aservers occasionally are unable to decrypt tokens from other aservers.
Originally Published: 2009-02-04
Article Number
Applies To
Issue
IWA authentication method loops continually without sending authenticated user to protected page.
aserver logs show the following error message directly associated with each IWA authentication failure:
sequence_number=5943,remote_client=aserver1,2009-02-03 15:59:52:344 GMT+00:00,messageID=6,client_ip_address=192.168.0.1,client_port=38547,result_code=0,result_action=User Token Failed,result_reason=Token error
Cause
Resolution
Check to ensure that there are no typos in the keyserver.conf files. Specifically check to ensure that each keyserver has a unique name defined for
cleartrust.keyserver.local_id
and that host name defined in the parameter refers to the physical machine where the keyserver resides.
Workaround
Notes
Related Articles
How to decrypt RADIUS traffic using Wireshark with RSA Authentication Manager 364Number of Views Bluecoat SSL Visibility "Traffic between Google Chrome and Google services, such as Gmail, can no longer be decrypted by S… 44Number of Views Error "System was modified beyond the allowed threshold, cannot decrypt" on RSA Authentication Manager 8.x 330Number of Views Corrections to RSA SecurID Token Record Decryption Guide 103Number of Views No encrypted token records were found in folder 205Number of Views
Trending Articles
AFX Server remains in a 'Not running' State, afx status shows 'timed out waiting for AFX applications to start' and mule_e… RSA Release Notes for RSA Authentication Manager 8.8 RSA Authentication Manager 8.7 SP1 Patch 1 Hotfix 1 Downloading RSA Authentication Manager license files or RSA Software token seed records RESTful Web Service Connector capability test fails with unauthorized (401) error when using Basic authentication in RSA G…
Don't see what you're looking for?