and more in a single search tool across platforms. Read the announcement here. |
06/08/2023 07:43 AM - edited 06/08/2023 07:44 AM
Hello,
We are using the ENABLEACCOUNTJSON to enable a disabled account through user update rules.
The Enable account task is created, but when we try to provision the task fails. There are no errors in the provisioning comments, but we do get this error in our logs:
We do not use objectGUID as reconcilation field, but we do use another field (entryDN) which is also always unique.
Can anyone help us with this error? Find current ENABLEACCOUNTJSON below:
{
"DISABLEACCOUNTCHECKRULE":[ "CN=${user.customproperty1},ou=STUDENT,o=uhasselt,c=be"],
"USEDNFROMACCOUNT": "YES",
"pwdLockout" : "FALSE",
"pwdPolicySubentry" : ''
}
We have also tried:
{
"DISABLEACCOUNTCHECKRULE":[ "CN=${user.customproperty1},ou=STUDENT,o=uhasselt,c=be"],
"USEDNFROMACCOUNT": "YES",
"AFTERENABLEACTIONS":
"{pwdLockout : FALSE, pwdPolicySubentry : ''}"
}
PS: Full logs added in attachments.
06/13/2023 03:25 PM
Based on the error and the recommendation, we do need to use objectGUID in reconciliation field. Can you update the same and then try once.
06/13/2023 11:40 PM
objectGUID is not an attribute in our OpenLDAP. We are using entryDN as reconcilation field, which is also a unique identifier.
06/14/2023 09:25 AM
can you run the job for only 1 task (Create a new one) and share the logs with the exception you are getting.
06/13/2023 03:28 PM
If it is still not working, can you run the job for only 1 task (Create a new one) and share the logs with the exception you are getting.