Previous Topic: Error Causes SSO Failure (74765, 80265)

Next Topic: Policy Server Does Not Check OCSP Responder Certificate Validation (76212, 80203)

Certificate-Only Authentication Schemes Fail with Custom Certificate Mapping (75552, 80266)

Symptom:

When you create a custom certificate mapping for an LDAP user directory, the resulting search query string includes the LDAP User DN Lookup Start and End strings in addition to the Mapping Expression that you specify on the Create Certificate Mapping pane. The resulting query is invalid and the search fails.

Solution:

You can exclude the DN Lookup Start and End strings from the search query string by setting the

\Netegrity\SiteMinder\CurrentVersion\PolicyServer\EnableCustomExprOnly

registry key as follows:

STAR Issue: 17360040-01