy.
- The Service Address URL should be sent to end users by email.
Related Articles
Software Token Profiles 376Number of Views Software Token Distribution 233Number of Views Reporting on SecurID software tokens with software token lifetime extension in RSA Authentication Manager 8.x 958Number of Views RSA SecurID Software Token for Microsoft Windows shows blank screen when asked to select a device where the token will be … 508Number of Views Types of Session Lifetime Limits 15Number of Views
Trending Articles
How a Multi-App Entitlement Collector (MAEDC) resolves entitlement relationships with accounts and groups collected by a M… RSA Governance & Lifecycle 8.0 Patch 10 Release Notes RSA SecurID software token .sdtid file fails to import into RSA SecurID Software Token 5.0 for Windows User Event Monitor Messages for Cloud Access Service (20601 - 38000) Authentication context not added / Context validation failed errors authenticating with RSA Authentication MFA Agent for A…
Don't see what you're looking for?