Users cannot authenticate successfully when the RSA SecurID token is in either Next Tokencode Mode or New PIN Mode when authentications originate from an IBM WebSeal in RSA Authentication Manager 8.x
Originally Published: 2015-10-21
Article Number
Applies To
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.x
Platform: IBM WebSEAL 6.1.1.x
Platform (Other): IBM Security Access Manager (formerly called IBM Tivoli Access Manager)
Issue
- Users cannot authenticate successfully when the RSA SecurID token is in either Next Tokencode Mode or New PIN Mode when authentications originate from an IBM WebSeal in RSA Authentication Manager 8.x.
- If the token is not in Next Tokencode Mode or New Pin Mode, authentication is successful.
- Underlying the IBM WebSeal is the RSA Authentication Agent for PAM.
- Both Next Tokencode Mode and New PIN Mode work as expected with the PAM acetest utility.
- Therefore, the problem is specific to using WebSEAL.
Cause
Resolution
- Create a new setting in the WebSEAL configuration.
create-unauth-sessions = yes
- Restart the WebSEAL application.
This will allow for successful authentications when a token is in either Next Tokencode Mode or New PIN Mode.
Notes
If consulting with IBM Support, reference IBM PMR 40092,122,000 for more information.
Related Articles
Partial Failure - Changes are not published successfully on the Identity Router (IDR) but successfully published on the Cl… 28Number of Views How to verify a third party patch has been installed successfully on Authentication Manager 8.1 6Number of Views RSA Governance & Lifecycle Integration: IBM Notes Summary 8Number of Views RSA Governance & Lifecycle Integration: IBM RACF Summary 25Number of Views PASSMARK_PAGE_SERVED event not being logged 4Number of Views
Trending Articles
RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA Release Notes for RSA Authentication Manager 8.8 RSA Authentication Manager 8.9 Release Notes (January 2026) Supported On-Demand Authentication (ODA) SMS providers for use with RSA Authentication Manager 8.x Deploying RSA Authenticator 6.2.2 for Windows Using DISM
Don't see what you're looking for?