Unable to vCenter RSA 2fa after upgrading RSA Manager 8.8P1 to 8.8P2
search cancel

Unable to vCenter RSA 2fa after upgrading RSA Manager 8.8P1 to 8.8P2

book

Article ID: 421569

calendar_today

Updated On:

Products

VMware vCenter Server

Issue/Introduction

  • Upgraded RSA Manager 8.8P1 to 8.8P2.
  • RSA does not push out the 2fa requests to our phones and immediately reject PIN number.
  • vCenter RSA 2fa authentication fails

Environment

vCenter 8.x

Cause

The vCenter RSA agent MessageKey is controlled by a timer. After upgrading the RSA manager, the vCenter STS service has to be restarted to clear the invalid MessageKey if trying to authenticate before the timer expires to get a new MessageKey.

Resolution

Restart vCenter services:

vcsa# service-control --stop --all; service-control --start --all

Or specifically the STS service: 

vcsa# /usr/lib/vmware-vmon/vmon-cli --restart sts

Additional Information

Contact RSA support for further assistance, see vCenter RSA ready Implementation Guide.