Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

Publish OWA w/SecurID - Node Verification Failed

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA 2006 Publishing] >> Exchange Publishing >> Publish OWA w/SecurID - Node Verification Failed Page: [1]
Login
Message << Older Topic   Newer Topic >>
Publish OWA w/SecurID - Node Verification Failed - 14.Nov.2006 10:39:41 PM   
jerrice

 

Posts: 28
Joined: 9.Dec.2005
Status: offline
Hi there...  I hope someone has some ideas on this, as it's been driving us nuts for a while now.  We have ISA 2006 Ent. set up, and are trying to publish Exchange 2003 OWA w/SecurID 6.1.  The ISA server has VPN and Local Authentication set up and running fine (so that would be the Local and Remote clients).  I've set up the OWA publishing rule and listener, and am getting the correct log-in screen (the 3 parter with user name, passcode, and password requested).  When I try to log in, I get an Access Denied error back from ISA, and the RSA server shows the following in the log:
11/15/2006 03:25:39U ----------/isaserver.domain.corp     ---->
11/14/2006 19:25:29L  Node verification failed                   rsaserver.domain.corp

The node is behaving correctly for local logins, and for VPN, so I suspect the node secret is fine.  I have tried clearing and re-instating it, but it did not help.  To set up OWA, I used the page at http://www.trustedaccess.info/.  I've got the published server running fine with the web agent, and I'm able to access that internally.

Any thoughts?
Post #: 1
RE: Publish OWA w/SecurID - Node Verification Failed - 15.Nov.2006 2:06:42 PM   
jerrice

 

Posts: 28
Joined: 9.Dec.2005
Status: offline
Ok, I got this figured out.  I'll document it in case someone else runs into it.  Apparently, ISA doesn't pick up the new node verification unless you reboot the server, even if the other verifications (for VPN, local access) are working.  Re-starting ISA didn't fix the problem, I had to actually reboot the server.

(in reply to jerrice)
Post #: 2
RE: Publish OWA w/SecurID - Node Verification Failed - 1.Feb.2007 8:33:14 PM   
shan.lee

 

Posts: 10
Joined: 16.Jan.2007
From: Brisbane, Australia
Status: offline
I'm having this exact same problem, but a restart hasn't helped.

I've even completely ripped out all the securid stuff I could find , removed the entry from the ACE server and started again, and ended up right back at the same point.

If I log onto the ISA server and use SDTEST, it authenticated fine. Go into the listener, tick the 'collect additional information' box, select securid, apply changes, restart firewall service and/or reboot, SDTEST still works fine, OWA gives me error 100 indicating the ACE server refused me, and the ACE log shows a node verification failure.

I'm stumped.

P.S. I have OWA, Activesync and RPC/HTTP all on this listener if that matters.

(in reply to jerrice)
Post #: 3
RE: Publish OWA w/SecurID - Node Verification Failed - 2.Mar.2007 9:32:19 AM   
Darkstarr13

 

Posts: 2
Joined: 10.Feb.2006
Status: offline
___________________ ISA - remove all SDCONF.REC (either in C:\windows\system32 and/or c:\program files\Microsoft ISA server\sdconfig) - remove all SECURID files (either in C:\windows\system32 and/or c:\program files\Microsoft ISA server\sdconfig), not necessarily on the system - remove file sdstatus.12 (c:\program files\Microsoft ISA server\sdconfig) - ensure, that if there is a sdopts.rec, that is ONLY contains a line "CLIENT_IP=xx.xx.xx.xx", nothing else
- reboot ISA ACE - edit agent host and ensure that node secret is unchecked, if not correct it   Go to Internet, start browser and do first authentication to the ISA. File SECURID should now be created in c:\program files\Microsoft ISA server\sdconfig, along with sdstatus.rec   (the test authentication tool was not used and will create node secret in a different folder than ISA expects) ___________________ That worked for me.
By the way: I troubleshooted the location of the SDOPTS.REC, SECURID and SDCONF.REC with FILEMON from Sysinternals (filter to process wspsrv.exe). Ín conjunction with the event log on ISA it gives you all the locations. At some point in the log you will see a CREATE of the SECURID file.


