An LDAP synchronization or refresh fails with one of the following symptoms:
PAM-CMN-0616: Refreshing LDAP groups completed with errors.PAM-CMN-2262: PA User CN=AD_user... not updated. Error message: PAM-CM-0620: No data found for specified User.PAM-CMN-2270: searchUser request for user@AD_example.com failed. Error message: PAM-CM-0620: No data found for specified User.LDAP Authentication typically continues to work normally despite these refresh errors.
CA Privileged Access Manager (PAM)
Versions: 4.1.x, 4.2.x, 4.3.x
This issue occurs due to a backend database inconsistency where a user exists in the uag.user table but is missing from the cspm.admin table. This prevents the LDAP synchronization process from updating or deleting the affected user records.
To resolve the database inconsistency in your current version:
PAM_USR_SYNC patch.logs.bin file (with LDAP Synchronization set to Verbose) to confirm the specific users affected.PAM_USR_SYNC_41X-.p.zipPAM_USR_SYNC_42.p.zipPAM_USR_SYNC.p.zipIt is recommended to subscribe to this article (see How to subscribe to Broadcom articles) to receive updates on fix status.