This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Accept
Reject
  • RSA.com
  • Home
  • Advisories
    • SecurID
    • SecurID Governance & Lifecycle
  • Documentation
    • SecurID
      • Authentication Agents
        • API / SDK
        • Apache Web Server
        • Citrix StoreFront
        • IIS Web Server
        • MFA Agent for macOS
        • MFA Agent for Windows
        • Microsoft AD FS
        • Microsoft Windows
        • PAM
      • Authentication Engine
      • Authentication Manager
      • Cloud Authentication Service
      • Hardware Appliance
        Component Updates
      • Hardware Tokens
      • Integrations
      • SecurID App
      • SecurID Authenticator for macOS
      • SecurID SDK
      • Software Tokens
        • Android
        • iOS
        • macOS
        • Token Converter
        • Windows
    • SecurID Governance & Lifecycle
    • Technology Partners
  • Downloads
    • SecurID
      • Authentication Agents
        • API / SDK
        • Apache Web Server
        • Citrix StoreFront
        • IIS Web Server
        • MFA Agent for macOS
        • MFA Agent for Windows
        • Microsoft AD FS
        • Microsoft Windows
        • PAM
      • Authentication Engine
      • Authentication Manager
      • Cloud Authentication Service
      • Hardware Appliance
        Component Updates
      • Hardware Tokens
      • Integrations
      • SecurID Authenticator for macOS
      • Software Tokens
        • Android
        • iOS
        • macOS
        • Token Converter
        • Windows
    • SecurID Governance & Lifecycle
  • Community
    • SecurID
      • Blog
      • Discussions
      • Events
      • Idea Exchange
      • Knowledge Base
    • SecurID Governance & Lifecycle
      • Blog
      • Discussions
      • Events
      • Idea Exchange
      • Knowledge Base
  • Support
    • Case Portal
      • Create New Case
      • View My Cases
      • View My Team's Cases
    • Community Support
      • Getting Started
      • News & Announcements
      • Ideas & Suggestions
      • Community Support Articles
      • Community Support Forum
    • Product Life Cycle
    • Support Information
    • General Security Advisories
  • Education
    • Blog
    • Browse Courses
      • SecurID
      • SecurID Governance & Lifecycle
    • Certification Program
    • New Product Readiness
    • Student Resources
Sign In Register Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
Announcements

SecurID® Discussions

Browse the SecurID discussion board to get product help and collaborate with other SecurID users.
  • SecurID Community
  • :
  • Products
  • :
  • SecurID
  • :
  • Discussions
  • :
  • RSA CTKIP URLs
  • Options
    • Subscribe to RSS Feed
    • Mark Topic as New
    • Mark Topic as Read
    • Float this Topic for Current User
    • Bookmark
    • Subscribe
    • Mute
    • Printer Friendly Page
ZahidYaqub
ZahidYaqub Beginner
Beginner
‎2019-09-25 06:32 AM
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

RSA CTKIP URLs

I am facing an interesting error. My deployment consist of one primary and one replica instance and also I have webtier Installed.  I have imported soft-tokens and hard tokens. everything is working fine except  ctkip token distribution. I have  question. When I install a web tier server and enable Dynamic seed Provisioning does it automatically move CTKIP service from primary instance to web tier ? and how can i verify on which server ctkip service is running ? 

 

When I I try to Import a token on my phone I get an error " Token Import failed" contact your system admin. 

Labels (1)
Labels
  • Labels:
  • RSA Authentication Manager

  • Tags:
  • AM
  • Auth Manager
  • Authentication Manager
  • Community Thread
  • ct-kip services
  • Discussion
  • Forum Thread
  • RSA Authentication Manager
  • RSA SecurID
  • RSA SecurID Access
  • SecurID
  • Web-Tier
0 Likes
Share
Reply
  • All forum topics
  • Previous Topic
  • Next Topic
4 Replies
EdwardDavis
Employee EdwardDavis
Employee
‎2019-09-25 08:01 AM
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

CTKIP will be on the webtier if you have enabled that on webtier, and it will also be on the self-service console. You could edit the webtier URL to be the self-service console and port 7004, and either one could do CTKIP. Whichever one is used first will expire that CTKIP link.

1 Like
Share
Reply
FabioGomes
FabioGomes Beginner
Beginner
In response to EdwardDavis
‎2020-05-26 01:15 PM
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Hi Edward,

 

We have Web Tier implemented.

When we try to import CT-KIP software token (QRCode) we got "Token Import Failed" error.

 

The QRCode URL is:

 

http://127.0.0.1/securid/ctkip?scheme=https&url=<OUR LOCAL SERVER>:7004/ctkip/services/CtkipService&activationCode=<SOME CODE>

 

As our mobile phone can't access our local server, how to set this default URL to point to our Web Tier?

1 Like
Share
Reply
StevenSpicer
Valued Contributor StevenSpicer Valued Contributor
Valued Contributor
In response to FabioGomes
‎2020-05-26 05:35 PM
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

That is the point of the Virtual Hostname.  You specify an externally visible hostname and get it into public DNS, then that address leads to your webtier hosts. You'll need a commercial SSL certificate or the end user devices may not trust it. 

 

A good place to start is the RSA Authentication Manager 8.4 Setup and Configuration Guide, specifically the chapters on Configuring a Load Balancer and Virtual Host, and Installing Web Tiers.  The Help menu in the Security Console can give you more information as well as step-by-step instructions.

1 Like
Share
Reply
EdwardDavis
Employee EdwardDavis
Employee
In response to FabioGomes
‎2020-05-27 08:06 AM
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

In the Security Console look up the option in Help Menu to change the CTKIP URL to whatever you want (which will be the webtier). It will be Security Console, setup, system settings, tokens page.

 

pastedImage_3.png

 

 

NOTE: The built-in Self Service Console CT-KIP will remain working and always be port 7004 [ https://primary.name.com:7004/... ] and any time you create a URL that is the webtier, you could change it by hand to be the self service page...both will keep working and the ct-kip token can be delivered by whichever one you use first.

 

This page here sets what URL gets sent to users to retrieve tokens, but the internal one is always up, as well as the webtier.

1 Like
Share
Reply
Powered by Khoros
  • Blog
  • Events
  • Discussions
  • Idea Exchange
  • Knowledge Base
  • Case Portal
  • Community Support
  • Product Life Cycle
  • Support Information
  • Customer Success
  • About the Community
  • Terms & Conditions
  • Privacy Statement
  • Provide Feedback
  • Employee Login
© 2022 RSA Security LLC or its affiliates. All rights reserved.