Unknown cause error and size limit exceeded error when synchronizing LDAPv3 identity source with RSA SecurID Access Cloud Authentication Service
Originally Published: 2020-05-11
Article Number
Applies To
RSA Product/Service Type: Identity Router, Cloud
Issue
In the RSA Cloud Administration Console, the following symptoms are observed:
- Synchronization status reports that Synchronization failed with the reason Unknown cause.
- The System Event Monitor contains an Identity Source Sync event code 2507 with:
Description: Identity source synchronization not completed successfully
Details: Unknown cause
Details: Unknown cause
- The System Log of one of the Identity Routers contains an LDAP error event similar to the following:
ERROR com.rsa.aae.internal.ldap.sync.LDAPSearchExecutor[71] - failed to read data from LDAP
LDAPException(resultCode=4 (size limit exceeded), numEntries=500, numReferences=0, errorMessage='size limit exceeded', ldapSDKVersion=4.0.6, revision=27850')
at com.unboundid.ldap.sdk.LDAPConnection.search(LDAPConnection.java:3734)
Cause
- The Root and User Search Filter configured for your identity source returns more users than the maximum number of records allowed by your LDAPv3 directory server in one search query result. The maximum number is 500.
- The Simple Paged Results control is either not enabled in your LDAPv3 directory server, or is not supported by it.
Resolution
Workaround
One option to workaround this limitation is to use limited synchronization methods:
- Scheduled Synchronization should be disabled and Manual Synchronization should not be used, as both fail.
- Just-In-Time Synchronization must be enabled under Company Settings. It is disabled by default. When enabled, Just-In-Time Synchronization applies to all identity sources configured in your RSA Cloud Authentication Service.
- Ongoing, only Just-In-Time Synchronization and Single-User Synchronization can be used to synchronize users in the identity source.
- Use multiple identity source configurations, each with a Root and User Search Filter chosen to represent a different, smaller subset of users. The number of users who are returned for each identity source must always be less than the maximum that your LDAPv3 directory server returns in one search query result (usually 500). Ensure that there is no overlap between subsets (that is, a user does not occur in more than one identity source) and no required users are omitted.
- Copy user records from your existing directory server to a new LDAPv3 directory server that does support and have enabled the Simple Paged Results control, or to Microsoft Active Directory.
Related Articles
When adding User Attributes in RSA Identity Governance and Lifecycle 7.1.0 the following error appear: The number of param… 14Number of Views Error message "GC overhead limit exceeded" in RSA IMG 6.8.1 88Number of Views What happens when you exceed the maximum number of email recipients limits on email provider 3Number of Views How to set up warnings/notifications about license limit or user limit expiry in RSA Mobile 27Number of Views 'UT000047: The number of parameters exceeded the maximum of 1000' error when adding User Attributes in RSA Identity Govern… 164Number of Views
Trending Articles
RSA Authentication Manager 8.9 Release Notes (January 2026) RSA announces the availability of the RSA SecurID Hardware Appliance 230 based on the Dell PowerEdge R240 Server How to troubleshoot Oracle database ORA-04030 errors in RSA Identity Governance & Lifecycle RSA Authentication Manager Upgrade Process Microsoft SQL Server Collectors can no longer connect to the SQL Server database after upgrade to Microsoft SQL Server 201…
Don't see what you're looking for?