Error [sm-xobsm-00320] and BlobAttribute in XPSsweeper
search cancel

Error [sm-xobsm-00320] and BlobAttribute in XPSsweeper

book

Article ID: 282002

calendar_today

Updated On:

Products

SITEMINDER

Issue/Introduction

Running XPSsweeper -a against a policy store, the utility reports the following error

[XPSSweeper - XPS Version 12.8.0700.2758]
Log output:<SM_HOME>/log/XPSSweeper.<YYYY-MM-DD_HHMMSS>.log
Initializing XPS, please wait...
Starting Integrity Analysis.

START ERROR REPORT*****************************************************


Integrity Errors: 1 errors detected

1) [sm-xobsm-00320] BlobAttribute="CA.SM::UserDirectory@XX-XXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX(<Directory name>)" should have BlobAttribute.
Object ID: CA.SM::PasswordPolicy@YY-YYYYYYYY-YYYY-YYYYYYYY-YYYYYYYYYYYY
Object Name: <ObjectName>
Object Path: PasswordPolicy[<ObjectName>]
Object Description:
Fix Information: Automatic fix currently not available.

What is this error and how can it be corrected ?

Environment

CA SiteMinder all versions

Cause

This error will occur when the directory <Directory name> to which Password Policy <ObjectName> is linked does not have the password data attribute defined

As per

https://techdocs.broadcom.com/us/en/symantec-security-software/identity-security/siteminder/12-8/configuring/policy-server-configuration/user-directories/directory-attributes-overview.html

each user directory needs to have a password data attribute defined which is used to track password policy information. If this is missing the password policy will have a problem working, so XPSSweeper is reporting an error

Resolution

One possible way is to delete the Password Policy mentioned and try to recreate it, if it is not being used. Likely it is not because otherwise it would be malfunctioning

It is also important to verify if the User Directory mentioned does have the Password Data attribute defined. To find out if this is so access SiteMinder GUI and navigate to User Directories, then edit the <Directory Name> mentioned in the message and see if a Password Data attribute is defined pointing to a specific attribute in the directory and correct it if wrong.

If none of these works please contact Broadcom Support for help