<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Linux, windows, asterisk, vmware &#187; rsa</title>
	<atom:link href="http://blog.simplic8.com/tag/rsa/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.simplic8.com</link>
	<description></description>
	<lastBuildDate>Tue, 08 Jun 2010 02:00:01 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>RSA ACE agent Access denied. Name lock failed.</title>
		<link>http://blog.simplic8.com/2010/01/18/rsa-ace-agent-access-denied-name-lock-failed/</link>
		<comments>http://blog.simplic8.com/2010/01/18/rsa-ace-agent-access-denied-name-lock-failed/#comments</comments>
		<pubDate>Mon, 18 Jan 2010 04:57:04 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[Windows Server]]></category>
		<category><![CDATA[rsa]]></category>
		<category><![CDATA[RSA Authentication Manager]]></category>
		<category><![CDATA[RSA Security Console]]></category>

		<guid isPermaLink="false">http://blog.simplic8.com/?p=200</guid>
		<description><![CDATA[I have been configured &#038; testing the RSA SecureID and i&#8217;ve setup the servers, integrated into the LDAP directory etc, I have multiple hosts connected and working, however I have been running into the following issue.
1234shayne@db1 ~]$ sudo /opt/pam/bin/acetest
Enter USERNAME: shayne
Access denied. Name lock failed.
[shayne@db1 ~]$ sudo /opt/pam/bin/acetes
There is no information on the error ANYWHERE! [...]]]></description>
			<content:encoded><![CDATA[<p>I have been configured &#038; testing the RSA SecureID and i&#8217;ve setup the servers, integrated into the LDAP directory etc, I have multiple hosts connected and working, however I have been running into the following issue.</p>
<div class="codecolorer-container text mac-classic" style="overflow:auto;white-space:nowrap;border: 1px solid #9F9F9F;width:435px;"><table cellspacing="0" cellpadding="0"><tbody><tr><td style="padding:5px;text-align:center;color:#888888;background-color:#EEEEEE;border-right: 1px solid #9F9F9F;font: normal 12px/1.4em Monaco, Lucida Console, monospace;"><div>1<br />2<br />3<br />4<br /></div></td><td><div class="text codecolorer" style="padding:5px;font:normal 12px/1.4em Monaco, Lucida Console, monospace;white-space:nowrap">shayne@db1 ~]$ sudo /opt/pam/bin/acetest<br />
Enter USERNAME: shayne<br />
Access denied. Name lock failed.<br />
[shayne@db1 ~]$ sudo /opt/pam/bin/acetes</div></td></tr></tbody></table></div>
<p>There is no information on the error ANYWHERE! *sigh*</p>
<p>Some people might find this funny, but I finally found an Authentication Monitor in the RSA Security Console, the whole thing is quite easy once you get your head around everything <img src='http://blog.simplic8.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p>After starting the Real-Time Authentication Monitor It logged the following error..</p>
<div class="codecolorer-container text mac-classic" style="overflow:auto;white-space:nowrap;border: 1px solid #9F9F9F;width:435px;"><table cellspacing="0" cellpadding="0"><tbody><tr><td style="padding:5px;text-align:center;color:#888888;background-color:#EEEEEE;border-right: 1px solid #9F9F9F;font: normal 12px/1.4em Monaco, Lucida Console, monospace;"><div>1<br /></div></td><td><div class="text codecolorer" style="padding:5px;font:normal 12px/1.4em Monaco, Lucida Console, monospace;white-space:nowrap">Node secret mismatch: cleared on server but not on agent</div></td></tr></tbody></table></div>
<p>Now at this point in time, I have not setup any node secret, the ACE Admin guide explains the following</p>
<blockquote><p>Best Practices for Automatic Delivery<br />
If you use Automatic Delivery, which is the default setting, the Authentication<br />
Manager automatically creates and sends the node secret to the Agent Host in<br />
response to the first successful authentication on the Agent Host. The transmission<br />
containing the node secret is encrypted with a key derived from the user’s passcode in<br />
combination with other information.<br />
•    Windows Agents with a version of 4.4.0 or later store the node secret file in the<br />
     system registry.<br />
•    Windows legacy Agents (other than 4.4.0) store the node secret file in the<br />
     %SYSTEMROOT%\system32 directory.<br />
• All UNIX Agents store the node secret file in the in the ACEDATA directory.<br />
The default name of the node secret file is securid.<br />
In the case of Automatic Delivery, capture of the node secret is possible if you are not<br />
careful to control the circumstances in which the first authentication on each Agent<br />
Host occurs.</p></blockquote>
<p>So, with that in mind, I did the following..</p>
<div class="codecolorer-container text mac-classic" style="overflow:auto;white-space:nowrap;border: 1px solid #9F9F9F;width:435px;"><table cellspacing="0" cellpadding="0"><tbody><tr><td style="padding:5px;text-align:center;color:#888888;background-color:#EEEEEE;border-right: 1px solid #9F9F9F;font: normal 12px/1.4em Monaco, Lucida Console, monospace;"><div>1<br />2<br />3<br />4<br /></div></td><td><div class="text codecolorer" style="padding:5px;font:normal 12px/1.4em Monaco, Lucida Console, monospace;white-space:nowrap">[root@db1 bin]# cd /var/ace/<br />
[root@db1 ace]# ls<br />
sdconf.rec &nbsp;sdstatus.1 securid<br />
[root@db1 ace]# rm securid</div></td></tr></tbody></table></div>
<p>I went back and tested the authentication, and BAM, it now works. &#8220;Authentication method success&#8221;</p>
<p>You will notice that it&#8217;s now auto generated a new secureid file <img src='http://blog.simplic8.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' />  It&#8217;s probably better that you create a new Node Secret file for each Agent, however i&#8217;m just in the testing phase right now, apart from a crap interface and confusing setup process, it handles it&#8217;s intended job very well. kudos to RSA.</p>
<img src="http://blog.simplic8.com/?ak_action=api_record_view&id=200&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://blog.simplic8.com/2010/01/18/rsa-ace-agent-access-denied-name-lock-failed/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
