RSA Authentication Manager 6.1.2 for Windows Patch Readme June 2007 ************************************************************ Requirements ************************************************************ Install this patch on all RSA Authentication Manager 6.1.0 and 6.1.1 Primary, Replica, and Remote Administration machines. Install this patch BEFORE you install the RSA Authentication Agent 6.1.2 for Microsoft Windows patch. Note: The RSA Authentication Agent 6.1.2 for Microsoft Windows patch is available from Customer Support. When prompted during this installation, do one of the following: * Insert the RSA Authentication Manager 6.1 CD * Browse to the local installation directory. Note: If the local installation directory no longer exists, you can download the RSA Authentication Manager 6.1 distribution file from the RSA Security web site. ************************************************************ Filename *********************************************************** authmgr_6.1.2_update.zip ************************************************************ NOTES ************************************************************ This patch includes a new "Self-Registered Agent" type. After applying the new type, you can set the RSA_AHAR_RESTRICT_TO_TYPE environment variable to restrict the sharing of IP addresses to Self-Registered Agent Hosts. This ensures that IP addresses are not taken from other agent types, such as the RADIUS Server. In RSA Authentication Manager Host mode, you can select the "Self-Registered Agent" type while adding an agent, or choose Agent Host > Change Agent Type to simultaneously apply the new type to multiple existing Agents, based upon filter criteria. Define RSA_AHAR_RESTRICT_TO_TYPE as a System variable with any value, and restart the machine for the changes to take effect. The "Self-Registered Agent" type takes its configuration settings from the Network Operating System Agent Host. ************************************************************ Primary and Replica Installation Instructions ************************************************************ 1) Terminate all administrative sessions, including Quick Admin and Remote Administration. 2) On the Primary RSA Authentication Manager, stop the authentication and broker services. 3) Extract the authmgr_6.1.2_update.zip file to the authmgr_6.1.2_update directory. 4) Execute authmgr_6.1.2_update.exe. 5) Follow the prompts to complete the installation. 6) Repeat steps 2 through 5 to perform the upgrade on each Replica. 7) Restart the Primary Authentication Manager, then restart each Replica. ************************************************************ Remote Administration Installation Instructions ************************************************************ 1) Copy authmgr_6.1.2_update.exe to the Remote Administration machine. 2) Execute authmgr_6.1.2_update.exe. 3) Follow the prompts to complete the installation. 4) Restart the machine. ************************************************************ Remote Administration Silent Installation Instructions ************************************************************ 1) Copy authmgr_6.1.2_update.exe to the Remote Administration machine. 2) The command to start the installation is authmgr_6.1.2_update.exe /s /v"/qb TYPE=REMOTE REINSTALL=ALL REINSTALLMODE=o" Note: Make sure you include the necessary quotation marks in the command. ************************************************************ Known Issues ************************************************************ 46421 You must back up any Quick Admin customizations before applying the update, and then reapply them after the update is complete. Otherwise, you will need to recreate your custom settings. 46434 Certain RADIUS clients can't handle the "Prompt" attribute, as defined in "RFC 2869 - RADIUS Extensions." For example, during access-challenge authentication, a New-PIN request with the "Prompt=NoEcho" attribute instructs the RADIUS client to not display the user's new PIN. If a RADIUS client can't handle the "Prompt" attribute, it rejects the New-PIN request, and remains in New-PIN mode. Customer sites with this issue can reconfigure RADIUS to resolve this problem by editing radius.ini. Remove the semi-colon (;) before "[Configuration]" to enable this section, and add the line shown below: [Configuration] DisablePromptAttribute = 1 Note: These changes prevent the RADIUS Server from sending the "Prompt" attribute to any RADIUS clients. Even RADIUS clients capable of handling the "Prompt=NoEcho" attribute may display the user's new PIN. 53172 The optional add-on described in the RSA RADIUS Server 6.1 Administrator’s Guide (rsa_radius_admin.pdf) in "Appendix A: Using the LDAP Configuration Interface" is not available. This appendix does not apply to RSA RADIUS Server 6.1. 