PAM-CM-0620 Occurs During LDAP Refresh
search cancel

PAM-CM-0620 Occurs During LDAP Refresh

book

Article ID: 280749

calendar_today

Updated On:

Products

CA Privileged Access Manager (PAM)

Issue/Introduction

An LDAP synchronization or refresh fails with one of the following symptoms:

  • New users created in LDAP do not appear in PAM.
  • The PAM UI displays: PAM-CMN-0616: Refreshing LDAP groups completed with errors.
  • Session logs show: PAM-CMN-2262: PA User CN=AD_user... not updated. Error message: PAM-CM-0620: No data found for specified User.
  • Session logs show: PAM-CMN-2270: searchUser request for user@AD_example.com failed. Error message: PAM-CM-0620: No data found for specified User.

LDAP Authentication typically continues to work normally despite these refresh errors.

Environment

CA Privileged Access Manager (PAM)

Versions: 4.1.x, 4.2.x, 4.3.x

Cause

This issue occurs due to a backend database inconsistency where a user exists in the uag.user table but is missing from the cspm.admin table. This prevents the LDAP synchronization process from updating or deleting the affected user records.

Resolution

To resolve the database inconsistency in your current version:

  1. Open a case with Broadcom Support to request the PAM_USR_SYNC patch.
  2. Provide session logs and a logs.bin file (with LDAP Synchronization set to Verbose) to confirm the specific users affected.
  3. Apply the version-specific patch provided by Support:
    • For PAM 4.1.x: PAM_USR_SYNC_41X-.p.zip
    • For PAM 4.2.0: PAM_USR_SYNC_42.p.zip
    • For PAM 4.2.1 and higher: PAM_USR_SYNC.p.zip
  4. If the above does not resolve the problem, contact the Broadcom support team to review further.

Additional Information

It is recommended to subscribe to this article (see How to subscribe to Broadcom articles) to receive updates on fix status.