Active Directory AFX Connector fails to create or modify accounts due to an 'LDAPException: Insufficient Access Rights' error in RSA Identity Governance & Lifecycle
Originally Published: 2018-06-08
Last Modified: 2023-12-01
Article Number
Applies To
RSA Version/Condition: 7.0.x, 7.1.x
Issue
The $AFX_HOME/esb/logs/esb.AFX-MAIN.log has the following error:
2018-05-31 16:29:35.675 [INFO] org.mule.api.processor.LoggerMessageProcessor:193 - returning: -1 ->
LDAPException: Insufficient Access Rights (50) Insufficient Access Rights
LDAPException: Server Message: 00000005: SecErr: DSID-03152612,
problem 4003 (INSUFF_ACCESS_RIGHTS), data 0
LDAPException: Matched DN
The $AFX_HOME/esb/logs/esb.AFX-CONN-{connector-name}.log (the connector log for the specific AFX connector that is failing) has the same error:
Root Exception stack trace:
LDAPException: Insufficient Access Rights (50) Insufficient Access Rights
LDAPException: Server Message: 00000005: SecErr: DSID-03152612,
problem 4003 (INSUFF_ACCESS_RIGHTS), data 0
LDAPException: Matched DN:
Cause
Resolution
Notes
Related Articles
RSA Governance & Lifecycle Recipes: Overview - Access Rights 10Number of Views AFX Server on Windows fails to stop/start with a message 'This script requires elevated rights' in RSA Governance & Lifecycle 51Number of Views WebSphere fails to restart with no errors in SystemOut.log but shows KMS failing right before loading Luna libraries 25Number of Views Active Directory AFX Connector Create Account capability fails when skip certificate validation in RSA Identity Governance… 407Number of Views How to define a custom attribute as a user with group review rights in RSA Identity Governance and Lifecycle 40Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Unable to login to RSA Authentication Manager Security Console as super admin Manual synchronization introduced in RSA Authentication Manager 8.2 Service Pack 1 patch 6 Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory How to verify NTP server synchronization is not working in RSA Authentication Manager 8.x
Don't see what you're looking for?