locked
Suggestion on Invalid_CRM_WRPC_Token value in CRM 2013 RRS feed

  • Question

  • Hello All,

    I am using CRM 2013, and facing an issue for a long time that Invalid_CRM_WRPC_Token value. I researched and found a way to make the changes in registry setting on CRM Server to fix this issue.

    Refer this link Click Here

    This is unsupported way and I did not find that what kind of risk is involved, if we go ahead on production with this method.

    Please let us know. and also if any one has suggestion on the other method to fix this issue, share with us.

    Thanks.


    Make sure to "Vote as Helpful" and "Mark As Answer",if you get answer of your question.


    Monday, January 12, 2015 10:39 AM

All replies

  • Hello,

    The biggest risk is following - after installation of rollup this functionality can be broken but I believe that would not happen. What kind of issue have you faced?


    Dynamics CRM MVP/ Technical Evangelist at SlickData LLC
    My blog

    Monday, January 12, 2015 10:48 AM
    Moderator
  • The use of tokens is a line of defence against cross-site request forgery attacks. There are two different ways to consider this:

    1. Good security practise would be to maintain defence in depth against all possible types of attacks, so you shouldn't disable tokens
    2. Or, cross-site request forgery attacks can only happen if something else is breached (normally cross-site scripting), and if cross-site scripting is breached, then that is a bigger problem that cross-site request forgery. Therefore it is not a big issue to disable tokens

    Where do you get the Invalid_CRM_WRPC_Token errors ? I'm not aware of any issues with using supported functionality in Crm 2013 that would give these errors. I can imagine unsupported modifications that could through these errors, but if that's the case it may be best to see if you can resolve the issue through changing the approach to a supported one


    Microsoft CRM MVP - http://mscrmuk.blogspot.com/ http://www.excitation.co.uk

    Monday, January 12, 2015 11:32 AM
    Moderator
  • Thanks Andrii and David for the response.

    Few users are facing this issue, when they are trying to download the document attached in Note. But for the other users it is working fine.Here, we did not done any customization.

    I am unable to get that, Whay system in generating invalid token value for some users?


    Make sure to "Vote as Helpful" and "Mark As Answer",if you get answer of your question.

    Monday, January 12, 2015 11:43 AM
  • What happens when they perform the same in private browsing?

    Thanks!

    Kalim Khan

    Monday, January 12, 2015 1:14 PM
  • Hey Kalim, If we tried with the Private Browsing, still it is giving the same error.


    Make sure to "Vote as Helpful" and "Mark As Answer",if you get answer of your question.

    Monday, January 12, 2015 1:25 PM
  • Are you using any antivirus like Kaspersky?

    Regards Faisal

    Monday, January 12, 2015 1:43 PM
  • No, We are not using Kaspersky.


    Make sure to "Vote as Helpful" and "Mark As Answer",if you get answer of your question.

    Monday, January 12, 2015 2:40 PM