<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic LDAP configuration giving an error for user configuration  in sas viya in Administration and Deployment</title>
    <link>https://communities.sas.com/t5/Administration-and-Deployment/LDAP-configuration-giving-an-error-for-user-configuration-in-sas/m-p/885776#M26979</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have configured and AD in my Microsoft server and configured the LDAP for it, I have kept my AD server public so that anyone can connect.&lt;/P&gt;&lt;P&gt;To check its connectivity I have installed apache directory studio in another windows instance and I am able to connect to my AD server using its host, user &amp;amp; password.&amp;nbsp;&lt;/P&gt;&lt;P&gt;so when I am configuring ldap for my Provider tenant from sas environment manager I am getting error as&lt;/P&gt;&lt;PRE&gt;LDAP: error code 32 - 0000208D: NameErr: DSID-0310028D, problem 2001 (NO_OBJECT), data 0, best match of:\n\t'OU=sas,DC=my-cloud-app,DC=link'\n\u0000]; remaining name 'ou=people,ou=provider,OU=sas,DC=my-cloud-app,DC=link'","properties":{"logger":"com.sas.identities.provider.ldap.LdapIdentityQueryRepository","thread":"configWatchTaskScheduler-1"}&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;So, i have kept my directory structure is like,&lt;/P&gt;&lt;P&gt;DC=my-cloud-app,DC=link&lt;/P&gt;&lt;P&gt;&amp;gt; ou=sas&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;gt;user=viya_admin&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;gt;user=test-user&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So i have kept my userDN for viya_admin user and i have already delgate this user for Ou=sas and whole directory&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;in User configuration, i given baseDN as "OU=sas,DC=my-cloud-app,DC=link" so ideally it should look for user in sas ou, but i am getting above error, and main thing we are getting is why it is appending ou=people,ou=provider&amp;nbsp; as mention below, i haven't mentioned it in my user configuration&lt;/P&gt;&lt;PRE&gt;best match of:\n\t'OU=sas,DC=my-cloud-app,DC=link'\n\u0000]; remaining name 'ou=people,ou=provider,OU=sas,DC=my-cloud-app,DC=link'"&lt;/PRE&gt;&lt;P&gt;so i want to understand why there is this errors are coming, from where it is fetching ou=people and ou=provider&lt;/P&gt;&lt;PRE&gt;{"version":1,"timeStamp":"2023-07-07T12:48:27.514Z","level":"info","source":"sas-identities","message":"[ADD_MEMBER_INFO] Adding viya_admin as a member of the group SASAdministrators","properties":{"logger":"com.sas.identities.config.DefaultMembershipLoader","thread":"configWatchTaskScheduler-1"},"messageKey":"com.sas.identities.LogMessages.ADD_MEMBER_INFO","messageParameters":{"0":"viya_admin","1":"SASAdministrators"}}
{"version":1,"timeStamp":"2023-07-07T12:48:27.52Z","level":"warn","source":"sas-identities","message":"[IDENTITY_FETCH_LDAP_ERROR] Error occurred while fetching identity: [LDAP: error code 32 - 0000208D: NameErr: DSID-0310028D, problem 2001 (NO_OBJECT), data 0, best match of:\n\t'OU=sas,DC=my-cloud-app,DC=link'\n\u0000]; nested exception is javax.naming.NameNotFoundException: [LDAP: error code 32 - 0000208D: NameErr: DSID-0310028D, problem 2001 (NO_OBJECT), data 0, best match of:\n\t'OU=sas,DC=my-cloud-app,DC=link'\n\u0000]; remaining name 'ou=people,ou=provider,OU=sas,DC=my-cloud-app,DC=link'","properties":{"logger":"com.sas.identities.provider.ldap.LdapIdentityQueryRepository","thread":"configWatchTaskScheduler-1"},"messageKey":"com.sas.identities.LogMessages.IDENTITY_FETCH_LDAP_ERROR","messageParameters":{"0":"[LDAP: error code 32 - 0000208D: NameErr: DSID-0310028D, problem 2001 (NO_OBJECT), data 0, best match of:\n\t'OU=sas,DC=my-cloud-app,DC=link'\n\t\u0000]; nested exception is javax.naming.NameNotFoundException: [LDAP: error code 32 - 0000208D: NameErr: DSID-0310028D, problem 2001 (NO_OBJECT), data 0, best match of:\n\t'OU=sas,DC=my-cloud-app,DC=link'\n\t\u0000]; remaining name 'ou=people,ou=provider,OU=sas,DC=my-cloud-app,DC=link'"}}
{"version":1,"timeStamp":"2023-07-07T12:48:27.523Z","level":"error","source":"sas-identities","message":"[GET_IDENTITY_MEMBER_ERROR] Cannot add viya_admin member to SASAdministrators group because the USER could not be found.","properties":{"logger":"com.sas.identities.config.DefaultMembershipLoader","thread":"configWatchTaskScheduler-1"},"messageKey":"com.sas.identities.LogMessages.GET_IDENTITY_MEMBER_ERROR","messageParameters":{"0":"viya_admin","1":"SASAdministrators","2":"USER"}}
{"version":1,"timeStamp":"2023-07-07T12:48:27.523Z","level":"info","source":"sas-identities","message":"Refresh keys changed: [sas.identities.providers.ldap.user.baseDN]","properties":{"logger":"org.springframework.cloud.endpoint.event.RefreshEventListener","thread":"configWatchTaskScheduler-1"}}

