Symantec Access Management

  • 1.  NameErr: DSID-0310020A, problem 2001 (NO_OBJECT)

    Broadcom Employee
    Posted May 19, 2018 08:35 PM

    Seeing this error intermittenly in smps log, any idea under what circumstance this error pops up?

     

    [SmDsLdapConnMgr.cpp:1207][ERROR][sm-Ldap-02230] Error# '32' during search: 'error: No such object extended error: 0000208D: NameErr: DSID-0310020A, problem 2001 (NO_OBJECT), data 0, best match of:

            'OU=employees,OU=People,DC=EXT,DC=abc,DC=com'

     matched dn: OU=employees,OU=People,DC=EXT,DC=abc,DC=com' Search Query = 'objectclass



  • 2.  Re: NameErr: DSID-0310020A, problem 2001 (NO_OBJECT)

    Broadcom Employee
    Posted Jun 26, 2018 06:10 PM

    I'm able to search this OU via LDAP browser, but SM is getting the error back from LDAP. I have asked LDAP admin to check on their end, in the mean time i would like to know if anyone seen such behavior.

     

    This is on SSO 12.7 SP2, AD 2012 as user store.



  • 3.  RE: Re: NameErr: DSID-0310020A, problem 2001 (NO_OBJECT)

    Posted Feb 13, 2020 09:09 AM
    Hello , Is this resolved ? We also see these errors frequently in SMPS logs.


  • 4.  RE: NameErr: DSID-0310020A, problem 2001 (NO_OBJECT)

    Broadcom Employee
    Posted Mar 12, 2020 05:33 AM
    Hi Makesh,

    It looks like the problem might be on the Active Directory side as per
    misconfiguration :

    Internal event: The LDAP server returned an error.

    It looks like this error says that the domain controller in question
    can't figure out what site it's in because the configuration partition
    of AD (which stores the site info) is unable to be located.

    This is bad.

    When demoting and promoting domain controllers results in problems
    that I don't normally see, I ask the questions:

    1. Do you still have all 5 FSMOs, and do you have any extra
    2. Are your DNS servers still up and running
    3. Did you ghost your domain controllers, if yes, did you translate
    the SID for your machines using SYSprep or some SID tool?

    Also, for this problem, you might want to use ADSI edit to connect to
    the configuration partition of AD and examine if the Site information
    actually does exist, or if it got deleted by something of unknown
    origin.

    https://social.technet.microsoft.com/Forums/windowsserver/en-US/517cfc7c-2a4e-47f9-80bf-0d5d7e2cd4ac/internal-event-the-ldap-server-returned-an-error?forum=winserverDS