# LDAP Provisioning Error

**URL:** <https://developer.sailpoint.com/discuss/t/ldap-provisioning-error/104997>\
**Category:** SHF Discussion and Questions\
**Tags:** provisioning, identity-security-cloud\
**Created:** [March 20, 2025, 8:22pm UTC](https://developer.sailpoint.com/discuss/t/ldap-provisioning-error/104997 "2025-03-20T20:22:33Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![BobbyV](https://avatars.discourse-cdn.com/v4/letter/b/e8c25b/32.png) [@BobbyV](https://developer.sailpoint.com/discuss/u/BobbyV)\
**Post date:** [March 20, 2025, 8:22pm UTC](https://developer.sailpoint.com/discuss/t/ldap-provisioning-error/104997/1 "2025-03-20T20:22:33Z")

</div>

I’m trying to provision to NetIQ eDirectory through the generic LDAP connector (the regular eDirectory connector is not working in our tenant), and am running into the error posted below

```auto
["sailpoint.connector.InvalidRequestException: [InvalidRequestException] \n [Possible suggestions] Ensure that value of \u0027User DN\u0027 is correct. \n [Error details] Invalid name: 00009999","sailpoint.connector.InvalidRequestException: [InvalidRequestException] \n [Possible suggestions] Ensure that value of \u0027User DN\u0027 is correct. \n [Error details] Invalid name: 00009999"]

```

Within the Create Account tab I have tried listing out both _User DN_ and _dn_ as static attribute with the format shown below. _CN_ is being filled with an identity attribute that is found on the accounts, whose value is akin to their employee ID. This matches with accounts already existing in the directory. I have also tried switching the attribute I am using to create the DN, but no matter what attribute I change it to the error does not change values. I did notice that there appears to be a quotation after the employee ID in the error, but again, I don’t know where that is coming from as none of our identity attributes contain quotations.

 ![Screenshot 2025-03-20 at 4.25.27 PM](https://global.discourse-cdn.com/sailpoint/original/3X/e/9/e94dd201cda774ce6dbbcfe8febca8e68ed3dc9c.png)

I have searched through CCG logs, tenant logs (using the CLI) and provisioning logs. None return any more information than the error posted above.

---

<div class="post-metadata">

**Author:** ![JackSparrow](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/jacksparrow/32/19685_2.png) [@JackSparrow](https://developer.sailpoint.com/discuss/u/JackSparrow)\
**Post date:** [March 21, 2025, 4:28am UTC](https://developer.sailpoint.com/discuss/t/ldap-provisioning-error/104997/2 "2025-03-21T04:28:51Z")

</div>

Hi @BobbyV ,

Welcome to developer community!  
Can you get the DN value for any existing users and check the format? Also, the attribute for CN value calculation should be above of DN.

Enable DEBUG level loggings for LDAP connector and check for more logs

---

<div class="post-metadata">

**Author:** ![rpriya](https://avatars.discourse-cdn.com/v4/letter/r/bc79bd/32.png) [@rpriya](https://developer.sailpoint.com/discuss/u/rpriya)\
**Post date:** [March 21, 2025, 1:18pm UTC](https://developer.sailpoint.com/discuss/t/ldap-provisioning-error/104997/3 "2025-03-21T13:18:31Z")

</div>

In the search tab, searching with a specific user’s ID will display some Account Activity logs. The ‘Account Activity’ tab should contain a log showing the values SailPoint is sending to the attributes. This log will include ‘Account Request’ and ‘Attribute Requests,’ where attribute information can be found in the ‘Attribute Requests’ section. Is the expected value been passed to ‘dn’ in the logs?

---

<div class="post-metadata">

**Author:** ![BobbyV](https://avatars.discourse-cdn.com/v4/letter/b/e8c25b/32.png) [@BobbyV](https://developer.sailpoint.com/discuss/u/BobbyV)\
**Post date:** [March 21, 2025, 1:34pm UTC](https://developer.sailpoint.com/discuss/t/ldap-provisioning-error/104997/4 "2025-03-21T13:34:19Z")

</div>

Hi @JackSparrow, @rpriya

Thank you both for responding!

The DN for existing users matches the format we are using for the _DN_. The _CN_ attribute is also defined above.

