This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Accept
Reject
  • RSA.com
  • Home
  • Advisories
    • SecurID
    • SecurID Governance & Lifecycle
  • Documentation
    • SecurID
      • Authentication Agents
        • API / SDK
        • Apache Web Server
        • Citrix StoreFront
        • IIS Web Server
        • MFA Agent for macOS
        • MFA Agent for Windows
        • Microsoft AD FS
        • Microsoft Windows
        • PAM
      • Authentication Engine
      • Authentication Manager
      • Cloud Authentication Service
      • Hardware Appliance
        Component Updates
      • Hardware Tokens
      • Integrations
      • SecurID App
      • SecurID Authenticator for macOS
      • SecurID SDK
      • Software Tokens
        • Android
        • iOS
        • macOS
        • Token Converter
        • Windows
    • SecurID Governance & Lifecycle
    • Technology Partners
  • Downloads
    • SecurID
      • Authentication Agents
        • API / SDK
        • Apache Web Server
        • Citrix StoreFront
        • IIS Web Server
        • MFA Agent for macOS
        • MFA Agent for Windows
        • Microsoft AD FS
        • Microsoft Windows
        • PAM
      • Authentication Engine
      • Authentication Manager
      • Cloud Authentication Service
      • Hardware Appliance
        Component Updates
      • Hardware Tokens
      • Integrations
      • SecurID Authenticator for macOS
      • Software Tokens
        • Android
        • iOS
        • macOS
        • Token Converter
        • Windows
    • SecurID Governance & Lifecycle
  • Community
    • SecurID
      • Blog
      • Discussions
      • Events
      • Idea Exchange
      • Knowledge Base
    • SecurID Governance & Lifecycle
      • Blog
      • Discussions
      • Events
      • Idea Exchange
      • Knowledge Base
  • Support
    • Case Portal
      • Create New Case
      • View My Cases
      • View My Team's Cases
    • Community Support
      • Getting Started
      • News & Announcements
      • Ideas & Suggestions
      • Community Support Articles
      • Community Support Forum
    • Product Life Cycle
    • Support Information
    • General Security Advisories
  • Education
    • Blog
    • Browse Courses
      • SecurID
      • SecurID Governance & Lifecycle
    • Certification Program
    • New Product Readiness
    • Student Resources
Sign In Register Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
Announcements

SecurID® Product Advisories

Read and subscribe to the latest announcements and advisories relating to the SecurID product.
  • SecurID Community
  • :
  • Products
  • :
  • SecurID
  • :
  • Advisories
  • :
  • Product Advisories
  • :
  • Action Required for Upcoming Identity Router and RSA SecurID Authenticate App Security Improvements
  • Options
    • Subscribe to RSS Feed
    • Bookmark
    • Subscribe
    • Email to a Friend
    • Printer Friendly Page
    • Report Inappropriate Content
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Action Required for Upcoming Identity Router and RSA SecurID Authenticate App Security Improvements

Summary:

To strengthen the overall security of RSA SecurID Access, RSA is rolling out significant improvements that affect all identity routers and the RSA SecurID Authenticate app (iOS and Android). Changes include:

  • Improving the strength of our database encryption by using Federal Information Processing Standards (FIPS)-supported algorithms in the Cloud Authentication Service.
  • Forcing the use of Transport Layer Security (TLS) 1.2 or greater encryption for all communication from the identity routers to the Cloud Authentication Service.
  • Identity routers upgraded to SUSE Linux Enterprise Server (SLES) version 12 SP5 hardened to Security Technical Implementation Guide (STIG) standards.

To ensure uninterrupted service and avoid downtime, you must take action by the following dates.

 

Event & ActionBegin ActionEnd Action

After RSA migrates database data to FIPS-supported algorithms, the Cloud Administration Console will display a Changes Pending message. Please ignore this message as a publish is not required. This status will disappear after your next regular publish.

No customer action needed.
EMEA and ANZ regions: 8/29/2020
US region: 9/12/2020
The RSA SecurID Authenticate app version 2.x will no longer work for iOS or Android. Users must upgrade to the latest version in order to authenticate. See the advisory for details.ImmediatelyOctober 12, 2020

You must update all identity routers to the August release (version 12.10.0.0.5 or higher for on-premises identity routers and RSA_Identity_Router 12.10.0.0.6 or higher for Amazon Cloud) before the last identity router upgrade date (October 31, 2020). After October 31, RSA SecurID Access will enforce TLS1.2 for all connections. Versions of TLS earlier than 1.2 will no longer work. To ensure uninterrupted connectivity, make sure your identity routers are running at least software version 12.10.0.0.8 prior to October 31. For instructions, see Update Identity Router Software for a Cluster.
If you are using a proxy server you must ensure it also support TLS 1.2 and later.

Follow your normal upgrade schedule.

October 31, 2020

Note: A new identity router that takes advantage of hardened security and the latest operating system patches using SLES version 12 SP5 is coming in November. Watch future notifications for details.

 

For additional documentation, downloads and more, visit the RSA SecurID Access page on RSA Link.

EOPS Policy:RSA has a defined End of Primary Support policy associated with all major versions. Please refer to the Product Version Life Cycle for additional details.
Labels (1)
Labels:
  • Product Advisories

Tags (13)
  • Advisory
  • Announcement
  • Product Advisory
  • product announcement
  • Product Communication
  • Product Notification
  • release announcement
  • RSA SecurID
  • RSA SecurID Access
  • SCOL Note
  • SecurID
  • SecurID Access
  • SecurID Suite
1 Like
Was this article helpful? Yes No
Share
No ratings
Version history
Last update:
‎2020-08-26 09:53 AM
Updated by:
Employee RSASecurIDTeam
Contributors
  • RSASecurIDTeam
    RSASecurIDTeam

Related Content

Article Dashboard
  • Article History
Powered by Khoros
  • Blog
  • Events
  • Discussions
  • Idea Exchange
  • Knowledge Base
  • Case Portal
  • Community Support
  • Product Life Cycle
  • Support Information
  • Customer Success
  • About the Community
  • Terms & Conditions
  • Privacy Statement
  • Provide Feedback
  • Employee Login
© 2022 RSA Security LLC or its affiliates. All rights reserved.