Hello

Identity Manager Roles Based Provisioning Module Version 4.0.2 Patch D
Build Revision 41026

LDAP Agent for NetIQ eDirectory 8.8 SP8 (20802.09)

I have some resources that were created with RMA and since they have
very long names in AD RMA created some resources with a trailing space
in the CN.

When we try to use the resource request activity we are getting errors
that it can't find the resource. If we rename it so it's named without a
trailing space it works, but it should work anyway since RMA created it.
And I'm not sure if it is supported to rename resources via LDAP.

This is what we see in the LDAP trace.
For some reason there are three \\\ in the query.

12:46:04 437D7700 LDAP: DoSearch on connection 0x801d070
12:46:04 437D7700 LDAP: Search request:
base:
"cn=ResourceDefs,cn=RoleConfig,cn=AppConfig,cn=UA, cn=DriverSet,o=System"
scope:2 dereference:0 sizelimit:0 timelimit:0 attrsonly:0
filter: "(&(objectClass=nrfResource))"
attribute: "nrfEntitlementRef"
attribute: "nrfLocalizedDescrs"
attribute: "nrfCategoryKey"
attribute: "nrfLocalizedNames"
attribute: "nrfResourceParms"
attribute: "srvprvHideUser"
attribute: "srvprvHideAttributes"
attribute: "modifyTimeStamp"
attribute: "objectClass"
12:46:04 437D7700 LDAP: nds_back_search: Search Control OID
2.16.840.1.113730.3.4.2
12:46:04 437D7700 LDAP: Sending search result entry "cn=CN_Admin XXXXXXX
YYYYYYYYY_OU_ZZZZZZZZZZZZZZ OOOOOOO_OU_UUUUUU\
,cn=ResourceDefs,cn=RoleConfig,cn=AppConfig,cn=UA, cn=DriverSet,o=System"
to connection 0x801d070
12:46:04 437D7700 LDAP: Sending search result entry "cn=cn=CN_Admin
XXXXXXX YYYYYYYYY_OU_ZZZZZZZZZZZZZZ OOOOOOO_OU_UUUUUU\ \
,cn=ResourceDefs,cn=RoleConfig,cn=AppConfig,cn=UA, cn=DriverSet,o=System"
to connection 0x801d070
12:46:04 437D7700 LDAP: Sending operation result 0:"":"" to connection
0x801d070
12:46:08 43CDC700 LDAP: DoSearch on connection 0x801b460
12:46:08 43CDC700 LDAP: Search request:
base: "cn=CN_Admin XXXXXXX YYYYYYYYY_OU_ZZZZZZZZZZZZZZ
OOOOOOO_OU_UUUUUU\\\
,cn=ResourceDefs,cn=RoleConfig,cn=AppConfig,cn=UA, cn=DriverSet,o=System"
scope:0 dereference:0 sizelimit:0 timelimit:0 attrsonly:0
filter: "(objectClass=*)"
attribute: "nrfApprovers"
attribute: "nrfRevokeQuorum"
attribute: "nrfCategoryKey"
attribute: "nrfAllowAprOveride"
attribute: "nrfRequestDef"
attribute: "nrfResourceParms"
attribute: "nrfRevokeApprovers"
attribute: "nrfQuorum"
attribute: "nrfRevokeRequestDef"
attribute: "nrfEntitlementRef"
attribute: "nrfLocalizedDescrs"
attribute: "nrfAllowMulti"
attribute: "owner"
attribute: "nrfLocalizedNames"
attribute: "nrfActive"
attribute: "srvprvHideUser"
attribute: "srvprvHideAttributes"
attribute: "modifyTimeStamp"
attribute: "objectClass"
12:46:08 43CDC700 LDAP: nds_back_search: Search Control OID
2.16.840.1.113730.3.4.2
12:46:08 43CDC700 LDAP: Cannot resolve NDS name 'CN=CN_Admin XXXXXXX
YYYYYYYYY_OU_ZZZZZZZZZZZZZZ OOOOOOO_OU_UUUUUU\
..CN=ResourceDefs.CN=RoleConfig.CN=AppConfig.CN=UA .CN=DriverSet.O=System'
in ResolveAndAuthNDSName, err = no such entry (-601)
12:46:08 43CDC700 LDAP: Base "cn=CN_Admin XXXXXXX
YYYYYYYYY_OU_ZZZZZZZZZZZZZZ OOOOOOO_OU_UUUUUU\\\
,cn=ResourceDefs,cn=RoleConfig,cn=AppConfig,cn=UA, cn=DriverSet,o=System"
not found, err = no such entry (-601)
12:46:08 43CDC700 LDAP: Sending operation result
32:"cn=ResourceDefs,cn=RoleConfig,cn=AppConfig,cn= UA,cn=DriverSet,o=System":"NDS
error: no such entry (-601)" to connection 0x801b460