RSA Identity Governance & Lifecycle authentication fails if the authentication sources uses Aveksa Data Collector (ADC) and the AccountSearchAttribute is different than the distinguishedName
Originally Published: 2017-01-24
Article Number
Applies To
RSA Version/Condition: 6.9.1 P16, 6.9.1 P17, 7.0.0 P04, 7.0.1
Issue
Invalid Login credentials
This issue occurs if the authentication sources use Aveksa Data Collector (ADC) and the AccountSearchAttribute is different than the distinguishedName.
The error in the aveksaServer.log always says that the account is orphaned, even though the account is not orphaned and there are no duplicate accounts in the system.
09/23/2016 15:19:52.569 WARN (default task-56) [com.aveksa.gui.core.ACMLoginLogout] name is not in dn format javax.naming.InvalidNameException: Invalid name: jsmith at javax.naming.ldap.Rfc2253Parser.doParse(Rfc2253Parser.java:111) at javax.naming.ldap.Rfc2253Parser.parseDn(Rfc2253Parser.java:70) at javax.naming.ldap.LdapName.parse(LdapName.java:789) at javax.naming.ldap.LdapName.<init>(LdapName.java:125) at com.aveksa.gui.core.ACMLoginLogout.getLoginUserIdForAccount(ACMLoginLogout.java:745) ... 09/23/2016 15:19:52.585 WARN (default task-29) [com.aveksa.gui.core.ACMLoginLogout] No User mapped to this account. Its an Orphaned Account
Cause
A defect introduced in the product in the affected versions causes the authentication to incorrectly attempt to map the Identity Governance & Lifecycle user to the AD account using the distinguishedName attribute. The distinguishedName collected for the ADC will not map with the authentication source's user account and will always fail. The Test Authentication does a simple bind with the AD server and searches for the user with the UserSearchAttribute. The user account mapping does not play a role here, hence it passes.
Resolution
Workaround
Related Articles
Account Data Collectors (ADC) fail with ORA-00904: "RESOURCE_NAME": invalid identifier after upgrading RSA Identity Govern… 202Number of Views Identity Data Collector (IDC) collection fails with the error: "ORA-00918: column ambiguously defined" during the Identit… 239Number of Views Root (Server) and Client Certificates are RFC-5280 compliant starting in version 7.2.0 of RSA Identity Governance & Lifecycle 113Number of Views How to create a CA hierarchy where one subordinate CA uses SHA1 and another subordinate CA uses SHA2 while both sub CA's … 139Number of Views Authentication Sources 19Number of Views
Trending Articles
Troubleshooting RSA SecurID Access Identity Router to RSA Authentication Manager test connection failures RSA SecurID Software Token 5.0.2 Downloads for Microsoft Windows RSA Authentication Manager 8.9 Release Notes (January 2026) Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory RSA Authentication Manager 8.8 Setup and Configuration Guide
Don't see what you're looking for?