New PIN rejected on first attempt in RSA ACE/Agent 5.0 or Agent based on 5.0 API
3 years ago
Originally Published: 2001-04-12
Article Number
000061752
Applies To
RSA ACE/Agent 5.0 API
RSA ACE/Server
Issue
New PIN rejected on first attempt in RSA ACE/Agent 5.0 or Agent based on 5.0 API
The second authentication attempt works
All subsequent authentication attempts work
This may also happen in Next Tokencode mode
Cause
This is a very rare scenario. If the authentication happens shortly after the Agent and Server are first upgraded or installed and the load balancing was taking place and there are multiple routes with NAT to the ACE/Server, it is possible for the IP header of the authentication and New PIN packets to be different. If this occurs, the ACE/Server will reject it. By the time the user tries again, the load balancing will be complete and all IP headers will be the same.
Resolution
To correct this issue, reauthenticate.