Your client does not have permissions to get this URL from the server error with RSA Authentication Agent for Web: IIS
Originally Published: 2020-05-01
Article Number
Applies To
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.x<
Issue
- The RSA Authentication Agent for Web: IIS is configured to challenge users from AD groups.
- RSA SecurID is enabled on a certain website that requires login with a password. The same applies to OWA.
- The user browses to the page and authenticates successfully using RSA SecurID passcode.
- The redirection to the OWA page fails with the following error:
FORBIDDEN
Your client does not have permissions to get this URL from the server.
- The following error appeared in the IIS logs:
[3616] 12:23:08.542 File:.\WAModule.cpp Line:420 # Group Security is enabled; check group permissions
[3616] 12:23:08.542 File:.\WAModule.cpp Line:421 # First, get the physical file path associated with this request.
[3616] 12:23:08.542 File:.\WAModule.cpp Line:427 # checkGroupSecurity() -- szURLPath is: /
[3616] 12:23:08.542 File:.\WAModule.cpp Line:470 # checkGroupSecurity() -- Widechar physical path is: C:\COR\RSA
[3616] 12:23:08.542 File:.\WAModule.cpp Line:488 # checkGroupSecurity() -- szPhysicalPath is: C:\COR\RSA
[3616] 12:23:08.542 File:..\IISWebAgentIF.cpp Line:717 # Entering CIISAgentIFFilter:::HasGroupPermission()
[3616] 12:23:08.542 File:..\IISWebAgentIF.cpp Line:723 # Physical path :C:\COR\RSA
[3616] 12:23:08.558 File:..\IISWebAgentIF.cpp Line:761 # Allocating 164 bytes for file DACL
[3616] 12:23:08.558 File:..\IISWebAgentIF.cpp Line:812 # User has membership in the following groups:
[3616] 12:23:08.558 File:..\IISWebAgentIF.cpp Line:876 # Leaving CIISAgentIFFilter:::HasGroupPermission(), return code: -1
[3616] 12:23:08.558 File:..\IISWebAgentIF.cpp Line:619 # Entering IISWebAgentIF::SINGLE addHeader()
[3616] 12:23:08.558 File:..\IISWebAgentIF.cpp Line:620 # IISWebAgentIF::addHeader Expires: 0 Pragma: no-cache
Cache-control: no-store,no-cache,max-age=0,must-revalidate
[3616] 12:23:08.558 File:..\IISWebAgentIF.cpp Line:665 # Header content : 0 Header name :Expires
[3616] 12:23:08.558 File:..\IISWebAgentIF.cpp Line:665 # Header content : no-cache Header name :Pragma
[3616] 12:23:08.558 File:..\IISWebAgentIF.cpp Line:665 # Header content : no-store,no-cache,max-age=0,must-revalidate Header name :Cache-control
[3616] 12:23:08.558 File:..\IISWebAgentIF.cpp Line:683 # Leaving IISWebAgentIF::SINGLE addHeader()
[3616] 12:23:08.558 File:..\genhtml.cpp Line:843 # Entering GenHTMLText()
[3616] 12:23:08.558 File:..\genhtml.cpp Line:1281 # Entering LoadTemplate()
[3616] 12:23:08.558 File:..\genhtml.cpp Line:1331 # Entering GetLanguageTemplate()
[3616] 12:23:08.558 File:..\genhtml.cpp Line:1377 # Leaving ReadTemplate() : Error opening HTML template file (C:\Program Files\RSA Security\RSAWebAgent\templates\nls\en-US\style.css)
[3616] 12:23:08.558 File:..\genhtml.cpp Line:1426 # Entering GetDefaultTemplate()
[3616] 12:23:08.558 File:..\genhtml.cpp Line:1439 # GetDefaultTemplate(): pathLen: 61, path: C:\Program Files\RSA Security\RSAWebAgent\templates/style.css
[3616] 12:23:08.558 File:..\genhtml.cpp Line:1474 # GetDefaultTemplate(): Read file for cache reload of template
[3616] 12:23:08.558 File:..\genhtml.cpp Line:1499 # Entering ReadTemplate()
[3616] 12:23:08.558 File:..\genhtml.cpp Line:1526 # Leaving ReadTemplate(), success
[3616] 12:23:08.558 File:..\genhtml.cpp Line:1485 # GetDefaultTemplate(): Reloaded cache entry
