Resolution for LDAP Mismatched Suffix Error During Password Updates - CA Identity Manager
search cancel

Resolution for LDAP Mismatched Suffix Error During Password Updates - CA Identity Manager

book

Article ID: 204074

calendar_today

Updated On:

Products

CA Identity Manager CA Identity Suite

Issue/Introduction

Users attempting to update passwords in the Identity Manager environment may encounter an LDAP error code 1 indicating a mismatched suffix between the domain and a component in the Directory Information Tree (DIT).

This configuration conflict prevents successful user attribute updates and password synchronization between the application server and the provisioning server.

 

ERROR [com.netegrity.ims.events.ResetPasswordEvent] (Thread-19752 (HornetQ-client-global-threads-407012620)) execute(): Error in executing event due to endpoint offline: [facility=6 severity=3 reason=0 status=0 message=Wrapped Exception: javax.naming.NamingException: [LDAP: error code 1 - Domain 'im' has mismatched suffix 'dc=im' and component 'dc=test']; remaining name 'eTGlobalUserName=test001,eTGlobalUserContainerName=Global Users,eTNamespaceName=CommonObjects,dc=test,dc=eta']

etatrans.log shows:

Search    :E506:----:F: FAILURE: External Search (eTGlobalUserName=test001)
Search    :E506:----:F:     rc:  0x0001 (Operations error)
Search    :E506:----:F:     msg: Domain 'im' has mismatched suffix 'dc=im' and component 'dc=test'

Selecting the Provisioning Roles tab in Modify or View User on IM User Console shows the following error:

javax.servlet.ServletException: [facility=6 severity=3 reason=0 status=12 message=A JIAM operation failed..]
javax.naming.NamingException: [LDAP: error code 1 - Domain 'im' has mismatched suffix 'dc=im' and component 'dc=test']; remaining name ...

 

Environment

Identity Manager 14.x

Cause

The Directory Information Tree (DIT) contains an invalid or incorrect domain name component (for example, dc=test) within the user container path. This configuration mismatch prevents the provisioning engine from successfully locating the user object during password operations.

Resolution

  1. Connect to your Provisioning Directory using an LDAP browser tool, such as JXplorer.
  2. Navigate the Directory Information Tree (DIT) to identify the incorrect domain component referenced in the error message (e.g., dc=test).
  3. Right-click the incorrect domain object and select Delete to remove it from the tree.
  4. Restart the Provisioning Server service to ensure the directory cache refreshes and recognizes the configuration change.
  5. Verify the resolution by attempting the password change operation again in the Identity Manager User Console.

Additional Information

To speak with a customer representative or a Support Engineer see Contact Support. Scroll to the bottom of the page and click on your respective region.