Passwrdstate RSA SecurID Cnfiguratin This dcument and the infrmatin cntrlled therein is the prperty f Click Studis. It must nt be reprduced in whle/part, r therwise disclsed, withut prir cnsent in writing frm Click Studis.
Table f Cntents 1 INTRODUCTION... 3 2 CREATING AND INSTALLING SECURID CONFIGURATION FILES... 4 3 TROUBLESHOOTING AUTHENTICATION ISSUES... 7
1 Intrductin This dcument will describe the prcess fr initially cnfiguring Passwrdstate t use tw-factr authenticatin with RSA s SecurID. It will als prvide sme guidance in trubleshting authenticating users, as the respnse cdes returned frm an attempted authenticatin sessin can smetimes be unclear. IMPORTANT When fllwing the instructins in this dcument, yu must be lgged int the RSA Security Cnsle with a user accunt which has Auth Mgr Agent Admin rights.
2 Creating and Installing SecurID Cnfiguratin Files Once Passwrdstate is installed and peratinal, yu must fllw the steps belw t create and cpy acrss the SecurID cnfiguratin files. Please nte these steps are based n RSA Authenticatin Manager 7.1 SP4 Patch 22, s the screens/instructins may be different fr yur versin f Authenticatin Manager. Create Authenticatin Agent(s) Lgn nt yur Authenticatin Manager Security Cnsle Navigate t the menu Access -> Authenticatin Agents -> Add New Select the apprpriate Security Dmain, specify the fully qualified Hstname f yur Passwrdstate web server, and click the Reslve IP Address buttn t ensure DNS is wrking crrectly Click n the Save buttn
Nte 1: Yu may need t specify different settings n this screen fr yur envirnment i.e. Enable Trusted Realm Authenticatin, etc. Nte 2: If yu are using the High Availability Instance f Passwrdstate, yu will als need t create an Authenticatin Agent fr yur HA web server hst name, and perfrm the same steps belw fr yur HA web server installatin. Create Nde Secret Navigate t the menu Access -> Authenticatin Agents -> Manage Existing On the right-hand side f the Authenticatin Agent yu just created, select Manage Nde Secret frm the drpdwn menu Click n the ptin Create a new randm nde secret, and exprt the nde secret file Specify an Encryptin Passwrd t use, the click n the Save buttn Click n the Dwnlad Nw buttn, extract the zip file cntents, and cpy the files t the /securid flder in the Passwrdstate web site Create and Install Cnfiguratin File Navigate t the menu Access -> Authenticatin Agents -> Generate Cnfiguratin File Specify any Agent Timeut and Retries settings applicable t yur envirnment Click n the Generate Cnfig file buttn Dwnlad the cnfiguratin file, extract the zip file cntents, and cpy the files t the /securid flder in the Passwrdstate web site
Generate the SecurID <n extensin> File On yur web server, pen a cmmand prmpt with Administrative Privileges Change t the fllwing flder c:\inetpub\passwrdstate\securid\<32bit r 64bit>. The path t this flder may be different fr yur installatin, and yu will need t change t either the 32bit r 64bit perating system, depending n what Operating System Architecture yu are using Type the cmmand belw, and enter the Encryptin Passwrd yu specified abve when prmpted. If the creatin f the securid file is successful, yu will see the message The Nde Secret is successfully laded. agent_nslad.exe -f c:\inetpub\passwrdstate\securid\ndesecret.rec -d c:\inetpub\passwrdstate\securid When the securid file is created, it is created withut any wner r any NTFS permissins. T crrect this, please fllw these instructins: Using Windws Explrer, right-click n the file and select Prperties Click n the Security tab and then n the Advanced buttn Click n the Cntinue buttn Click n the ptin Include inheritable permissins frm the bject s parent, then click n the Apply buttn Click n the OK buttn and clse all remaining pen windws Nte 1: It is imprtant yu fix the NTFS permissins n the securid file, therwise the file cannt be backed up. Nte 2: Please wait at least 10 t 15 minutes befre trying yur first SecurID authenticatin in Passwrdstate, as it can take a little time fr the new Authenticatin Agent t be functinal in RSA Authenticatin Manager. Nte 1: If at any stage yu decide t mve yur Passwrdstate installatin t a different web server with a different hstname/ip address, yu will need t red all these steps.
3 Trubleshting Authenticatin Issues There are multiple reasns why authenticatin can fail fr a user, including an invalid sdcnfig.rec file, r lcked accunt, etc. Apart frm errr messages displayed in Passwrdstate, the mst effective means f determine what s causing the issue is my using the Real-Time Activity Mnitrs feature in yur Authenticatin Manager Security Cnsle. Navigate t Reprting -> Real-Time Activity Mnitrs -> Authenticatin Activity Mnitr Click n the Start Mnitr buttn, and retry yur user authenticatin. Any errrs r successful authenticatin attempts will nw be displayed n the screen belw. If yu re still unable t determine what the cause is, please cntact Click Studis and we will try t assist. If yu see errrs similar t Nde secret mismatch: cleared n server but nt n agent, r Nde secret mismatch. Cleared n agent but nt n server, then yu may need t delete the Authenticatin Agent yu created, and red all the steps abve.