When resetting an out of band (OOB) account password, Access Fulfillment Express (AFX) will always look for full DN to search accounts in RSA Identity Governance and Lifecycle
Originally Published: 2016-05-27
Article Number
Applies To
RSA Product/Service Type: All
Issue
AFX reports this item failed with code [-1] and message: 'org.mule.api.transformer.TransformerMessagingException:
Search for attributes for CN=jdoe,OU=Test_User,DC=2k8r2-vcloud,DC=local returned empty. The entry may not exist.
Aborting request! (java.lang.IllegalArgumentException) (org.mule.api.transformer.TransformerException).
Message payload is of type: String'. If available, another handler will be used to fulfill this item.
Below error seen in comment box :
Cause
The DN for the test user John Doe is CN= John Doe ,OU=Test_User,DC=2k8r2-vcloud,DC=local. If the account is a sAMAccountName (e. g., jdoe) then AFX tries to search the DN as CN=jdoe,OU=Test_User,DC=2k8r2-vcloud,DC=local. Since it does not find this DN in Active directory, it displays the error.
Resolution
The connector will always try to look up an account or group using the DN.
This doesn't mean that you need to collect accounts with Account ID set to DN. What it does mean is that you need to collect either the account CN or DN as an attribute and map that attribute to the account parameter on the Reset an Account's Password tab and for any other account-related command EXCEPT for Create Account. It is most likely that not all of your accounts are in the same OU, so you would want to collect and map the full DN to the account parameter.
If, however, all the accounts are in the same OU structure and the CN is made up of attributes from associated user object(s), then the account parameter for the Reset Password command can be mapped to those user attributes. An example of this would be if your CN looks like CN = $User.First_Name $User.Last_Name. For the account parameter to Reset an Account's Password in the connector, the attribute mapping would look like $User.First_Name $User.Last_Name.
Related Articles
Java client looks for a new key when requested stale key is in the cache 20Number of Views RSA Authenticator 4.3 for iOS and Android Coming in August 2023 with New Look and More 32Number of Views A user sees an empty screen when looking at review items in RSA Identity Governance & Lifecycle 18Number of Views In RSA Identity Governance & Lifecycle, when a user looks at a role in a role review that is on hold and presses OK instea… 19Number of Views SA Looking for Live Manager Thick client in order to down load packages for off external Network SA Servers 7Number of Views
Trending Articles
RSA Authentication Manager Upgrade Process RSA Release Notes for RSA Authentication Manager 8.8 RSA RADIUS Server service failed to start in the RSA Authentication Manager 8.1 Operations Console Microsoft Entra ID External MFA - Relying Party Configuration Using OIDC - RSA Ready Implementation Guide RSA Release Notes: Cloud Access Service and RSA Authenticators
Don't see what you're looking for?