Symantec Access Management

  • 1.  12.6 and EnableCustomExprOnly registry setting

    Posted Jan 13, 2017 11:34 AM

    So I recently took the plunge and migrated a test 12.52 policy server over to 12.6 on Windows.  We use custom certificate mapping authentication with the EnableCustomExprOnly registry key set to allow us to use another LDAP attribute to store the user CN from the certificate.  It would appear that 12.6 no longer recognizes this registry key and tries to map the custom expression to the user directory attribute.  I have opened a support request for this but was wondering if anyone else has ran into any similar issues with registry settings in 12.6.



  • 2.  Re: 12.6 and EnableCustomExprOnly registry setting



  • 3.  Re: 12.6 and EnableCustomExprOnly registry setting
    Best Answer

    Posted Jan 16, 2017 08:12 PM

    Hi Andrew,

     

    I can confirm from source code review that , the support for EnableCustomExprOnly registry is indeed disabled in 12.6

    This has not been documented in the bookshelf. 

    As per the source code comment, this was temporarily disabled for  testing the 64 bit support for Policy server.

    I reckon they forgot to undo the debug changes.


    So this really is a bug.

    I have instructed the assigned engineer of your support case to engage SE and provide dev fix.

     

    Cheers,

    Ujwol Shrestha

    Ujwol's Single Sign-On Blog 



  • 4.  Re: 12.6 and EnableCustomExprOnly registry setting

    Posted Jan 17, 2017 10:58 AM

    Thank you Ujwol!