Readme
RSA Authentication Agent 6.1 for Microsoft Windows

November 28, 2006

 

Introduction

This document lists late-breaking information for RSA Authentication Agent 6.1 for Microsoft Windows. Read this document before installing the software. This document contains the following sections:

This Readme may be updated. The most current version can be found on RSA SecurCare Online https://knowledge.rsasecurity.com. To print this Readme, click here.


Product Documentation

RSA Authentication Agent 6.1 for Microsoft Windows includes the following documentation:

You can access the Installation and Administration Guide, the Planning Guide, and the Readme directly from the RSA Authentication Agent 6.1 for Microsoft Windows downloadable .zip file, or from the RSA Authentication Agent 6.1 for Microsoft Windows CD. However, you can access the Help only by installing RSA Authentication Agent 6.1 for Microsoft Windows.

Top


 

Supported Platforms

Although RSA Authentication Agent 6.1 for Microsoft Windows is supported on Windows 2003 Enterprise and Windows 2000 Advanced Server, these platforms have not been qualified for this release of the software.


Required Service Packs and Fixes

Top


Known Issues

Interoperability

Installation

If you manually installed only the Authentication Agent Remote Authentication Server component or RSA Security EAP Client component, and then uninstall the Authenticator Utility, perform the following steps:

If you silently installed only the Authentication Agent Remote Authentication Server component or RSA Security EAP Client component, and then install the Authenticator Utility, silently reinstall the Authentication Agent components.

If you silently installed only the Authentication Agent Remote Authentication Server component or RSA Security EAP Client component, and then uninstall the Authenticator Utility, silently reinstall the Authentication Agent components.

Configuration

Authentication

General Authentication

Authentication Using the RSA SecurID Authenticator SID800 USB Token

Wireless Authentication

Remote Authentication

After initially installing the local authentication client component on a computer, some Authentication Agent features do not work when you are remotely connected to the network unless you do one of the following:

Offline Authentication

Terminal Services Authentication

For Windows XP platforms, remove your RSA SecurID Authenticator SID800 USB token from your computer before you run a terminal services session to the computer. If you leave the token connected to the computer and then run a terminal services session to the computer, you need to restart the computer before you can log on to it again.

RSA Security Center

Tracing

Windows Password Integration

On Local Authentication Client computers, policy settings are updated every two hours. Therefore, when you enable Windows password integration on a client computer, Windows password integration will not work until the policy has been updated. However, if you cannot wait until the policy is updated automatically, you can force a policy update by restarting the client computer.

Workstation Unlock with RSA SecurID PIN

Documentation Issues

The RSA Authentication Agent 6.1 for Microsoft Windows Installation and Administration Guide and the RSA SecurID for Microsoft Windows Planning Guide 1.1 erroneously recommend a minimum of 5 MB of disk space for successful installation of RSA Authentication Agent 6.1 for Microsoft Windows. RSA Security recommends 50 MB of disk space for successful installation.

Top


Variations from Microsoft Compliance

RSA Authentication Agent 6.1 for Microsoft Windows complies with Microsoft branding requirements with the following exceptions. The titles and title numbers in this section pertain to the Microsoft compliance documentation.

Cross-Platform Certification Requirements

2.5 Install to Program Files by Default

RSA Authentication Agent 6.1 for Microsoft Windows installs the following shared files in SystemFolder:

Installing the files elsewhere makes the Authentication Agent incompatible with legacy RSA Security products that share these files. The Authentication Agent also installs unshared files inherited from previous versions of the Agent to SystemFolder.

The Authentication Agent installs the following files to WindowsFolder\Help:

S5.4 Install using a Windows Installer-Based Package That Passes Validation Testing

RSA Authentication Agent 6.1 for Microsoft Windows installation deviates from certification requirements by adding references in the Start menu to components that occur per computer as opposed to per user. This is required because the RSA Authentication Agent can be installed only once on a computer, and all Start menu references must pertain to all users. Therefore, registry key links to these components must originate under HKLM instead of HKCU.

Windows 2000 Server Certification Requirements

3.3 Provide Documented Keyboard Access to all Features

RSA Authentication Agent 6.1 for Microsoft Windows documents all assigned navigation keys in the interface with underlines.

Windows Server 2003 Certification Requirements

S2.8 Terminal Server Requirements

The RSA Authentication Agent 6.1 for Microsoft Windows installation modifies a HKEY_CURRENT_USER value. However, the modification results from Microsoft Windows Installer and not from the Authentication Agent software.

3.8 Services Running as LocalSystem Must Not Present a UI

The sdagentsvc service opens the default Microsoft Windows station and desktop. However, it does not present a user interface or accept user input or Windows messages.

Windows XP Certification Requirements

2.6: Install Shared Files to the Correct Locations

RSA Authentication Agent 6.1 for Microsoft Windows does not support the side-by-side shared files requirement because doing so would disable the backward compatibility of legacy Agents. Therefore, the following files are installed under the /program files folder/RSA Security/RSA Authentication Agent directory:

The following files must remain in the /system32 directory to ensure backward compatibility with legacy agents:

2.7 Support Add or Remove Programs Properly

The RSA Authentication Agent 6.1 for Microsoft Windows uninstaller removes all "non-shared" .dll files and services. It also removes all registry keys associated with the Authentication Agent that are not user configuration settings that must be maintained for future installations. The uninstall does not remove the following files:

3.2 Classify and Store Application Data Correctly

The sdcatool writes to a registry key other than HKCU. However, the sdcatool is designed to affect the system as a whole, and not individual users.

Top


Getting Support and Service

RSA SecurCare Online: https://knowledge.rsasecurity.com

Customer Support Information: www.rsasecurity.com/support

RSA Secured Partner Solutions Directory: www.rsasecured.com

Top


© 2006 RSA Security Inc. All rights reserved.

Trademarks

ACE/Agent, ACE/Server, Because Knowledge is Security, BSAFE, ClearTrust, Confidence Inspired, e-Titlement, IntelliAccess, Keon, RC2, RC4, RC5, RSA, the RSA logo, RSA Secured, the RSA Secured logo, RSA Security, SecurCare, SecurID, SecurWorld, Smart Rules, The Most Trusted Name in e-Security, Transaction Authority, and Virtual Business Units are either registered trademarks or trademarks of RSA Security Inc. in the United States and other countries. All other goods and services mentioned are trademarks of their respective companies.

Top