
This document lists late-breaking information for RSA Authentication Agent 6.1 for Microsoft Windows. Read this document before installing the software. This document contains the following sections:
This Readme may be updated. The most current version can be found on RSA SecurCare Online https://knowledge.rsasecurity.com. To print this Readme, click here.
RSA Authentication Agent 6.1 for Microsoft Windows includes the following documentation:
You can access the Installation and Administration Guide, the Planning Guide, and the Readme directly from the RSA Authentication Agent 6.1 for Microsoft Windows downloadable .zip file, or from the RSA Authentication Agent 6.1 for Microsoft Windows CD. However, you can access the Help only by installing RSA Authentication Agent 6.1 for Microsoft Windows.
Although RSA Authentication Agent 6.1 for Microsoft Windows is supported on Windows 2003 Enterprise and Windows 2000 Advanced Server, these platforms have not been qualified for this release of the software.
For wireless authentication using EAP, access points must support 802.1x authentication.
To use wireless LAN with PEAP, install SP2 for Windows XP or SP1 for Windows Server 2003. If you cannot update to the current service pack, you must install Microsoft hot fix Article ID #827537 on the Windows XP client and the Windows Server 2003 host. To get the fix and installation instructions, see "Windows XP Service Pack 1 and Windows Server 2003 wireless clients are not compatible with RSA Security Extensible Authentication Protocol (EAP) type" in the Microsoft Knowledge Database at www.microsoft.com.
RSA Authentication Agent 6.1 for Microsoft Windows is not compatible with pcAnywhere.
The RSA SecurID for Microsoft Windows solution does not support smart card-based
logon. RSA Security recommends that you disable the smart card service on
client computers that host RSA Authentication Agent 6.1 for Microsoft Windows.
If the smart card service on the client computer is not disabled, smart
card authentications bypass RSA SecurID authentications.
To use RSA Authentication Agent and Novell on the same computer, you must install Novell before installing RSA Authentication Agent. When you install RSA Authentication Agent, the installer warns you that another GINA (the Novell GINA) is already installed. When you are prompted, choose to replace the Novell GINA with the Authentication Agent GINA.
Important: If you uninstall RSA Keon Web PassPort before you uninstall the Authentication Agent, you cannot log on to the Authentication Agent host computer.
After installing RSA Authentication Agent 6.1 for Microsoft Windows, you must complete the installation by restarting the Authentication Agent host computer. Installing the Agent modifies the registry to reference the Authentication Agent GINA (AceGina.dll) instead of the Microsoft GINA (msgina.dll).
Installing or uninstalling RSA Authenticator Utility
on a computer that also hosts RSA Authentication Agent requires additional
steps if the only Authentication Agent components installed are the Remote
Authentication Server component or the RSA EAP Client component.
If you manually installed only the Authentication Agent Remote Authentication
Server component or RSA Security EAP Client component, and then install
the Authenticator Utility, perform the following steps:
If you manually installed only the Authentication Agent Remote Authentication Server component or RSA Security EAP Client component, and then uninstall the Authenticator Utility, perform the following steps:
If you silently installed only the Authentication Agent Remote Authentication Server component or RSA Security EAP Client component, and then install the Authenticator Utility, silently reinstall the Authentication Agent components.
If you silently installed only the Authentication Agent Remote Authentication Server component or RSA Security EAP Client component, and then uninstall the Authenticator Utility, silently reinstall the Authentication Agent components.
- Use the Cisco Installation Wizard to uninstall the Cisco software.
Important: Do not use the Microsoft Windows Add/Remove program.
- Reinstall the Cisco software without PEAP.
To change the machine name of an Authentication Agent host computer:
- On the Authentication Agent host computer, set the RSA SecurID challenge to None.
- Change the machine name.
- Set the challenge to a setting other than None, and select the challenge group based on the new machine name.
If you have already changed the machine name of an Authentication Agent host computer without performing the preventative steps listed above, perform the following steps:
- Restart the Authentication Agent host computer in Safe mode.
- Log on as an administrator.
- Set the challenge to None.
- Restart the computer.
- Log on as an administrator.
- Set the challenge to a setting other than None, and select the challenge group based on the new machine name.
To change the static IP address of an Agent host computer:
Change the IP address of the Authentication Agent host computer, then restart the computer.
Although the RSA Authentication Manager allows the @ sign as part of a user name, Windows Active Directory does not.
When you use a connected RSA SecurID Authenticator SID800 USB token, the Time Remaining field on the RSA Security Center View USB Token page shows that the tokencode is valid for a greater amount of time than it is actually valid. Regardless of how long a tokencode has displayed, every time you reopen the View USB Token page, the Time Remaining field starts a new count instead of beginning the count at the actual amount of time the tokencode remains valid. Therefore, the Time Remaining field and the actual time the tokencode remains valid may differ by as much as 60 seconds.
Remote access authentication with wireless PEAP does not support RSA SecurID authenticators set for 180 second intervals.
In this release, RSA Security EAP - Protected OTP without PEAP does not support session resumption. Users must reauthenticate if the wireless connection is lost. Session resumption is supported if you are using PEAP.
When a computer comes out of hibernation during a wireless connection, the connection can be restored without an additional authentication. For greater security, disable hibernation on users' computers and instruct users to log off the network before leaving their desks.
When you roam from one access point to another, if access points are serviced by the same IAS server, you are not prompted for additional RSA SecurID passcodes. However, if you roam to an access point that is serviced by a different IAS server, you must reauthenticate. To enable wireless authentication to work in this way, you must enable Fast Reconnect in the PEAP configuration on the remote client computer.
During an initial wireless authentication, the Authentication Agent prompts you for both a user name and an RSA SecurID passcode. During subsequent authentications, the Authentication Agent prompts you for only an RSA SecurID passcode. If, during a subsequent authentication, you must provide a different user name, cancel the prompt and perform the following steps:
At the next authentication prompt, change the user name.
For more information, see Microsoft Knowledge Base article #823731 "How
to remove cached user credentials that are used for PEAP authentication in
Windows XP."
After initially installing the local authentication client component on a computer, some Authentication Agent features do not work when you are remotely connected to the network unless you do one of the following:
Restart the client computer at least once after performing a test authentication or authenticating online.
If you cannot connect to the network directly, do the following:
If, during authentication, the system prompts the user to recharge offline days, then notifies the user that the recharge failed, determine whether the user's RSA SecurID token is about to expire. If a user authenticates with an RSA SecurID token that is set to expire before the user's offline days expire, the system prompts the user to recharge offline logon days. However, it is not possible to recharge offline days under this circumstance, and attempts to do so fail.
If you clear offline data from an Authentication Agent host, but RSA Security Center still shows available offline days, instruct the user to restart RSA Security Center.
For Windows XP platforms, remove your RSA SecurID Authenticator SID800 USB token from your computer before you run a terminal services session to the computer. If you leave the token connected to the computer and then run a terminal services session to the computer, you need to restart the computer before you can log on to it again.
The first time you use the RSA Security Center to enable tracing and specify a log file as the tracing destination, the system continues to log GINA tracing to the default location, aceclient.log, instead of the specified destination. To solve the problem, restart the computer.
On Local Authentication Client computers, policy settings are updated every two hours. Therefore, when you enable Windows password integration on a client computer, Windows password integration will not work until the policy has been updated. However, if you cannot wait until the policy is updated automatically, you can force a policy update by restarting the client computer.
Workstation Unlock with RSA SecurID PIN (Quick Workstation Unlock) does not work if you reset your PIN to a character length that is not the same as the former PIN. Although the PIN Unlock screen appears, you are not able to unlock your workstation using your new PIN. If you experience this problem, click Force Logoff, and then unlock the workstation by entering your user name and RSA SecurID passcode.
The RSA Authentication Agent 6.1 for Microsoft Windows Installation and Administration Guide and the RSA SecurID for Microsoft Windows Planning Guide 1.1 erroneously recommend a minimum of 5 MB of disk space for successful installation of RSA Authentication Agent 6.1 for Microsoft Windows. RSA Security recommends 50 MB of disk space for successful installation.
RSA Authentication Agent 6.1 for Microsoft Windows complies with Microsoft branding requirements with the following exceptions. The titles and title numbers in this section pertain to the Microsoft compliance documentation.
RSA Authentication Agent 6.1 for Microsoft Windows installs the following shared files in SystemFolder:
Installing the files elsewhere makes the Authentication Agent incompatible
with legacy RSA Security products that share these files. The Authentication
Agent also installs unshared files inherited from previous versions of the Agent
to SystemFolder.
The Authentication Agent installs the following files to WindowsFolder\Help:
RSA Authentication Agent 6.1 for Microsoft Windows installation deviates from
certification requirements by adding references in the Start menu to components
that occur per computer as opposed to per user. This is required because the
RSA Authentication Agent can be installed only once on a computer, and all Start
menu references must pertain to all users. Therefore, registry key links to
these components must originate under HKLM instead of HKCU.
RSA Authentication Agent 6.1 for Microsoft Windows documents all assigned navigation keys in the interface with underlines.
The RSA Authentication Agent 6.1 for Microsoft Windows installation modifies a HKEY_CURRENT_USER value. However, the modification results from Microsoft Windows Installer and not from the Authentication Agent software.
The sdagentsvc service opens the default Microsoft Windows station and desktop. However, it does not present a user interface or accept user input or Windows messages.
RSA Authentication Agent 6.1 for Microsoft Windows does not support the side-by-side shared files requirement because doing so would disable the backward compatibility of legacy Agents. Therefore, the following files are installed under the /program files folder/RSA Security/RSA Authentication Agent directory:
The following files must remain in the /system32 directory to ensure backward compatibility with legacy agents:
The RSA Authentication Agent 6.1 for Microsoft Windows uninstaller removes all "non-shared" .dll files and services. It also removes all registry keys associated with the Authentication Agent that are not user configuration settings that must be maintained for future installations. The uninstall does not remove the following files:
The sdcatool writes to a registry key other than HKCU. However, the sdcatool is designed to affect the system as a whole, and not individual users.
RSA SecurCare Online: https://knowledge.rsasecurity.com
Customer Support Information: www.rsasecurity.com/support
RSA Secured Partner Solutions Directory: www.rsasecured.com
© 2006 RSA Security Inc. All rights reserved.
ACE/Agent, ACE/Server, Because Knowledge is Security, BSAFE, ClearTrust, Confidence Inspired, e-Titlement, IntelliAccess, Keon, RC2, RC4, RC5, RSA, the RSA logo, RSA Secured, the RSA Secured logo, RSA Security, SecurCare, SecurID, SecurWorld, Smart Rules, The Most Trusted Name in e-Security, Transaction Authority, and Virtual Business Units are either registered trademarks or trademarks of RSA Security Inc. in the United States and other countries. All other goods and services mentioned are trademarks of their respective companies.