Federated Identity Management Module 2.5
Federated Identity Management Module 2.6
ctUidX509RdnAttribute
In FIM's debug log the following exception appears:
2007-03-29 15:17:02,944 - exception: com.rsa.csf.techservice.saml.plugins.SubjectMapperPluginException: local user name attribute value not found in X.509 name: CN=first.last,OU=webusers,DC=test,DC=org
at com.rsa.csf.techservice.saml.plugins.CtX509SubjectMapperPluginRP.mapSamlToLocalSubject(Lcom/rsa/csf/techservice/saml/opensaml/SAMLSubject;Ljava/util/Map;)Lcom/rsa/csf/techservice/saml/opensaml/SAMLSubject;(Unknown Source)
at com.rsa.csf.techservice.saml.common.SamlAssertionProcessor.mapSAMLSubject2LocalSubject(Lcom/rsa/csf/techservice/saml/opensaml/SAMLSubject;Lcom/rsa/csf/domain/objects/RPAssertingParty;)Lcom/rsa/csf/techservice/saml/opensaml/SAMLSubject;(Unknown Source)
A misconfiguration of the "" plugin attribute is the likely cause for this exception.
In order to correct this issue:
Identify the affected plugin. As you can see, the exception in raised within the class highlighted in red in the above section.
That class is used (by default) by the plugin "RSA_ClearTrust_X.509_Subject_Plug-in_RP", as you can see from "Class Name" field in FIM's management GUI (Configure System -> Plugins -> Manage Existing, look at the "Class Name" field for all plugins until you have a match).
Verify that in the Plug-In configuration screen the value of the "ctUidX509RdnAttribute" attribute is set correctly. By default this attribute is set to "uid". For the subject line
CN=first.last,OU=webusers,DC=test,DC=org
to be correctly parsed this would need to be changed to "CN".
Related Articles
Cloud Administration Update Local User API 6Number of Views Cloud Administration Create Local User API 10Number of Views RSA MFA Agent 2.4 for Windows and later fails to authenticate local users who are managed on devices participating in Micr… 151Number of Views Local entitlements belonging to roles are not consistently added to users in RSA Identity Governance & Lifecycle 40Number of Views Windows Share is not accessible from local users after upgrading to 8.5 263Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Reporting on RSA Authentication Manager 8.x users with On-Demand Token, a fixed passcode or a hardware/software token assi… How to Download OTP Token Seed Files from myRSA Anomalix idGenius - SAML Relying Party Configuration - RSA Ready Implementation Guide RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide