User initially shows passcode accepted and node secret sent, but second authentication fails with node secret mismatch: cleared on agent but not on server for RSA Authentication Agent 7.x for Windows
Originally Published: 2001-10-31
Article Number
Applies To
RSA Product/Service Type: Authentication Agent for Windows
RSA Version/Condition: AAWin 7.x, IIS agent 7.x or 8.x UDP
Issue
The user initially receives a message of passcode accepted. The RSA Authentication Manager server log shows that the passcode was accepted and the node secret is sent to the agent. However, the second and subsequent authentication attempts fail with the RSA Authentication Manager server log showing the following message:
Node secret mismatch: cleared on agent but not on server.
Cause
This could be a user permissions or UAT issue. The user may not have rights to write to Winnt\System32 or the registry or disk on this computer.
RSA Authentication Agent 7.x for Windows writes the node secret file named securid to C:\Program Files\Common Files\RSA Shared\\Auth Data.
Resolution
If the node secret was sent to the agent, but does not exist on the agent, the problem is that the node secret was not written to C:\Program Files\Common Files\RSA Shared\\Auth Data (for Windows Agent) or not written to \Program Files\RSA Security\RSAWebAgent (for IIS agent), after it was sent to the agent. This indicates some type of permissions or privilege issue, or a locked down folder due to UAT.
The resolution would be to ensure that the node secret can be written to the C:\Program Files\Common Files\RSA Shared\\Auth Data directory, by doing one or more of the following:
- Disabling or modifying UAT,
- Open the RSA Control Center or Test Authentication with "Run As Administrator" right click, for elevated permissions. Perform the initial authentication with the RSA Control Center by doing a Test Authentication with a local administrator account, or
- Modifying the folder permissions on C:\Program Files\Common Files\RSA Shared\\Auth Data to allow read/write permissions to the application.
Workaround
Related Articles
Refresh the Node Secret 146Number of Views Authentication Manager Node secret mismatch on TMG or UAG 308Number of Views How to recreate the node secret for RADIUS Server in RSA Authentication Manager 8.x 942Number of Views Manage the Node Secret 211Number of Views Manually creating the node secret for RSA Authenticaiton Manager fails on Microsoft Forefront Threat Management Gateway 276Number of Views
Trending Articles
RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA Release Notes for RSA Authentication Manager 8.8 RSA Authentication Manager 8.9 Release Notes (January 2026) Deploying RSA Authenticator 6.2.2 for Windows Using DISM RSA MFA Agent 2.4 for Microsoft Windows Installation and Administration Guide
Don't see what you're looking for?