Running a form incorrectly filters on raw name when filtering on the Application Name attribute in RSA Identity Governance & Lifecycle
Originally Published: 2018-11-08
Last Modified: 2023-09-25
Article Number
Applies To
RSA Version/Condition: 7.0.1, 7.0.2, 7.1.0
Issue
Steps to Reproduce
- Navigate to Resources > Directories.
- Select any directory. Active Directory is being used in he example below.
- Select General > Edit.
- Change Directory Raw Name to Active Directory Raw Name.
- Click OK.
- After saving the changes, note that the Directory name is changed to the Directory Raw Name.
- Edit the directory again and change the Directory name back to what it was. In this case, Active Directory.
- Note the entry in T_APPLICATIONS
- Verify that NAME (Directory Raw name, also the application name) and ALT_NAME are different.
- Go to Requests > Configuration > Request Forms > Default Password Form > Fields and click Edit next to the Account variable name.
- Click on the Account filter.
- From the drop down options choose Application Name, one of, and Active Directory Raw Name then click OK.
- Verify the information is correct in the Modify Question: Account page.
- Refresh and note that no accounts show under Select account because you have no applications with a display or alt_name of Active Directory Raw Name. This is expected.
- Click Cancel.
- Find a user with an account in Resources > Directories > Active Directory > Accounts.
- Run the form and choose the AD user (Requests > Configuration > Request Forms > Default Password Form > Fields > Run Form).
Expected Behavior
There is no Active Directory showing under Application Name because there is no Application Name called Active Directory Raw Name, which is the filter. Active Directory Raw Name is the Business Source Raw Name. This would also be consistent with the behavior in step 6.
Observed Behavior
The Active Directory directory is displayed on the form. Note when editing the form field, accounts in this directory were not shown. Now they get shown because the filter is now filtering on the alt_name field. So when you edit the field, it filters on name and when you run the form, it filters on alt_name. So when you design a form it acts one way and when you run the form it acts another way. You cannot trust your design as a result.
Resolution
Workaround
Related Articles
Cannot access RSA SecurID Access protected SAML application due to incorrectly specified Identity Provider URL 121Number of Views Unification slow and identity collections show users in reprocessed state in RSA Identity Governance & Lifecycle 72Number of Views RSA Authentication Agent for Microsoft Windows Is Not Authenticating Against the Correct Contact List 47Number of Views Incorrect setting for Oracle PARALLEL_DEGREE_POLICY causes issue in RSA Identity Governance & Lifecycle 85Number of Views AFX Server is in a 'Not running' State in the user interface but 'afx status' indicates AFX is running in RSA Identity Gov… 376Number of Views
Trending Articles
Artifacts to gather in RSA Identity Governance & Lifecycle How to Update the Root (Server) and Client Certificates in RSA Identity Governance & Lifecycle How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Troubleshooting AFX Connector issues in RSA Identity Governance & Lifecycle How to Download and Reinstall the AFX Server Archive in RSA Governance & Lifecycle
Don't see what you're looking for?