[3616] 12:23:08.558 File:..\genhtml.cpp Line:1490 # Leaving GetDefaultTemplate(), template located
[3616] 12:23:08.558 File:..\genhtml.cpp Line:1314 # Leaving LoadTemplate(), got template style
[3616] 12:23:08.558 File:..\genhtml.cpp Line:1281 # Entering LoadTemplate()
[3616] 12:23:08.558 File:..\genhtml.cpp Line:1331 # Entering GetLanguageTemplate()
[3616] 12:23:08.558 File:..\genhtml.cpp Line:1377 # Leaving ReadTemplate() : Error opening HTML template file (C:\Program Files\RSA Security\RSAWebAgent\templates\nls\en-US\forbidden.htm)
[3616] 12:23:08.558 File:..\genhtml.cpp Line:1426 # Entering GetDefaultTemplate()
[3616] 12:23:08.558 File:..\genhtml.cpp Line:1439 # GetDefaultTemplate(): pathLen: 65, path: C:\Program Files\RSA Security\RSAWebAgent\templates/forbidden.htm
[3616] 12:23:08.574 File:..\genhtml.cpp Line:1474 # GetDefaultTemplate(): Read file for cache reload of template
[3616] 12:23:08.574 File:..\genhtml.cpp Line:1499 # Entering ReadTemplate()
[3616] 12:23:08.574 File:..\genhtml.cpp Line:1526 # Leaving ReadTemplate(), success
[3616] 12:23:08.574 File:..\genhtml.cpp Line:1485 # GetDefaultTemplate(): Reloaded cache entry
[3616] 12:23:08.574 File:..\genhtml.cpp Line:1490 # Leaving GetDefaultTemplate(), template located
[3616] 12:23:08.574 File:..\genhtml.cpp Line:1314 # Leaving LoadTemplate(), got template forbidden
[3616] 12:23:08.574 File:..\genhtml.cpp Line:902 # Leaving GenHTMLText()
[3616] 12:23:08.542 File:.\WAModule.cpp Line:421 # First, get the physical file path associated with this request.
[3616] 12:23:08.542 File:.\WAModule.cpp Line:427 # checkGroupSecurity() -- szURLPath is: /
[3616] 12:23:08.542 File:.\WAModule.cpp Line:470 # checkGroupSecurity() -- Widechar physical path is: C:\COR\RSA
[3616] 12:23:08.542 File:.\WAModule.cpp Line:488 # checkGroupSecurity() -- szPhysicalPath is: C:\COR\RSA
[3616] 12:23:08.542 File:..\IISWebAgentIF.cpp Line:717 # Entering CIISAgentIFFilter:::HasGroupPermission()
[3616] 12:23:08.542 File:..\IISWebAgentIF.cpp Line:723 # Physical path :C:\COR\RSA
[3616] 12:23:08.558 File:..\IISWebAgentIF.cpp Line:761 # Allocating 164 bytes for file DACL
[3616] 12:23:08.558 File:..\IISWebAgentIF.cpp Line:812 # User has membership in the following groups:
[3616] 12:23:08.558 File:..\IISWebAgentIF.cpp Line:876 # Leaving CIISAgentIFFilter:::HasGroupPermission(), return code: -1
[3616] 12:23:08.558 File:..\IISWebAgentIF.cpp Line:619 # Entering IISWebAgentIF::SINGLE addHeader()
[3616] 12:23:08.558 File:..\IISWebAgentIF.cpp Line:620 # IISWebAgentIF::addHeader Expires: 0 Pragma: no-cache
Cache-control: no-store,no-cache,max-age=0,must-revalidate
[3616] 12:23:08.558 File:..\IISWebAgentIF.cpp Line:665 # Header content : 0 Header name :Expires
[3616] 12:23:08.558 File:..\IISWebAgentIF.cpp Line:665 # Header content : no-cache Header name :Pragma
[3616] 12:23:08.558 File:..\IISWebAgentIF.cpp Line:665 # Header content : no-store,no-cache,max-age=0,must-revalidate Header name :Cache-control
[3616] 12:23:08.558 File:..\IISWebAgentIF.cpp Line:683 # Leaving IISWebAgentIF::SINGLE addHeader()
[3616] 12:23:08.558 File:..\genhtml.cpp Line:843 # Entering GenHTMLText()
[3616] 12:23:08.558 File:..\genhtml.cpp Line:1281 # Entering LoadTemplate()
[3616] 12:23:08.558 File:..\genhtml.cpp Line:1331 # Entering GetLanguageTemplate()
[3616] 12:23:08.558 File:..\genhtml.cpp Line:1377 # Leaving ReadTemplate() : Error opening HTML template file (C:\Program Files\RSA Security\RSAWebAgent\templates\nls\en-US\style.css)
