RSA Identity Governance and Lifecycle Access Fulfillment Express (AFX) command output parameters do not work if the attribute name contains spaces
Originally Published: 2017-01-06
Article Number
Applies To
RSA Version/Condition: 7.0.0, 7.0.1
Issue
Steps to reproduce the issue
- Setup an Active Directory as a directory.
- Under Requests link any simple Account template with a pending parameter Name and choose Entitlements require an Account.
- Setup an AD AFX connector.
- Under Create Account capability, add a command output parameter to read the distinguishedName and map it to any attribute that has spaces in its name (for example: External ID):
- Now in the capability Add Account to Group, use the same attribute used above as the "Account" Parameter.
- Create a change request to add an AD Group to any user that does not yet have an AD account.
Expected behavior
- CR created with two items, create account then add group to account. Both items are fulfilled by AFX and then wait for verification
Actual behavior
- CR created with two items, create account then add group to account. Create account is successful, but Add group to account fails.
Cause
Resolution
Workaround
Access the RSA Identity Governance and LIfecycle portal. Go to Admin > Attributes and remove the space in the attribute name used in the AFX output parameter or use the parameter that doesn't contain any spaces.
An example of a scenario where attribute name has no space follows:
1. Choose another attribute that does not have any spaces in its name and use it as the output parameter (for example, DN).
- Create another similar CR. This time changes will be fulfilled as expected.
Related Articles
Validation URI JSP files do not work when uploaded to the secured JSP Pages section in RSA Identity Governance & Lifecycle 191Number of Views The display names of the 'Contains Privilege Access' and 'Business Criticality' attributes fail to change after they have … 61Number of Views DB2 Access Fulfillment Express (AFX) connector template has limited connector capabilities in RSA Identity Governance & Li… 54Number of Views Assign a User Alias to a RADIUS Profile 27Number of Views On systems where the BINDING_ATTR value has been changed should the USERID_ATTR value also be changed? 8Number of Views
Trending Articles
Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory RSA Authentication Manager 8.9 Release Notes (January 2026) Artifacts to gather in RSA Identity Governance & Lifecycle RSA Governance & Lifecycle 8.0.0 Administrators Guide RSA Governance & Lifecycle 8.0.0 Installation Guide
Don't see what you're looking for?