|Applies To||RSA ClearTrust 5.5 install scripts|
Microsoft Windows 2000 Professional SP4
Microsoft Active Directory
|Issue||Error: "Add error on line xx: Constraint violation. x entries modified successfully. An error has occurred in the program." while running Install-ct-data.bat file prior to RSA ClearTrust installation|
If attempting to add the ctscUserDN attribute manually to the CN=Default Administrative User object, the following error appears:
C3:24:45 PM: Failed to add 'ctscUserDN' attribute for ldap://127.0.0.1:389/CN=Default Administrative User, OU=ctscAdminRepository, OU=cleartrustmy, DC=ds,DC=dev,DC=rsa,DC=com
Reason: [LDAP: error code 19 - 000020B5: AtrErr: DSID-03152286, #1:
0: 000020B5: DSID-03152286, problem 1005 (CONSTRAINT_ATT_TYPE), data 0, Att 40b60048 (ctscUserDN)
This error occurs if the Administrative user does not already exist in Active Directory, the Administrative User is in the wrong location, or if the Administrative User has not been replicated to the local domain. Double check the spelling of the ctscUserDN value. A constraint violation is issued whenever an attempt is made to add an attribute of type DN where the DN does not point to a valid object in the AD domain - in this case, the DN of the administrative user.
To correct this issue, set up a normal Active Directory user object to be used for ClearTrust administration. This user should be within the scope of the base DN set in the cleartrust.data.ldap.user.basedn parameter. Modify the last line of the install-activedirectory.ldif file, ensuring that the value of ctscUserDN: points to the full DN of the user you have created. Lastly, run the install-ct-data.bat file again.
|Legacy Article ID||a22260|