May 26, 2004
This document lists late-breaking information for RSA ACE/Agent 5.6 for Windows. Read this document before installing the software. This document contains the following sections:
This Readme may be updated. You can get the most current version on RSA SecurCare Online https://knowledge.rsasecurity.com.
RSA ACE/Agent 5.6 for Windows includes the following documentation:
You can access the RSA ACE/Agent 5.6 for Windows Installation and Administration Guide and the RSA ACE/Agent 5.6 for Windows Readme directly from the WinAgent56.zip file. However, you can access the Help only by installing RSA ACE/Agent 5.6 for Windows.
When you install RSA ACE/Agent 5.6 for Windows, you can instruct the installation program to copy the RSA ACE/Agent 5.6 for Windows Installation and Administration Guide and the RSA ACE/Agent 5.6 for Windows Readme (this document) to the Agent host. The RSA ACE/Agent 5.6 for Windows Installation and Administration Guide is copied to the %SYSTEMROOT%\system32\Aceclnt directory. The RSA ACE/Agent 5.6 for Windows Readme is copied to the %SYSTEMROOT%\system32\Aceclnt\nt_i386 directory.
To use the RSA ACE/Agent on Windows XP computers, you must install Service Pack 1 (SP1).
To use Wireless LAN with PEAP, you must install Microsoft fix Article ID #827537 on the Windows XP client and the Windows Server 2003 host. To get the fix and installation instructions, see "Windows XP SP1 and Windows Server 2003 Client cannot connect to some third-party wireless implementations of 802.1X," in the Microsoft Knowledge Database at www.microsoft.com.
For wireless communication, Cisco access points must have 1204 firmware or later.
To use RSA SecurID token cards and fobs set for 180 second intervals, you must install fixes on the RSA ACE/Server and the RSA ACE/Agent client component host. Otherwise, the RSA SecurID authentication prompts time out before the token generates a new passcode. To get the fixes, call RSA Security Customer Support and request the following:
RSA ACE/Server
Remote access authentication with wireless PEAP does not support RSA SecurID
token cards and fobs set for 180 second intervals.
Important: DO NOT install RSA ACE/Agent 5.6 for Windows if your current Agent installation has the Network access or Web access authentication components, and you want to continue to use these components. Installing RSA ACE/Agent 5.6 for Windows removes any previous versions of web and network access, and installs the only the Local and Remote access authentication components.
When a user who is not an administrator on the host computer attempts to install RSA ACE/Agent 5.6 for Windows, an incorrect error message appears. The message should read, "To install the Agent, you must be an administrator on the host computer." If you see an error message when you attempt to install RSA ACE/Agent 5.6, make sure you have administrative privileges on the installation host.
For wireless authentication using Cisco, if you erroneously install Cisco PEAP on a client computer instead of installing Microsoft EAP, perform the following steps:
For wireless authentication, when users attempt to authenticate while the RSA ACE/Server is down, and the IAS server has been restarted, the system does not generate the message Access Denied.
For wireless authentication with EAP, when a user enters an invalid passcode at two consecutive authentication prompts, the system generates the message "Access Denied" each time. However, if the user enters an invalid passcode at the third consecutive authentication prompt, the system does not generate the message. Unless the system generates the message "Authentication Successful," the user's third passcode is invalid.
For wireless authentication with EAP, if the user enters a passcode at the authentication prompt, and the system does not generate an "Access Denied" or "Authentication Successful" message, there may be a problem with your network.
The IAS System Event log may indicate that users are timing out when the
actual problem is that the connection to the ACE Server is down. To determine
whether that is the case, check the IAS application Event log.
For wireless authentication with EAP, if a user enters a username that is not recognized by Active Directory Server, or not in the specified domain, the system generates the message "Cannot be logged on." The system also logs a message in the Microsoft IAS Event log. If this situation occurs:
For wireless authentication with EAP, if a user successfully authenticates to the RSA ACE/Server and the wireless card is subsequently disabled and enabled, the user remains authenticated. Therefore, RSA Security recommends that you protect resources that are accessible through wireless connections with a password in addition to RSA SecurID authentication.
When a computer comes out of hibernation during a wireless connection, the connection is restored without an additional authentication. This occurs because, by default, the hibernation and disabling timer (tls_cache timeout) is set to 10 hours. Only wireless connections in excess of 10 hours require users to authenticate a second time. For greater security, RSA Security recommends that instead of using hibernation, you log off the network.
For wireless authentication with PEAP, after you enter your RSA SecurID credentials, you see a screen that asks you to validate the server credentials. If you do not address this screen immediately by clicking one of the options, the system generates multiple copies of the screen.
For wireless authentication, if you roam from one access point to another while maintaining the connection you are not prompted for additional RSA SecurID passcodes. However, if the connection breaks, you must reauthenticate. To enable wireless authentication to work in this way, you must enable "Fast Reconnect" on both the IAS server and the client computer.
During an initial wireless authentication, the Agent prompts you for both a username and an RSA SecurID passcode. During subsequent authentications, the Agent prompts you for only an RSA SecurID passcode. If, during a subsequent authentication, you must provide a different username, cancel the prompt and perform the following steps:
When you successfully authenticate to open a wireless connection, the RSA SecurID Successful Authentication dialog box opens. If you click OK, the dialog box closes. If you do not click OK, the dialog box closes automatically within approximately 25 seconds.
For Windows Server 2003, if Terminal Services or Citrix Metaframe users are prompted to authenticate with RSA SecurID even though you configured the terminal server for standard Windows authentication, install hot fix article number 838462 from the Microsoft web site.
If a user logs on to a local computer with a username and password that matches domain credentials, then successfully establishes an authenticated wireless PEAP connection, the user gains access to domain resources without having to authenticate to the domain. This behavior is supported by Microsoft.
If the RSA ACE/Server does not accept a new PIN during authentication through RSA Security EAP (Extensible Authentication Protocol), the system does not generate a message to indicate that the new PIN was rejected. Instead, the system display the message "Access Denied." If this situation occurs, check with the RSA ACE/Server administrator to determine whether the new PIN was accepted or rejected.
On Windows XP computers, if you configure Local access authentication to challenge groups with either the "Users In" or "All Users except" settings, there may be instances where every user is challenged when the computer is restarted. This is caused by a delay in relaying necessary group information from the Windows XP operating system to the RSA ACE/Agent. Instruct users who are inappropriately challenged to do the following:
During the second login, the user is not challenged.
The section "Wireless LAN Access Authentication Platforms and Requirements" in "Chapter 1: Requirements and Preparations" in the RSA ACE/Agent 5.6 for Windows Installation and Administration Guide states, "Computers that act as clients must have wireless LAN cards that support 802.1X PEAP, and computers that act as servers must have connections to access points that support 802.1X PEAP." It should be, "Computers that act as clients must have wireless LAN cards that support the 802.1X PEAP protocol and 802.11B networking technology. Computers that act as servers must have connections to access points that support the 802.1X PEAP protocol and 802.11B networking technology."
Some sections in the documentation use the term "post-dial terminal based" incorrectly. When referring to remote connections without EAP, the term is used correctly. When referring to remote connections with EAP, the term should be replaced with "dial-up."
The information in "Appendix B: Automated Registration of Agent Hosts in the RSA ACE/Server Database" does not pertain to RSA ACE/Servers that are later than verison 4.1.
If you do not configure the RRAS server to use RSA EAP, the Routing and Remote Access Service will use RSA EAP setting is ignored.
For more information on setting up wireless LAN connections with access points that support 802.1X PEAP, see the documentation provided by Microsoft and your access points vendor.
| RSA SecurCare Online | https://knowledge.rsasecurity.com |
| Customer Support Information | http://www.rsasecurity.com/support |
(c) 2004 RSA Security Inc. All rights reserved.
First printing: February 2004
Trademarks
ACE/Agent, ACE/Server, Because Knowledge is Security, BSAFE, ClearTrust, Keon,
RC2, RC4, RC5, RSA, the RSA logo, RSA Secured, RSA Security, SecurCare, SecurID,
Smart Rules, The Most Trusted Name in e-Security, and Virtual Business Units
are registered trademarks, and e-Titlement, the RSA Secured logo, SecurWorld,
and Transaction Authority are trademarks of RSA Security Inc. in the U.S. and/or
other countries. All other trademarks mentioned herein are the property of their
respective owners.