(in reply to jerrice)
Post #: 4
RE: Publish OWA w/SecurID - Node Verification Failed - 5.Apr.2007 10:26:05 AM   
Zabulon

 

Posts: 22
Joined: 23.Jan.2007
Status: offline
I am recieving the same 'Node verification failed' error on my ISA 2006 box.  I tried removing the sdconf.rec, etc and rebooting but it did not resolve my issue.  I can successfully authenticate with the RSA test tool but get the Error:









100: Access denied. RSA ACE/Server rejected the passcode that you supplied. Try again with a valid passcode.
when trying to loing through OWA.

Any help would be appreciated!

(in reply to Darkstarr13)
Post #: 5
RE: Publish OWA w/SecurID - Node Verification Failed - 9.Apr.2007 5:50:43 PM   
shan.lee

 

Posts: 10
Joined: 16.Jan.2007
From: Brisbane, Australia
Status: offline
Darkstarrs post is spot on, but I somehow managed to have all my files created in \system32. I manually copied them across to the sdconfig folder and it worked.

(in reply to Zabulon)
Post #: 6
RE: Publish OWA w/SecurID - Node Verification Failed - 13.Apr.2007 5:46:24 PM   
jerrice

 

Posts: 28
Joined: 9.Dec.2005
Status: offline
One thing I just noticed after my OWA stopped working again:
On my ISA server that SECURID file didn't seem to get created in the C:\Program Files\Microsoft ISA Server\sdconfig directory.  I had to manually copy it from C:\Windows\System32.  Once I did that, with no restarts or anything, OWA started working with RSA correctly again.

< Message edited by jerrice -- 13.Apr.2007 6:05:33 PM >

(in reply to Zabulon)
Post #: 7
RE: Publish OWA w/SecurID - Node Verification Failed - 16.Apr.2007 11:22:05 AM   
Zabulon

 

Posts: 22
Joined: 23.Jan.2007
Status: offline
Thanks guys for the input... I found the isue:

I was running my sdtest.exe from the \system32 folder not from the \ISA folder.

Once i ran it from there it created the files I needed then I manually copied them into the \ISA folder\sdconfig and it worked like a charm! 

Thanks for all the input

(in reply to jerrice)
Post #: 8
RE: Publish OWA w/SecurID - Node Verification Failed - 9.May2007 5:02:28 AM   
TCalixto

 

Posts: 24
Joined: 25.Apr.2003
From: The Netherlands
Status: offline
Jerrice,

The RSA authentication server and the host agent (ISA Server) exchange encrypted information when they connect for the very first time.

Now, here is the catch: by sucessfully connect the host agent to the RSA Auth. Serv. with the SDTEST tool a node secret will be created between them.This encrypted information is not the same that will be used by the ISA Server API when connecting to the RSA Auth. Serv. via a Publishing Rule.

A new set of encrypted information needs to be created. To do so, create a publishing rule that uses RSA SecurID and then connect to the published site with an external client.

Good luck.






(in reply to jerrice)
Post #: 9
RE: Publish OWA w/SecurID - Node Verification Failed - 9.May2007 10:40:52 AM   
TCalixto

 

Posts: 24
Joined: 25.Apr.2003
From: The Netherlands
Status: offline
Jarrice,

In addition to my last, here is the link where the document can be found:

http://www.microsoft.com/downloads/details.aspx?familyid=7B0CA409-55D0-4D33-BB3F-1BA4376D5737&displaylang=en

Specifically the ISA Server 2006 Tools: RSA Test Authentication Utility document. Section 3 goes as follows:

1.       After successfully running the RSA Test Authentication Utility, perform the following steps:
a.        On the ISA Server computer, verify that the Sdconfig folder under the ISA Server installation folder contains only the file Sdconf.rec. Delete any other files that you find in this folder.
b.        On the RSA Authentication Manager computer, on the Agent Host menu, click Edit Agent Host, select the name of your ISA Server computer, and then verify that Sent Node Secret is not selected.

(in reply to TCalixto)
Post #: 10

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [ISA 2006 Publishing] >> Exchange Publishing >> Publish OWA w/SecurID - Node Verification Failed Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts