SAP Endpoint Fails with Lowercase Password Policy Error
search cancel

SAP Endpoint Fails with Lowercase Password Policy Error

book

Article ID: 437900

calendar_today

Updated On:

Products

CA Identity Suite

Issue/Introduction

When creating or managing SAP accounts in Identity Manager (IDM), the system returns an error despite the password containing lowercase characters. The error typically states:

The password must contain at least 1 lowercase characters (a-z)

Logs show that the SAP function call BAPI_USER_CREATE1 fails with error type "E". This indicates that the password is being converted to uppercase before reaching the SAP endpoint, causing it to violate SAP's case-sensitive password policy.

Environment

Product: Symantec Identity Governance and Administration (IGA)
Version: 15.0.x
Endpoint: SAP R3 / ERP
OS: Red Hat Enterprise Linux (RHEL)

Cause

A product defect in Identity Manager 15.0 causes the connector to treat password fields as case-insensitive or hardcode them to uppercase during transmission, even when the SAP system is configured for case-sensitive passwords (version 7.00 and above).

Resolution

The fix is scheduled for inclusion in Identity Suite 15.0 Fix Pack 6.

After applying the Fix Pack also need to add the SAP endpoint type to the IMCS Connector Server Configuration via the Endpoints tab This will enable the SAP-related configurations located under the Other tab as mentioned in the Product Doc for configuring the Convert Password To UpperCase property.

Additional Information

For the latest updates and download information, refer to the Identity Suite 15.0 Release Notes