Previous Topic: Remove the Trusted Members of a Trusted GroupNext Topic: Salesforce.com Connector


Known Issues

This section contains the following known issues for the RSA SecurID 7 Connector.

More information:

Non-English Character Support for RADIUS Profiles

Properties of RADIUS Profile Created with Japanese Characters

RADIUS Profiles with French Characters

Trusted Groups with More than 25 French or Japanese Characters

Attempting to Create a Security Domain Above the Top Level Security Domain Fails

RADIUS Profiles with Japanese Characters

Connector Data Migration Fails in Interactive Mode

Non-English Character Support for RADIUS Profiles

The RSA 7 connector does not support non-English characters for RADIUS Profiles. The following are known issues with non-English character support:

RADIUS Profiles with Japanese Characters

If you try to delete a RADIUS profile on an RSA7 server using CA Identity Manager Provisioning Manager in a Japanese environment, the delete operation appears to remove the profile in the Provisioning Server. However, when you look at the RSA Server, the RSA Profile is not deleted from the endpoint.

Properties of RADIUS Profile Created with Japanese Characters

When you create a RADIUS profile in CA Identity Manager Provisioning Manager using Japanese characters, the profile creation is successful. However you cannot display the property window of the profile after it has been created.

However, the profile is created correctly on the endpoint, and you can view and edit it using the RSA console.

RADIUS Profiles with French Characters

If you create one RADIUS profile with French characters using CA Identity Manager Provisioning Manager on an endpoint that does not contain RADIUS profiles with French characters (such as 'àçèéù) two profiles are created on the Endpoint

One profile is correct, however the second profile created contains invalid characters.

In addition, you cannot display properties of RADIUS profiles created with French characters.

Trusted Groups with More than 25 French or Japanese Characters

The character limit for trusted group name is 50. However, due to the byte limit, you can only enter 25 French or Japanese characters. You can enter a maximum of 16 Kanji characters for a trusted group using CA Identity Manager Provisioning Manager. The number of Japanese or French characters that you can enter in a particular field can be less than the number of English language characters that you can enter in the same field in the Provisioning Manager.

Attempting to Create a Security Domain Above the Top Level Security Domain Fails

When you select the top-level of the endpoint in the container tree on the Endpoint Content dialog, the New button on the Endpoint Content dialog is displayed as available. However when you attempt to create a security domain, the creation fails because you cannot create a security domain above the top-level security domain. The New button on the Endpoint Content dialog is incorrectly displayed as available.

Connector Data Migration Fails in Interactive Mode

If you run the RSA7Migrate utility in Mode 2 (create a template even if errors found, but do not associate it with a namespace) reconcile the templates and their missing objects before you use the templates. If you run the RSA7Migrate utility before you reconcile the templates and their missing objects, the migration utility fails.

Assigning a Provisioning Role to a Global User to Create an RSA Trusted User Account Fails

Valid on Windows and Solaris

Symptom:

When I assign a Provisioning Role to a global user to create an RSA trusted use in CA Identity Manager, the account creation fails.

Solution:

The account creation fails because the account template contains the default rule strings %P%, %UL% and %XD% that are not required for an RSA trusted user.

When you first create the template and delete the rule strings that are not required, the rule strings reappear when you assign the template.

When you create a template for an RSA trusted user, do the following.

  1. Create the template using the default rule strings and click Submit.
  2. Modify the account template, and delete the %P%, %XD% rule strings from the Password and Start Date fields on the Account tab.
  3. Delete the rule string %UL% from the Start Date field on the User tab.
  4. Submit the template.
  5. Assign the provisioning role to the global user again.