Within the ccg logs I can see the _dn_ formatted correctly (picture below with some omissions).  
 ![Screenshot 2025-03-21 at 9.23.56 AM](https://global.discourse-cdn.com/sailpoint/original/3X/f/c/fc5c034f408fffe032dfc215c39b5f663c6a78c3.png)

From the ‘Account Activity’ tab, this is the error received.

```auto
sailpoint.connector.InvalidRequestException: [InvalidRequestException] 
 [Possible suggestions] Ensure that value of 'User DN' is correct. 
 [Error details] Invalid name: 02######

```

The _dn_ value within the ‘Attribute Request’ matches with what I pasted from the VA logs.

Again, even when changing the _dn_ name to _User DN_ or any variation of, the same error returns. I’m not sure where it’s getting the Invalid Name from as I am obviously passing in a complete DN, not just the CN

---

<div class="post-metadata">

**Author:** ![JackSparrow](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/jacksparrow/32/19685_2.png) [@JackSparrow](https://developer.sailpoint.com/discuss/u/JackSparrow)\
**Post date:** [March 21, 2025, 1:47pm UTC](https://developer.sailpoint.com/discuss/t/ldap-provisioning-error/104997/5 "2025-03-21T13:47:00Z")

</div>

Hi @BobbyV ,

I think the DN format should be as below. It should be “uid” than “cn”. Not sure if this varies across systems. You can check for any existing user in LDAP system

uid=1234567,ou=Field Users,ou=People,[o=test.com](http://o=test.com)

---

<div class="post-metadata">

**Author:** ![rpriya](https://avatars.discourse-cdn.com/v4/letter/r/bc79bd/32.png) [@rpriya](https://developer.sailpoint.com/discuss/u/rpriya)\
**Post date:** [March 21, 2025, 2:03pm UTC](https://developer.sailpoint.com/discuss/t/ldap-provisioning-error/104997/6 "2025-03-21T14:03:14Z")

</div>

Can you try using a hardcoded value?  
Also, the error you mentioned is for ‘User DN’. Is it the same for ‘dn’? Usually, policy attributes don’t have spaces, and their names should match the schema attributes

---

<div class="post-metadata">

**Author:** ![BobbyV](https://avatars.discourse-cdn.com/v4/letter/b/e8c25b/32.png) [@BobbyV](https://developer.sailpoint.com/discuss/u/BobbyV)\
**Post date:** [March 21, 2025, 2:04pm UTC](https://developer.sailpoint.com/discuss/t/ldap-provisioning-error/104997/7 "2025-03-21T14:04:19Z")

</div>

Our directory structure uses CN to formulate the DN. For example, my DN may be cn=bvielma,ou=People,ou=Users,o=Org (the difference in CN values between mine and the one I’m using for testing is expected and seen within our directory)

---

<div class="post-metadata">

**Author:** ![BobbyV](https://avatars.discourse-cdn.com/v4/letter/b/e8c25b/32.png) [@BobbyV](https://developer.sailpoint.com/discuss/u/BobbyV)\
**Post date:** [March 21, 2025, 2:07pm UTC](https://developer.sailpoint.com/discuss/t/ldap-provisioning-error/104997/8 "2025-03-21T14:07:29Z")

</div>

The same error returns when hardcoding the value of their CN and processing them again.

Your comment on the error is also what has prevented me from troubleshooting it on my own any further. I do not know why this error is being thrown with that attribute name as there is no _User DN_ attribute within the schema nor within our directory.

---

<div class="post-metadata">

**Author:** ![j\_place](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/j_place/32/19181_2.png) [@j\_place](https://developer.sailpoint.com/discuss/u/j_place)\
**Post date:** [March 21, 2025, 2:17pm UTC](https://developer.sailpoint.com/discuss/t/ldap-provisioning-error/104997/9 "2025-03-21T14:17:14Z")

</div>

Hi @BobbyV Are you passing CN as a separate attribute as well as in the DN?

