Unknown cause error and size limit exceeded error when synchronizing LDAPv3 identity source with RSA SecurID Access Cloud Authentication Service
Originally Published: 2020-05-11
Article Number
Applies To
RSA Product/Service Type: Identity Router, Cloud
Issue
In the RSA Cloud Administration Console, the following symptoms are observed:
- Synchronization status reports that Synchronization failed with the reason Unknown cause.
- The System Event Monitor contains an Identity Source Sync event code 2507 with:
Description: Identity source synchronization not completed successfully
Details: Unknown cause
Details: Unknown cause
- The System Log of one of the Identity Routers contains an LDAP error event similar to the following:
ERROR com.rsa.aae.internal.ldap.sync.LDAPSearchExecutor[71] - failed to read data from LDAP
LDAPException(resultCode=4 (size limit exceeded), numEntries=500, numReferences=0, errorMessage='size limit exceeded', ldapSDKVersion=4.0.6, revision=27850')
at com.unboundid.ldap.sdk.LDAPConnection.search(LDAPConnection.java:3734)
Cause
- The Root and User Search Filter configured for your identity source returns more users than the maximum number of records allowed by your LDAPv3 directory server in one search query result. The maximum number is 500.
- The Simple Paged Results control is either not enabled in your LDAPv3 directory server, or is not supported by it.
Resolution
Workaround
One option to workaround this limitation is to use limited synchronization methods:
- Scheduled Synchronization should be disabled and Manual Synchronization should not be used, as both fail.
- Just-In-Time Synchronization must be enabled under Company Settings. It is disabled by default. When enabled, Just-In-Time Synchronization applies to all identity sources configured in your RSA Cloud Authentication Service.
- Ongoing, only Just-In-Time Synchronization and Single-User Synchronization can be used to synchronize users in the identity source.
- Use multiple identity source configurations, each with a Root and User Search Filter chosen to represent a different, smaller subset of users. The number of users who are returned for each identity source must always be less than the maximum that your LDAPv3 directory server returns in one search query result (usually 500). Ensure that there is no overlap between subsets (that is, a user does not occur in more than one identity source) and no required users are omitted.
- Copy user records from your existing directory server to a new LDAPv3 directory server that does support and have enabled the Simple Paged Results control, or to Microsoft Active Directory.
Related Articles
Data Purging does not complete in the configured time limit in RSA Identity Governance & Lifecycle 44Number of Views Error message "GC overhead limit exceeded" in RSA IMG 6.8.1 90Number of Views FIM - user (s) experiencing difficulty with SSO - Expired Certificate 11Number of Views How to implement group security to limit access to web pages by Windows groups. 26Number of Views How to set up warnings/notifications about license limit or user limit expiry in RSA Mobile 28Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA Authentication Manager 8.7 SP2 Setup and Configuration Guide How to Download OTP Token Seed Files from myRSA Download RSA SecurID Access Cloud User Event audit logs using Cloud Administration REST API CLU
Don't see what you're looking for?