RSA Identity Governance and Lifecycle Access Fulfillment Express (AFX) command output parameters do not work if the attribute name contains spaces
Originally Published: 2017-01-06
Article Number
Applies To
RSA Version/Condition: 7.0.0, 7.0.1
Issue
Steps to reproduce the issue
- Setup an Active Directory as a directory.
- Under Requests link any simple Account template with a pending parameter Name and choose Entitlements require an Account.
- Setup an AD AFX connector.
- Under Create Account capability, add a command output parameter to read the distinguishedName and map it to any attribute that has spaces in its name (for example: External ID):
- Now in the capability Add Account to Group, use the same attribute used above as the "Account" Parameter.
- Create a change request to add an AD Group to any user that does not yet have an AD account.
Expected behavior
- CR created with two items, create account then add group to account. Both items are fulfilled by AFX and then wait for verification
Actual behavior
- CR created with two items, create account then add group to account. Create account is successful, but Add group to account fails.
Cause
Resolution
Workaround
Access the RSA Identity Governance and LIfecycle portal. Go to Admin > Attributes and remove the space in the attribute name used in the AFX output parameter or use the parameter that doesn't contain any spaces.
An example of a scenario where attribute name has no space follows:
1. Choose another attribute that does not have any spaces in its name and use it as the output parameter (for example, DN).
- Create another similar CR. This time changes will be fulfilled as expected.
Related Articles
Account column missing under Available Columns in Review display view in RSA Identity Governance & Lifecycle 22Number of Views Unauthorized change rule triggered although change request for add access has passed approval phase in RSA Identity Govern… 50Number of Views WebService createChangeRequest command "Remove account to group" does not populate the user information in request tab in … 37Number of Views Compare User variable in request form is not working for user filters containing avform.user variables in RSA Identity Gov… 36Number of Views Security scope does not display report names associated with Aveksa Report Result entitlements in RSA Identity Governance … 44Number of Views
Don't see what you're looking for?