When integrating CA Identity Manager (IAM) with CA Privileged Access Manager (PAM), the PAM user account creation may fail even if the associated Active Directory (AD) account is created successfully. This issue is typically characterized by the following error reported in the Provisioning Manager:
ETA_E_0016, Account for Global User 'x' on Endpoint 'CA PAM' creation failed: :ETA_E_0004, Account 'DS' on 'CA PAM' creation failed: Connector Server Add failed: code 53 (UNWILLING_TO_PERFORM)... PAM: peer not authenticated
This article provides steps to resolve this failure, which is often caused by certificate mismatches during the secure handshake.
Identity Manager 14.x & 15
The error "PAM: peer not authenticated" often occurs because the "PAM Server" attribute in the Identity Manager endpoint configuration does not match the Subject Alternative Name (SAN) defined in the certificate presented by the PAM server. The connection is rejected by the connector because the certificate identity cannot be verified against the configured endpoint address.
To resolve this integration failure, perform the following verification steps: