Password dictionary file browsing and upload options unavailable in IM Password Policy when integrated with SiteMinder SSO - Identity Manager
search cancel

Password dictionary file browsing and upload options unavailable in IM Password Policy when integrated with SiteMinder SSO - Identity Manager

book

Article ID: 206800

calendar_today

Updated On:

Products

CA Identity Manager CA Identity Suite SITEMINDER

Issue/Introduction

When Identity Manager (IM) is integrated with SiteMinder SSO, the Password Policy configuration interface changes. This environment expects dictionary files to be managed and stored on the Policy Server rather than within the Identity Manager Object Store.

This article addresses why the "Browse" and "Upload" options for dictionary files are unavailable in the Identity Manager Administrative UI and explains how to configure these policies correctly in an integrated environment.

Environment

Identity Manager 14.x

Siteminder 12.8

Cause

In an integrated SiteMinder SSO and Identity Manager environment, the Policy Server assumes responsibility for password policy enforcement. Consequently, the Identity Manager interface redirects dictionary file management to the Policy Server file system, disabling local file uploads within the IM Administrative UI.

Resolution

To apply or update a dictionary file for password policies, you must perform the configuration directly on the Policy Server:

  1. Obtain the dictionary file (note: Broadcom does not provide dictionary files; standard English-word lists are available through external open-source repositories).
  2. Manually copy the dictionary file to the file system of the Policy Server.
  3. If your environment utilizes a cluster, ensure the dictionary file is placed on all Policy Servers in the cluster.
  4. Log into the SiteMinder/SSO Web Admin UI.
  5. Navigate to the Password Policy restrictions tab and specify the file path to the dictionary file located on the Policy Server.
  6. For technical assistance, refer to the SiteMinder SSO Documentation.

Additional Information

To speak with a customer representative or a Support Engineer see Contact Support. Scroll to the bottom of the page and click on your respective region.