Previous Topic: Connector Data Migration Fails in Interactive ModeNext Topic: Salesforce.com Connector


Assigning a Provisioning Role to a Global User to Create an RSA Trusted User Account Fails

Valid on Windows and Solaris

Symptom:

When I assign a Provisioning Role to a global user to create an RSA trusted use in CA IdentityMinder, the account creation fails.

Solution:

The account creation fails because the account template contains the default rule strings %P%, %UL% and %XD% that are not required for an RSA trusted user.

When you first create the template and delete the rule strings that are not required, the rule strings reappear when you assign the template.

When you create a template for an RSA trusted user, do the following.

  1. Create the template using the default rule strings and click Submit.
  2. Modify the account template, and delete the %P%, %XD% rule strings from the Password and Start Date fields on the Account tab.
  3. Delete the rule string %UL% from the Start Date field on the User tab.
  4. Submit the template.
  5. Assign the provisioning role to the global user again.