Microsoft Integrated Windows Authentication (IWA) fails with 'no uid mapping' error in RSA Access Manager 6.1
Originally Published: 2011-10-05
Article Number
Applies To
RSA Product Set: Access Manager
RSA Product/Service Type: RSA Access Manager Agent 4.8 for IIS 6.0RSA Version: 6.1
Platform: Microsoft Integrated Windows Authentication (IWA)
Issue
ct_agent.log file shows the following error:
2011-10-05 07:44:17 -0400 - [14312] - <Warning> - Agent not enabled for this virtual host 2011-10-05 07:44:17 -0400 - [428] - <Debug> - value_in_map=(null) 2011-10-05 07:44:17 -0400 - [428] - <Critical> - No uid mapping for user user1@supportlab.com at CT_WINDOWS_UPN 2011-10-05 07:44:17 -0400 - [428] - <Warning> - Failed to obtain user mapping 2011-10-05 07:44:17 -0400 - [428] - <Warning> - IWA authentication, No CT uid is available in uid mapping for user :supportlab\\user1, Status is CT_COOKIE_ERROR
SunOne LDAP log shows the following error:
[05/Oct/2011:07:44:17 -0400] conn=980037 op=81682 msgId=908584 - SRCH base="ou=axm,dc=rsa.com" scope=2 filter="(&(objectClass=inetOrgPerson)(upsUserPrincipalName=user1@supportlab.com))" attrs="uid UserPrincipalName" [05/Oct/2011:07:44:17 -0400] conn=980037 op=81682 msgId=908584 - RESULT err=11 tag=101 nentries=0 etime=0 notes=U
Cause
Resolution
cleartrust.data.ldap.user.attributemap.windowsupn :userPrincipalName
By default this value is set to userPrincipalName which typically already has an index in most LDAP stores, but if a custom attribute is used here you may need to add an index manually.
Related Articles
Cloud Access Service - Integrated Windows Authentication 6Number of Views Integrated Windows Authentication 28Number of Views Deploying Integrated Windows Authentication 86Number of Views Terminated Users not correctly removed from Roles in RSA Identity Governance & Lifecycle 115Number of Views "The request could not be handled" message occurs in the RSA Identity Governance & Lifecycle UI when a rule remediator is … 66Number of Views
Don't see what you're looking for?