---

<div class="post-metadata">

**Author:** ![BobbyV](https://avatars.discourse-cdn.com/v4/letter/b/e8c25b/32.png) [@BobbyV](https://developer.sailpoint.com/discuss/u/BobbyV)\
**Post date:** [March 21, 2025, 2:24pm UTC](https://developer.sailpoint.com/discuss/t/ldap-provisioning-error/104997/10 "2025-03-21T14:24:51Z")

</div>

Hey Jeremy,

Yes, it’s being defined higher up in the Create Account module, and is being passed over correctly in the ‘Attribute Request’ section of ‘Account Activity’

---

<div class="post-metadata">

**Author:** ![j\_place](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/j_place/32/19181_2.png) [@j\_place](https://developer.sailpoint.com/discuss/u/j_place)\
**Post date:** [March 21, 2025, 2:28pm UTC](https://developer.sailpoint.com/discuss/t/ldap-provisioning-error/104997/11 "2025-03-21T14:28:07Z")

</div>

I would try not passing CN as a separate attribute. The error is about an invalid “name” which normally refers to the CN. To test, remove CN from create profile and hard code your DN.

---

<div class="post-metadata">

**Author:** ![RAKRHEEM](https://avatars.discourse-cdn.com/v4/letter/r/f05b48/32.png) [@RAKRHEEM](https://developer.sailpoint.com/discuss/u/RAKRHEEM)\
**Post date:** [March 21, 2025, 2:46pm UTC](https://developer.sailpoint.com/discuss/t/ldap-provisioning-error/104997/12 "2025-03-21T14:46:14Z")

</div>

Hey Bobby,  
If you are passing dn do not pass cn. It will be added by the connector. To Test this remove the cn value and just have the dn value. Also can you share the Account Activity how the attribute looks like after you change the setting and let us know if it fixes your issue

Thanks

---

<div class="post-metadata">

**Author:** ![BobbyV](https://avatars.discourse-cdn.com/v4/letter/b/e8c25b/32.png) [@BobbyV](https://developer.sailpoint.com/discuss/u/BobbyV)\
**Post date:** [March 21, 2025, 3:10pm UTC](https://developer.sailpoint.com/discuss/t/ldap-provisioning-error/104997/13 "2025-03-21T15:10:49Z")

</div>

@j_place as well.

I removed the CN attribute from the Create Profile and hardcoded the entire DN, but the error persists. I’d also like to call out that the CN and DN fields both come OOB on the ‘Create Account’ screen when setting up the connector. If there’s documentation that states to not include CN when DN is filled out, I’d appreciate it if someone could link it.

Below is a sample of the Account Activity data when removing CN and hardcoding DN. Other attempts look identical (except for including CN).

```auto
ACCOUNT REQUEST
Create account: 02######
ATTRIBUTE REQUESTS
Add groupMembership: cn=Stores,ou=AA,ou=Groups,o=Org
Add password: Unknown
Add givenName: Katie
Add SN: Test
Add afBusinessTitle: Brand Representative
Add afBusinessUnit: S
Add afCompany: Stores, Inc.
Add afCompanyCode: AST
Add afDepartment: Ala Moana
Add afEmployeePayType: H
Add afFirstName: Katie
Add afJobCode: 0023
Add afDepartmentID: #####
Add afJobCodeDescr: Brand Representative
Add afJobFamily: STONON
Add afJobFunction: STO
Add afJobGrouping: 02
Add afLastName: Test
Add afLocation: Ala Moana
Add afLocationCode: #####
Add afLocationDesc: Ala Moana
Add afManagerLevel: Support
Add afManagerLevelCode: S1
Add afObjectActive: TRUE
Add afOfficeType: S
Add afPersonType: EMP
Add afPosition: Representative
Add afPositionNumber: ########
Add afRmsEmployeeTypeCode: None
Add afStartDate: 2025-03-14
Add afTitle: Brand Representative
Add co: USA
Add displayName: Katie Test
Add employeeStatus: A
Add Language: ENG
Add title: Brand Representative
Add uid: 02######
Add objectClass: inetOrgPerson,Person,afPerson,Top,organizationalPerson,afVendor,DirXML-PasswordSyncStatusUser
Add mail: none@testdomain.com
Add dn: cn=02######,ou=People,ou=Users,o=Org

```

---

<div class="post-metadata">

**Author:** ![j\_place](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/j_place/32/19181_2.png) [@j\_place](https://developer.sailpoint.com/discuss/u/j_place)\
**Post date:** [March 21, 2025, 3:40pm UTC](https://developer.sailpoint.com/discuss/t/ldap-provisioning-error/104997/14 "2025-03-21T15:40:41Z")

</div>

Hi @BobbyV One more thing to try - possibly the UID syntax doesn’t allow prefixed zeros, I believe it is integer syntax.