[3616] 12:23:08.558 File:..\genhtml.cpp Line:1426 # Entering GetDefaultTemplate()
[3616] 12:23:08.558 File:..\genhtml.cpp Line:1439 # GetDefaultTemplate(): pathLen: 61, path: C:\Program Files\RSA Security\RSAWebAgent\templates/style.css
[3616] 12:23:08.558 File:..\genhtml.cpp Line:1474 # GetDefaultTemplate(): Read file for cache reload of template
[3616] 12:23:08.558 File:..\genhtml.cpp Line:1499 # Entering ReadTemplate()
[3616] 12:23:08.558 File:..\genhtml.cpp Line:1526 # Leaving ReadTemplate(), success
[3616] 12:23:08.558 File:..\genhtml.cpp Line:1485 # GetDefaultTemplate(): Reloaded cache entry
[3616] 12:23:08.558 File:..\genhtml.cpp Line:1490 # Leaving GetDefaultTemplate(), template located
[3616] 12:23:08.558 File:..\genhtml.cpp Line:1314 # Leaving LoadTemplate(), got template style
[3616] 12:23:08.558 File:..\genhtml.cpp Line:1281 # Entering LoadTemplate()
[3616] 12:23:08.558 File:..\genhtml.cpp Line:1331 # Entering GetLanguageTemplate()
[3616] 12:23:08.558 File:..\genhtml.cpp Line:1377 # Leaving ReadTemplate() : Error opening HTML template file (C:\Program Files\RSA Security\RSAWebAgent\templates\nls\en-US\forbidden.htm)
[3616] 12:23:08.558 File:..\genhtml.cpp Line:1426 # Entering GetDefaultTemplate()
[3616] 12:23:08.558 File:..\genhtml.cpp Line:1439 # GetDefaultTemplate(): pathLen: 65, path: C:\Program Files\RSA Security\RSAWebAgent\templates/forbidden.htm
[3616] 12:23:08.574 File:..\genhtml.cpp Line:1474 # GetDefaultTemplate(): Read file for cache reload of template
[3616] 12:23:08.574 File:..\genhtml.cpp Line:1499 # Entering ReadTemplate()
[3616] 12:23:08.574 File:..\genhtml.cpp Line:1526 # Leaving ReadTemplate(), success
[3616] 12:23:08.574 File:..\genhtml.cpp Line:1485 # GetDefaultTemplate(): Reloaded cache entry
[3616] 12:23:08.574 File:..\genhtml.cpp Line:1490 # Leaving GetDefaultTemplate(), template located
[3616] 12:23:08.574 File:..\genhtml.cpp Line:1314 # Leaving LoadTemplate(), got template forbidden
[3616] 12:23:08.574 File:..\genhtml.cpp Line:902 # Leaving GenHTMLText()
Cause
Enabling Group Security is used when the users are added to a local group and configured in the default shell in RSA Authentication Manager.
This setting blocks the user from redirecting to the OWA page and displays the Forbidden template and the 403 error.
Resolution
Related Articles
Authentication Manager 8.5 P5 connection to Cloud Authentication Service gets “permitted only authenticators you have purc… 59Number of Views How to synchronize user accounts that do not have an email address to the SecurID Access Cloud Authentication Service 120Number of Views Cloning AFX connectors creates duplicate connectors if connector names have been modified in RSA Identity Governance & Lif… 158Number of Views In RSA Identity Governance & Lifecycle While attempting to create/modify review definition, when we include users with Dat… 33Number of Views Windows Password Integration (WPI) fails for the RSA MFA Agent for Microsoft Windows with error "JWT token has expired" 459Number of Views
Trending Articles
Oracle 12c TEMP_UNDO_ENABLED parameter for managing GTT UNDO activity in RSA Identity Governance & Lifecycle Unable to attach a replica instance due to a configuration error when enabling replication for the RADIUS server for RSA A… RSA Authentication Manager 8.7 SP2 Setup and Configuration Guide RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide Troubleshooting RSA MFA Agent for Microsoft Windows
Don't see what you're looking for?