Unable to authenticate through Radius devices after moving the ACE/Server to a new machine.
3 years ago
Originally Published: 2001-01-12
Article Number
000061769
Applies To
RSA ACE/Server
RADIUS
UNIX (AIX, HP-UX, Solaris)
Microsoft Windows NT 4.0
Issue
Unable to authenticate through Radius devices after moving the ACE/Server to a new machine.
User receives "Access denied"
Error: "Access Denied"
Error: "Node verification failed" in ACE/Server logs
Cause
There is no securid file present on the ACE/Server Master.
Resolution
Create a client definition in the administration tool for the ACE/Server itself. Authenticate via "path"/ace/prog/sdshell on a UNIX ACE/Server or winnt\system32\sdtest.exe on a Windows NT ACE/Server. This will create a securid file in the "path"/ace/prog directory. If the client already exists, clear the "sent node secret" checkbox before authenticating.
Workaround
Moving a database from one machine to another does not move the securid (node secret) file from "path"/ace/data on the old machine to the new machine. If the IP address or hostname of the server is different from the old machine, the node secret will also change.