55499 When you convert your deployment from the Domain Authentication solution to the Local Authentication solution, custom settings, such as the location of the offline days file folder, are reverted to default settings. After replacing the Domain Authentication Server component with the Local Authentication client component, users are unable to download offline days. To resolve this issue: 1) Remove the Agent Host record for the Authentication Agent on the domain controller from the Authentication Manager database, and then re-create it manually as a Net OS Agent. 2) Use the RSA Security Center on the domain controller to clear the Node Secret on the domain controller. 3) Restart the domain conroller. Offline days download successfully. 23477 You must install the RSA RADIUS Server 6.1.1 patch before uninstalling the RSA RADIUS Server or uninstalling any RSA Authentication Agent on the same system. You should install the RSA RADIUS Server 6.1.1 patch before installing RSA RADIUS Server 6.1.2. 56136 If you restore your RSA Authentication Manager 6.1.2 database from a 6.1 or 6.1.1 backup file, you must re-create the "Self-Registered Agent" type that was added by the 6.1.2 patch. Open a command prompt, change to the \Program Files\RSA Security\RSA Authentication Manager\prog directory, and type: agenttype -a To confirm that the "Self-Registered Agent" type is added to the database, at the command prompt, type: agenttype -l 22645 RSA Authentication Manager uses TCP and UDP ports as described in the section "Services With Network Ports (Windows and UNIX)" in "Appendix B: Services and Processes" of the RSA Authentication Manager 6.1 Administrator's Guide. Make sure these ports are not already defined for use by other services. If they are, you must make these ports available for use by RSA Authentication Manager or reconfigure the Authentication Manager to use ports other than the documented defaults. 20044 Profile names in the RSA Authentication Manager database cannot be longer than 48 characters. You must use the Administration Toolkit to add and edit profile names in excess of 48 characters. ************************************************************ This patch resolves the following issues since RSA Authentication Manager patch 6.1.1. ************************************************************ Defect Description ------ ----------- 20955 Can successfully compile Custom Queries that use the MAX or MIN aggregate functions and pass the syntax check. 21479 Offline authentication now supports uppercase alphabetic PIN characters. 24012 Replaced a misleading Quick Admin error with a session timeout message. If you log on to Quick Admin using Internet Explorer and are idle for 15 minutes, an informational event log message indicates that the session is exiting due to a timeout. 24270 Unassigned, revoked, or replaced tokens are automatically disabled, and unassigned tokens cannot be enabled again. Authentication Manager disables imported tokens that were previously exported as unassigned and enabled. 24380 Fixed a Quick Admin error that could cause a denial of service. 25226 Fixed an issue where replicating the SDProfile table caused database errors. 25307 After a token was deleted on a Replica, the Primary was not updated. 26010 8-digit PIN offline authentication issues resolved. 26493 An incorrect token was identified while assigning a replacement token. The correct replacement token is now selected. 39304 Fixed an issue where a large database caused a slow response to authentication requests. 39802 Fixed a cosmetic display issue that caused high LDAP port numbers to show a comma. 40068 Sd_DynamicSelectTS now accepts spaces as a valid column separator. 40069 Utilities that display version information now show the cumulative hot fix build number. 40375 Updated jsed to handle record locking conflicts more appropriately. 