You are prompted two times when you access a Web site that uses RSA SecurID authentication ISA Server 2004 (897328)



The information in this article applies to:

  • Microsoft Internet Security and Acceleration Server 2004, Enterprise Edition
  • Microsoft Internet Security and Acceleration Server 2004, Standard Edition

SYMPTOMS

Consider the following scenario. You try to visit a Web site that uses RSA SecurID authentication. A Web publishing rule in Microsoft Internet Security and Acceleration (ISA) Server 2004 publishes the Web site that you try to visit. You have enabled Web access authentication cookies for the domain. In this scenario, ISA Server prompts you for your credentials. Additionally, the Web server also prompts you for your credentials.

Note ISA Server must validate your credentials and then pass the validation to the upstream Web server. The Web server itself must not prompt you for your credentials. When you enable domain cookies, ISA Server must prompt you for your credentials one time.

CAUSE

This problem occurs because RSA SecurID authentication and validation fails for single sign on (SSO) from ISA Server to the upstream Web server that uses RSA Authentication Agent 5.3.

RESOLUTION

To resolve this problem, apply the fix that is described in the RSA SecurCare Online Knowledgebase article, ID16753. For more information about this fix, visit the following RSA SecurCare Online Web site:

Microsoft provides third-party contact information to help you find technical support. This contact information may change without notice. Microsoft does not guarantee the accuracy of this third-party contact information.

MORE INFORMATION

The third-party products that this article discusses are manufactured by companies that are independent of Microsoft. Microsoft makes no warranty, implied or otherwise, regarding the performance or reliability of these products.

Modification Type:MinorLast Reviewed:5/9/2006
Keywords:kbtshoot kbBug kbprb KB897328 kbAudITPRO