Symptom:
When you create a custom certificate mapping for an LDAP user directory, the resulting search query string includes the LDAP User DN Lookup Start and End strings in addition to the Mapping Expression that you specify on the Create Certificate Mapping pane. The resulting query is invalid and the search fails.
Solution:
You can exclude the DN Lookup Start and End strings from the search query string by setting the
\Netegrity\SiteMinder\CurrentVersion\PolicyServer\EnableCustomExprOnly
registry key as follows:
Excludes the DN Lookup Start and End strings from the search query string.
Includes the DN Lookup Start and End strings in the search query string.
STAR Issue: 17360040-01
Copyright © 2010 CA. All rights reserved. | Email CA about this topic |