&lt;/PRE&gt;&lt;P&gt;also this viya_admin it is trying to add as member to SASAdministrator, i don't get from where and why it is trying to this user at first and second why i am getting this no object error even though i have user in given baseDN.&lt;/P&gt;&lt;P&gt;i have kept the rest attribute default for user configuration&lt;/P&gt;</description>
    <pubDate>Fri, 21 Jul 2023 09:34:26 GMT</pubDate>
    <dc:creator>Shriramwasule</dc:creator>
    <dc:date>2023-07-21T09:34:26Z</dc:date>
    <item>
      <title>LDAP configuration giving an error for user configuration  in sas viya</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/LDAP-configuration-giving-an-error-for-user-configuration-in-sas/m-p/885776#M26979</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have configured and AD in my Microsoft server and configured the LDAP for it, I have kept my AD server public so that anyone can connect.&lt;/P&gt;&lt;P&gt;To check its connectivity I have installed apache directory studio in another windows instance and I am able to connect to my AD server using its host, user &amp;amp; password.&amp;nbsp;&lt;/P&gt;&lt;P&gt;so when I am configuring ldap for my Provider tenant from sas environment manager I am getting error as&lt;/P&gt;&lt;PRE&gt;LDAP: error code 32 - 0000208D: NameErr: DSID-0310028D, problem 2001 (NO_OBJECT), data 0, best match of:\n\t'OU=sas,DC=my-cloud-app,DC=link'\n\u0000]; remaining name 'ou=people,ou=provider,OU=sas,DC=my-cloud-app,DC=link'","properties":{"logger":"com.sas.identities.provider.ldap.LdapIdentityQueryRepository","thread":"configWatchTaskScheduler-1"}&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;So, i have kept my directory structure is like,&lt;/P&gt;&lt;P&gt;DC=my-cloud-app,DC=link&lt;/P&gt;&lt;P&gt;&amp;gt; ou=sas&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;gt;user=viya_admin&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;gt;user=test-user&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So i have kept my userDN for viya_admin user and i have already delgate this user for Ou=sas and whole directory&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;in User configuration, i given baseDN as "OU=sas,DC=my-cloud-app,DC=link" so ideally it should look for user in sas ou, but i am getting above error, and main thing we are getting is why it is appending ou=people,ou=provider&amp;nbsp; as mention below, i haven't mentioned it in my user configuration&lt;/P&gt;&lt;PRE&gt;best match of:\n\t'OU=sas,DC=my-cloud-app,DC=link'\n\u0000]; remaining name 'ou=people,ou=provider,OU=sas,DC=my-cloud-app,DC=link'"&lt;/PRE&gt;&lt;P&gt;so i want to understand why there is this errors are coming, from where it is fetching ou=people and ou=provider&lt;/P&gt;&lt;PRE&gt;{"version":1,"timeStamp":"2023-07-07T12:48:27.514Z","level":"info","source":"sas-identities","message":"[ADD_MEMBER_INFO] Adding viya_admin as a member of the group SASAdministrators","properties":{"logger":"com.sas.identities.config.DefaultMembershipLoader","thread":"configWatchTaskScheduler-1"},"messageKey":"com.sas.identities.LogMessages.ADD_MEMBER_INFO","messageParameters":{"0":"viya_admin","1":"SASAdministrators"}}
{"version":1,"timeStamp":"2023-07-07T12:48:27.52Z","level":"warn","source":"sas-identities","message":"[IDENTITY_FETCH_LDAP_ERROR] Error occurred while fetching identity: [LDAP: error code 32 - 0000208D: NameErr: DSID-0310028D, problem 2001 (NO_OBJECT), data 0, best match of:\n\t'OU=sas,DC=my-cloud-app,DC=link'\n\u0000]; nested exception is javax.naming.NameNotFoundException: [LDAP: error code 32 - 0000208D: NameErr: DSID-0310028D, problem 2001 (NO_OBJECT), data 0, best match of:\n\t'OU=sas,DC=my-cloud-app,DC=link'\n\u0000]; remaining name 'ou=people,ou=provider,OU=sas,DC=my-cloud-app,DC=link'","properties":{"logger":"com.sas.identities.provider.ldap.LdapIdentityQueryRepository","thread":"configWatchTaskScheduler-1"},"messageKey":"com.sas.identities.LogMessages.IDENTITY_FETCH_LDAP_ERROR","messageParameters":{"0":"[LDAP: error code 32 - 0000208D: NameErr: DSID-0310028D, problem 2001 (NO_OBJECT), data 0, best match of:\n\t'OU=sas,DC=my-cloud-app,DC=link'\n\t\u0000]; nested exception is javax.naming.NameNotFoundException: [LDAP: error code 32 - 0000208D: NameErr: DSID-0310028D, problem 2001 (NO_OBJECT), data 0, best match of:\n\t'OU=sas,DC=my-cloud-app,DC=link'\n\t\u0000]; remaining name 'ou=people,ou=provider,OU=sas,DC=my-cloud-app,DC=link'"}}
