Previous Topic: Recreating a Tenant After Deletion FailsNext Topic: Error With AcrotID PKI Authentication With Desktop Client 1.6


Authentication Issues

Connector Server Network Peers Connectivity Problems

Symptom:

When using network peer On Premise CA IAM Connector Server and you stop one CA IAM Connector Server, it may not be detected, and previsioning may fail.

Solution:

When you stop one CA IAM Connector Server, force a synchronization between the two on-premise nodes.

User With Expired Credentials Must Perform Extra Step

Symptom:

When authenticating with PKI, you use your password to unlock your PKI credentials. If you are forced to change your password (such as when a temporary password is generated, or the admin sets the user to change password) and authenticate with PKI, Advanced Authentication sends you correctly to the enrollment task, where you can change your password and reissue your PKI credentials in one task.

However, if you authenticate with PKI and you are in violation of password policies (such as inactivity, not changing your password in required time) Advanced Authentication does not detect this. The system then sends you to the Password Change task.

Solution:

Users must first go to the Password Change task, and then the Enrollment task. Users must change their password, and then perform a secondary authentication to reissue their credentials.

Special Characters Not Allowed In Username During Arcot OTP Enrollment

Symptom:

If a user’s name or other account information uses special characters (such as an umlaut: ü), trying to enroll a user with Arcot One Time Password generates an error message.

Solution:

If possible, do not use special characters when entering user information. Special characters include Chinese and Japanese characters, as well as the following characters: À, Á, Â, Ã, Ä, È, É, Ê, Ë, Ò, Ó, Ô, Õ, Ö, Û, Ü, à, á, â, ã, ä