---

<div class="post-metadata">

**Author:** ![delaudee](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/delaudee/32/23687_2.png) [@delaudee](https://developer.sailpoint.com/discuss/u/delaudee)\
**Post date:** [March 21, 2025, 5:31pm UTC](https://developer.sailpoint.com/discuss/t/ldap-provisioning-error/104997/15 "2025-03-21T17:31:22Z")

</div>

Based on this screenshot:  
 ![image](https://global.discourse-cdn.com/sailpoint/original/3X/2/1/21c6d7b68685c4412ff98ccb1d340a9abe21ae5e.png)

It looks like you are trying to set the “name” attribute in eDir as a DN. The name attribute is an LDAP attribute but not an eDir attribute. Verify in your create account that you are not sending a value for name. LDAP will show the CN as the name attribute when using an LDAP browser, it does not need to be part of the create. I am not sure if eDir sets some other attribute that maps to name in LDAP or how that part is working but it cannot be part of the create as eDir does not recognize that attribute unless you add it to your LDAP group attribute map and have it mapped to some other eDir attribute.

---

<div class="post-metadata">

**Author:** ![BobbyV](https://avatars.discourse-cdn.com/v4/letter/b/e8c25b/32.png) [@BobbyV](https://developer.sailpoint.com/discuss/u/BobbyV)\
**Post date:** [March 21, 2025, 6:10pm UTC](https://developer.sailpoint.com/discuss/t/ldap-provisioning-error/104997/16 "2025-03-21T18:10:24Z")

</div>

Hey Eric,

Thanks for the reply.

I believe the part you highlighted is part of the connector call. As in it is saying the _name_ of attribute is “dn”, just as the _op_ is “Add” and the _value_ is “cn=02…”

---

<div class="post-metadata">

**Author:** ![BobbyV](https://avatars.discourse-cdn.com/v4/letter/b/e8c25b/32.png) [@BobbyV](https://developer.sailpoint.com/discuss/u/BobbyV)\
**Post date:** [March 21, 2025, 6:17pm UTC](https://developer.sailpoint.com/discuss/t/ldap-provisioning-error/104997/17 "2025-03-21T18:17:14Z")

</div>

Hey Jeremy,

The OOB connector sets _uid_ to be a string. It’s also set as a string in our LDAP schema and other existing accounts have leading zeros as their UID. I did try hardcoding a value without a leading zero (as we don’t have any _int_ or _long_ data types in our schema) but it didn’t work (although I’m sure it was still processing it as a string)

---

<div class="post-metadata">

**Author:** ![j\_place](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/j_place/32/19181_2.png) [@j\_place](https://developer.sailpoint.com/discuss/u/j_place)\
**Post date:** [March 21, 2025, 6:32pm UTC](https://developer.sailpoint.com/discuss/t/ldap-provisioning-error/104997/18 "2025-03-21T18:32:53Z")

</div>

Understood, the only thing I’ve got left (assuming you’ve already checked uniqueness) is case sensitivity on the attribute name - maybe try “DN” vs “dn”?

---

<div class="post-metadata">

**Author:** ![BobbyV](https://avatars.discourse-cdn.com/v4/letter/b/e8c25b/32.png) [@BobbyV](https://developer.sailpoint.com/discuss/u/BobbyV)\
**Post date:** [March 24, 2025, 2:50pm UTC](https://developer.sailpoint.com/discuss/t/ldap-provisioning-error/104997/19 "2025-03-24T14:50:41Z")

</div>

Unfortunately didn’t work. I suppose I’ll open a ticket with SailPoint support to see if they’re able to assist with expert services.

Thanks all! I’ll update once I get it figured out

---

<div class="post-metadata">

**Author:** ![BobbyV](https://avatars.discourse-cdn.com/v4/letter/b/e8c25b/32.png) [@BobbyV](https://developer.sailpoint.com/discuss/u/BobbyV)\
**Post date:** [March 27, 2025, 3:05pm UTC](https://developer.sailpoint.com/discuss/t/ldap-provisioning-error/104997/20 "2025-03-27T15:05:33Z")

</div>

Following up here, the issue was changing the Account ID from DN.

[Next page](https://developer.sailpoint.com/discuss/t/ldap-provisioning-error/104997.md?page=2)