40490 The RSA Authentication Manager Host Mode failed to open from the Windows Start menu. 40655 Updated lock manager to prevent the Replica alias address list from being added to the address table of the next Replica. 41638 Quick Admin can now display group names that contain a comma. 44012 Under certain circumstances, tokens were disabled too soon. 44181 Sd_ResetToken sometimes reported a misleading invalid token error for a valid token. 45332 Fixed an auto-registration issue that affected certain legacy agent hosts. 45545 Auto-registration succeeds when there is no node secret or hostname in the database, but an existing IP address. 45546 Auto-registration succeeds after the Agent hostname changes, but the IP address remains the same. The original node secret is cleared, and the IP address is reassigned. 45547 Auto-registration succeeds after an Agent changes its hostname and IP address. Auto-registration creates a new Agent Host with a new IP address, and the node secret is cleared. 45548 Auto-registration automatically detects Agent IP address changes. The node secret and hostname remain the same, but the IP address changes. 45549 After changing the Agent IP address, you can successfully run manual auto-registration. 45550 With a multi-homed host, authentications use the IP address registered by auto-registration. 45551 A registered Agent Host that is taken offline without authenticating can register again with a new IP address. 45644 Exiting the tcl shell without using Sd_ApiEnd failed to end apidemon. 46166 Authentication Manager now correctly converts Agent Host names to lowercase letters. 46169 Updated the cumulative hot fix TCL scripts. 46321 Fixed an issue where foreign characters were not being sent from Quick Admin to the Authentication Manager Server. 52975 Applied a Progress Software hot fix that addresses an issue in which improperly specifying the length of input to the database port could cause heap corruption. ************************************************************ The following files are updated during installation: ************************************************************ Primary and Replica Installations: \Program Files\RSA Security\RSA Authentication Manager\doc\ acehelp.cnt acehelp.hlp authmgr_admin.pdf authmgr_admin_toolkit.pdf authmgr_authentication.doc authmgr_authentication.pdf authmgr_authorization_api.pdf authmgr_deployment.pdf authmgr_getting_started.pdf authmgr_install_unix.pdf authmgr_install_windows.pdf authmgr_performance.pdf authmgr_readme.pdf patch_readme_win.txt tacplus_user_guide.pdf \Program Files\RSA Security\RSA Authentication Manager\prog\ _aceping.exe _mprosrv.exe aceclnt.dll acesrvc.exe acesrvc_be.exe acesrvc_fe.dll agenttype.exe apidemon.exe cfgmgmt.exe commands.conf dps.exe dumpreader.exe jsed.exe logmaintthd.exe patchinfo.dll rsalicutil.exe sdadmlch.exe sdadmind.exe sdcmprss.exe sdcommd.exe sdcommd_session.exe sdconfig.exe sddump.exe sddumpsrv.exe sdldapsync.exe sdload.exe sdloadsrv.exe srvcmgr.dll syncsrvc.exe sys_console_nt.exe tpyldap.dll \Program Files\RSA Security\RSA Authentication Manager\prog\proapi adbapi.pl sdproapi.pl \Program Files\RSA Security\RSA Authentication Manager\prog\progui agtypewiz.r editcli.r edittok.r edituser.r impdump.r importtk.r ldapjobe.r menu.r prow32.dll qrywizard.r radiuspol.r replactk.r revstok.r rpltklst.r sdabout.r sdmpro.dll \Program Files\RSA Security\RSA Authentication Manager\prog\protrig sdtrig.pl \Program Files\RSA Security\RSA Authentication Manager\utils\oldutil emergency.exe repltok.exe resync.exe setpin.exe \Program Files\RSA Security\RSA Authentication Manager\utils\tcl\bin tcl-sd.exe wish-sd.exe \Program Files\RSA Security\RSA Authentication Manager\utils\toolkit ace_api.lib ace_apits.lib acert_api.lib acert_apits.lib admexampts.cpp api_errors.h api_msgs.h apiuser.h apiuserts.h message.h -------------------------------------------------------- Remote Administration Installations: \Program Files\RSA Security\RSA Authentication Manager\prog\ _aceping.exe _mprosrv.exe aceclnt.dll acesrvc_fe.dll sdadmlch.exe sdconfig.exe srvcmgr.dll sys_console_nt.exe \Program Files\RSA Security\RSA Authentication Manager\prog\proapi adbapi.pl sdproapi.pl \Program Files\RSA Security\RSA Authentication Manager\prog\progui agtypewiz.r editcli.r edittok.r edituser.r impdump.r importtk.r ldapjobe.r menu.r prow32.dll qrywizard.r radiuspol.r replactk.r revstok.r rpltklst.r sdabout.r sdmpro.dll ***** End of Readme *****