{"version":1,"timeStamp":"2023-07-07T12:48:27.523Z","level":"error","source":"sas-identities","message":"[GET_IDENTITY_MEMBER_ERROR] Cannot add viya_admin member to SASAdministrators group because the USER could not be found.","properties":{"logger":"com.sas.identities.config.DefaultMembershipLoader","thread":"configWatchTaskScheduler-1"},"messageKey":"com.sas.identities.LogMessages.GET_IDENTITY_MEMBER_ERROR","messageParameters":{"0":"viya_admin","1":"SASAdministrators","2":"USER"}}
{"version":1,"timeStamp":"2023-07-07T12:48:27.523Z","level":"info","source":"sas-identities","message":"Refresh keys changed: [sas.identities.providers.ldap.user.baseDN]","properties":{"logger":"org.springframework.cloud.endpoint.event.RefreshEventListener","thread":"configWatchTaskScheduler-1"}}

&lt;/PRE&gt;&lt;P&gt;also this viya_admin it is trying to add as member to SASAdministrator, i don't get from where and why it is trying to this user at first and second why i am getting this no object error even though i have user in given baseDN.&lt;/P&gt;&lt;P&gt;i have kept the rest attribute default for user configuration&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jul 2023 09:34:26 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/LDAP-configuration-giving-an-error-for-user-configuration-in-sas/m-p/885776#M26979</guid>
      <dc:creator>Shriramwasule</dc:creator>
      <dc:date>2023-07-21T09:34:26Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP configuration giving an error for user configuration  in sas viya</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/LDAP-configuration-giving-an-error-for-user-configuration-in-sas/m-p/885824#M26985</link>
      <description>It sounds like you have not set the user configuration to "Apply configuration only to this tenant" so it is trying to use the configuration for a single LDAP configuration for all tenants. This expects a specific LDAP structure, which it's trying to use here. This is discussed here:&lt;BR /&gt;&lt;BR /&gt;Set Up Accounts for Multi-tenant Deployments: Single LDAP Server for All Tenants&lt;BR /&gt;&lt;A href="https://go.documentation.sas.com/doc/en/calcdc/3.5/dplyml0phy0lax/n15hhewllr5ji2n1sxf96imqvtpj.htm#p1hg2b12g1pc3sn12nyuhdl47qyl" target="_blank"&gt;https://go.documentation.sas.com/doc/en/calcdc/3.5/dplyml0phy0lax/n15hhewllr5ji2n1sxf96imqvtpj.htm#p1hg2b12g1pc3sn12nyuhdl47qyl&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;whereas what you want to do is here:&lt;BR /&gt;Set Up Accounts for Multi-tenant Deployments: Separate LDAP Server per Tenant&lt;BR /&gt;&lt;A href="https://go.documentation.sas.com/doc/en/calcdc/3.5/dplyml0phy0lax/n15hhewllr5ji2n1sxf96imqvtpj.htm#n1o63hqzwa1ry8n1glia1d2x92ib" target="_blank"&gt;https://go.documentation.sas.com/doc/en/calcdc/3.5/dplyml0phy0lax/n15hhewllr5ji2n1sxf96imqvtpj.htm#n1o63hqzwa1ry8n1glia1d2x92ib&lt;/A&gt;</description>
      <pubDate>Fri, 21 Jul 2023 14:12:12 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/LDAP-configuration-giving-an-error-for-user-configuration-in-sas/m-p/885824#M26985</guid>
      <dc:creator>gwootton</dc:creator>
      <dc:date>2023-07-21T14:12:12Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP configuration giving an error for user configuration in sas viya</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/LDAP-configuration-giving-an-error-for-user-configuration-in-sas/m-p/885829#M26986</link>
      <description>Thanks for the reply,&lt;BR /&gt;I am using separate LDAP config for each tenant, currently I want to enable&lt;BR /&gt;LDAP for provider tenant. I have logged into the environment manager&lt;BR /&gt;account using sasboot user.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 21 Jul 2023 14:39:56 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/LDAP-configuration-giving-an-error-for-user-configuration-in-sas/m-p/885829#M26986</guid>
      <dc:creator>Shriramwasule</dc:creator>
      <dc:date>2023-07-21T14:39:56Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP configuration giving an error for user configuration in sas viya</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/LDAP-configuration-giving-an-error-for-user-configuration-in-sas/m-p/885831#M26987</link>
      <description>Yes, so you'll need to turn on the "Apply configuration only to this tenant" switch in your sas.identities.providers.ldap.user configuration in the provider tenant. From your description, this is currently off.</description>
      <pubDate>Fri, 21 Jul 2023 14:46:12 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/LDAP-configuration-giving-an-error-for-user-configuration-in-sas/m-p/885831#M26987</guid>
      <dc:creator>gwootton</dc:creator>
      <dc:date>2023-07-21T14:46:12Z</dc:date>
    </item>
  </channel>
</rss>

