Error: findUsersInScope: Exception doing scoped search - Invalid DN string - Identity Manager
search cancel

Error: findUsersInScope: Exception doing scoped search - Invalid DN string - Identity Manager

book

Article ID: 94801

calendar_today

Updated On:

Products

CA Identity Manager CA Identity Suite

Issue/Introduction

This article describes the resolution for the "Invalid DN string" error encountered during search tasks in Identity Manager, typically caused by misconfigured search scopes or invalid Organizational Unit (OU) pathing in admin roles.

Environment

Identity Manager 14.5

Cause

The error is triggered when the Identity Manager task's search configuration or an assigned Admin Role's membership/scope rule includes an incorrect Distinguished Name (DN) path. Specifically, duplicate or malformed OU entries within the directory structure (e.g., OU=PrePROD,OU=PrePROD) prevent the system from resolving the object.

Resolution

  1. Identify the Affected Task: Open the Identity Manager console and navigate to the task reporting the error (e.g., Modify Admin Task > Modify User > Search Tab).
  2. Review Search Configurations: Within the Search tab, verify the default search configuration for both User and Organization searches.
  3. Verify Scope Rules: Click Role Use to identify which Admin Roles are assigned to the task.
  4. Correct Admin Role Configuration: Navigate to Modify Admin Roles for the identified roles. Check the membership and scope rules.
  5. Remove Invalid DNs: Locate the incorrect DN path (such as the duplicate OU noted in the error log) and remove it from the role membership/scope rule definition.
  6. Save and Test: Save the changes and re-run the task to verify that the search completes successfully.

Additional Information

To speak with a customer representative or a Support Engineer see Contact Support. Scroll to the bottom of the page and click on your respective region.