Previous Topic: All Accounts are Imported, Regardless of Filtering

Next Topic: Salesforce.com Connector

Assigning a Provisioning Role to a Global User to Create an RSA Trusted User Account Fails

Valid on Windows and Solaris

Symptom:

When I assign a Provisioning Role to a global user to create an RSA trusted use in CA Identity Manager, the account creation fails.

Solution:

The account creation fails because the account template contains the default rule strings %P%, %UL% and %XD% that are not required for an RSA trusted user.

When you first create the template and delete the rule strings that are not required, the rule strings reappear when you assign the template.

When you create a template for an RSA trusted user, do the following.

  1. Create the template using the default rule strings and click Submit.
  2. Modify the account template, and delete the %P%, %XD% rule strings from the Password and Start Date fields on the Account tab.
  3. Delete the rule string %UL% from the Start Date field on the User tab.
  4. Submit the template.
  5. Assign the provisioning role to the global user again.