RSA Identity Governance and Lifecycle Access Fulfillment Express (AFX) AD connector does not accept more than 26 parameters
Originally Published: 2016-11-24
Last Modified: 2023-09-22
Article Number
Applies To
RSA Version/Condition: 6.9.1+
Issue
In the UI, the following message is seen:
LDAPException: Server refused to perform migration. Password does not meet complexity requirements
The detail provided is as follows:
Error: LDAPException: Unwilling To Perform (53) Unwilling To Perform LDAPException: Server Message: 0000052D: SvcErr: DSID-031A12D2, problem
5003 (WILL_NOT_PERFORM), data 0 LDAPException: Matched DN:
******************************************************************************** Message : Failed to route event via endpoint:
DefaultOutboundEndpoint{endpointUri=ldapx://AD-Test-OU-Connector.LDAP, connector=LdapxConnector { name=AD-Test-OU-Connector.LDAP.connector
lifecycle=start this=3993db98 numberOfConcurrentTransactedReceivers=4 createMultipleTransactedReceivers=true connected=true
supportedProtocols=[ldapx] serviceOverrides= } , name='endpoint.ldapx.AD.Test.OU.Connector.LDAP', mep=REQUEST_RESPONSE, properties={},
transactionConfig=Transaction{factory=null, action=INDIFFERENT, timeout=0}, deleteUnacceptedMessages=false, initialState=started,
responseTimeout=10000, endpointEncoding=UTF-8, disableTransportTransformer=false}. Message payload is of type: LDAPModifyRequest Code :
MULE_ERROR-42999 -------------------------------------------------------------------------------- Exception stack is: 1. Unwilling To Perform
(com.novell.ldap.LDAPException) com.novell.ldap.LDAPResponse:-1 (null) 2. Failed to route event via endpoint:
DefaultOutboundEndpoint{endpointUri=ldapx://AD-Test-OU-Connector.LDAP, connector=LdapxConnector { name=AD-Test-OU-Connector.LDAP.connector
lifecycle=start this=3993db98 numberOfConcurrentTransactedReceivers=4 createMultipleTransactedReceivers=true connected=true
supportedProtocols=[ldapx] serviceOverrides= } , name='endpoint.ldapx.AD.Test.OU.Connector.LDAP', mep=REQUEST_RESPONSE, properties={},
transactionConfig=Transaction{factory=null, action=INDIFFERENT, timeout=0}, deleteUnacceptedMessages=false, initialState=started,
responseTimeout=10000, endpointEncoding=UTF-8, disableTransportTransformer=false}. Message payload is of type: LDAPModifyRequest
(org.mule.api.transport.DispatchException) org.mule.transport.AbstractMessageDispatcher:109 (http://www.mulesoft.org/docs/site/current3/apidocs/org/mule/api/transport/DispatchException.html)
-------------------------------------------------------------------------------- Root Exception stack trace: LDAPException:
Unwilling To Perform (53) Unwilling To Perform LDAPException: Server Message: 0000052D: SvcErr: DSID-031A12D2,
problem 5003 (WILL_NOT_PERFORM), data 0 LDAPException: Matched DN: at com.novell.ldap.LDAPResponse.getResultException(Unknown Source)
at com.novell.ldap.LDAPResponse.chkResultCode(Unknown Source) at com.novell.ldap.LDAPConnection.chkResultCode(Unknown Source) + 3 more
(set debug level logging or '-Dmule.verbose.exceptions=true' for everything) ********************************************************************************Cause
Resolution
Workaround
- Edit the CreateAccount capability. In the userAccountControl the current value is 512, replace it with NORMAL_ACCOUNT (standard string constant) and add an additional flag of PASSWD_NOTREQD. In doing this, the final value to be provided should be NORMAL_ACCOUNT,PASSWD_NOTREQD.
- Save these settings and execute the command.
Related Articles
How to install Access Fulfillment Express (AFX) for use with RSA Identity Governance & Lifecycle 1.3KNumber of Views RSA Identity Governance and Lifecycle Access Fulfillment Express (AFX) command output parameters do not work if the attrib… 278Number of Views Troubleshooting AFX Connector issues in RSA Identity Governance & Lifecycle 1.33KNumber of Views RSA Identity Governance & Lifecycle Access Fulfillment Express (AFX) Change Requests that depend on Entitlements Require A… 410Number of Views Access Fulfillment Express (AFX) AD LDAP connector fails to remove AD account with error "Not Allowed On Non-leaf" in RSA … 189Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Manual synchronization introduced in RSA Authentication Manager 8.2 Service Pack 1 patch 6 Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory How to verify NTP server synchronization is not working in RSA Authentication Manager 8.x RSA Governance & Lifecycle 8.0.0 Installation Guide
Don't see what you're looking for?