Cannot link the runtime identity source because no administrative identity sources reference this runtime source in RSA Authentication Manager
Originally Published: 2010-12-24
Article Number
Applies To
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 3.0, 7.1, 8.x
Issue
Cannot link the runtime identity source because no administrative identity sources reference this runtime source
Cause
Resolution
Authentication Manager 8.x
-
Create the identity source for the GC
- Launch the Authentication Manager Operations Console and from the Home tab, select Manage Identity Sources > Add New Identity Source.
- Create an identity source for the GC, defining the identity source basics and connection information.
- Click on the Map tab.
- Leave the User Base DN and User Group Base DN information blank.
- Check the option that the directory is an Active Directory Global Catalog.
- Complete the rest of the information on the page.
- Click Save and Finish.
-
Create the identity source for the DC
- Launch the Auth Manager Operations Console and from the Home tab, select Manage Identity Sources > Add New Identity Source.
- Create an identity source for the DC, defining the identity source basics and connection information using the same name and directory information as above.
- Click on the Map tab.
- Enter the User Base DN and User Group Base DN information. The User Base DN and User Group Base DN entries should be the same. To get all of your users, just enter top level of your domain such as dc=gizmo,dc=com. This information can be modified later.
- Uncheck the option that the directory is an Active Directory Global Catalog.
- For the User Authentication option, select the option that users authenticate to a GC and select the proper GC from the drop down list.
- Complete the rest of the information on the page.
- Click Save and Finish.
-
Link identity source to system
- From the Security Console, select Setup > Identity Sources > Link Identity Source to System.
- The available identity sources are listed on the left.
- Select the source(s) to be linked.
- Click the > button to move the source(s) to the Linked box.
- Click Save.
Authentication Manager 7.1 and RSA SecurID Appliance 3.0
-
Create the identity source for the GC
- Launch the Authentication Manager Operations Console and from the Home tab, select Manage Identity Sources > Add New Identity Source.
- Create an identity source for the GC, defining the identity source basics and connection information.
- Click on the Map tab.
- Leave the User Base DN and User Group Base DN information blank.
- Set the directory to read only.
- Check the option that the directory is an Active Directory Global Catalog.
- Leave the default user group type as Universal.
- Complete the rest of the information on the page.
- Click Save and Finish.
-
Create the identity source for the DC
- Launch the Auth Manager Operations Console and from the Home tab, select Manage Identity Sources > Add New Identity Source.
- Create an identity source for the DC, defining the identity source basics and connection information using the same name and directory information as above.
- Click on the Map tab.
- Enter the User Base DN and User Group Base DN information. The User Base DN and User Group Base DN entries should be the same. To get all of your users, just enter top level of your domain such as dc=gizmo,dc=com. This information can be modified later.
- Set the directory to read only.
- Uncheck the option that the directory is an Active Directory Global Catalog.
- For user authentication, define that users authenticate to a GC and select the GC from the drop down list.
- Complete the rest of the information on the page.
- Click Save and Finish.
-
Link identity source to realm
- From the Security Console, select Administration > Realms > Manage Existing.
- Click on the down arrow next to SystemDomain and choose Edit.
- The available identity sources are listed on the left.
- Select the source(s) to be linked.
- Click the > button to move the source(s) to the Linked box.
- Click Save.
Notes
Anecdotally, RSA support has found performance improvements with a GC when there are tens of thousands or hundreds of thousands of users authenticating. For smaller deployments, implementing a GC does not improve authentication speed to a significant degree.
Related Articles
How to troubleshoot RSA SecurID Access identity source errors 440Number of Views Unlink the identity source if it is linked to the system error when deleting an unlinked external identity source in RSA A… 537Number of Views How to map an Active Directory external identity source to a universal group for Authentication Manager 8.x 601Number of Views How to create an external identity source to Active Directory in RSA Authentication Manager 8.x 1.8KNumber of Views How to create an external LDAP identity source in RSA Authentication Manager 8.1 SP1 or later 1.57KNumber of Views
Trending Articles
An example of SSO using SAML and ADFS with RSA Identity Management and Governance 6.9.x RSA Authentication Manager 8.9 Release Notes (January 2026) RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide Passwordless Authentication in Windows MFA Agent for Active Directory – Quick Setup Guide RSA Authentication Manager Upgrade Process
Don't see what you're looking for?