Microsoft Integrated Windows Authentication (IWA) fails with 'no uid mapping' error in RSA Access Manager 6.1
Originally Published: 2011-10-05
Article Number
Applies To
RSA Product Set: Access Manager
RSA Product/Service Type: RSA Access Manager Agent 4.8 for IIS 6.0RSA Version: 6.1
Platform: Microsoft Integrated Windows Authentication (IWA)
Issue
ct_agent.log file shows the following error:
2011-10-05 07:44:17 -0400 - [14312] - <Warning> - Agent not enabled for this virtual host 2011-10-05 07:44:17 -0400 - [428] - <Debug> - value_in_map=(null) 2011-10-05 07:44:17 -0400 - [428] - <Critical> - No uid mapping for user user1@supportlab.com at CT_WINDOWS_UPN 2011-10-05 07:44:17 -0400 - [428] - <Warning> - Failed to obtain user mapping 2011-10-05 07:44:17 -0400 - [428] - <Warning> - IWA authentication, No CT uid is available in uid mapping for user :supportlab\\user1, Status is CT_COOKIE_ERROR
SunOne LDAP log shows the following error:
[05/Oct/2011:07:44:17 -0400] conn=980037 op=81682 msgId=908584 - SRCH base="ou=axm,dc=rsa.com" scope=2 filter="(&(objectClass=inetOrgPerson)(upsUserPrincipalName=user1@supportlab.com))" attrs="uid UserPrincipalName" [05/Oct/2011:07:44:17 -0400] conn=980037 op=81682 msgId=908584 - RESULT err=11 tag=101 nentries=0 etime=0 notes=U
Cause
Resolution
cleartrust.data.ldap.user.attributemap.windowsupn :userPrincipalName
By default this value is set to userPrincipalName which typically already has an index in most LDAP stores, but if a custom attribute is used here you may need to add an index manually.
Related Articles
RSA November 2023 Release Announcements 15Number of Views Integrated Windows Authentication 28Number of Views Cloud Access Service - Integrated Windows Authentication 6Number of Views Deploying Integrated Windows Authentication 80Number of Views Configure User Browsers for Integrated Windows Authentication 13Number of Views
Trending Articles
RSA Authentication Manager Upgrade Process RSA Release Notes for RSA Authentication Manager 8.8 RSA RADIUS Server service failed to start in the RSA Authentication Manager 8.1 Operations Console Microsoft Entra ID External MFA - Relying Party Configuration Using OIDC - RSA Ready Implementation Guide RSA Release Notes: Cloud Access Service and RSA Authenticators
Don't see what you're looking for?