IBM Support

PM66670: WHEN LOGIN ATTRIBUTE VALUE HAS "=" SIGN IN IT, INVALIDUNIQUENAME EXCEPTION IS THROWN.

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • UniqueName formation was incorrect which leads to login failure
    with 6/5/12 9:53:35:968 EDT] 00000087 UserRegistryI E
    SECJ0363E: Cannot create credential for the user tw=admin
    because of the following exception
    com.ibm.websphere.wim.exception.InvalidUniqueNameException:
    CWWIM0515E  The 'tw=admin' entity is not in the scope of the
    'defined' realm.
     at
    com.ibm.ws.wim.RepositoryManager.getRepositoryIndexByUniqueName(
    RepositoryManager.java:333)
     at
    com.ibm.ws.wim.RepositoryManager.getRepositoryID(RepositoryManag
    er.java:279)
     at
    com.ibm.ws.wim.ProfileManager.retrieveEntityFromRepository(Profi
    leManager.java:2800)
     at
    com.ibm.ws.wim.ProfileManager.retrieveEntity(ProfileManager.java
    :2916)
     at
    com.ibm.ws.wim.ProfileManager.getImpl(ProfileManager.java:1614)
     at
    com.ibm.ws.wim.ProfileManager.genericProfileManagerMethod(Profil
    eManager.java:364)
     at
    com.ibm.ws.wim.ProfileManager.get(ProfileManager.java:417)
     at
    com.ibm.websphere.wim.ServiceProvider.get(ServiceProvider.java:3
    66)
     at
    com.ibm.ws.wim.registry.util.BridgeUtils.getEntityByIdentifier(B
    ridgeUtils.java:622)
     at
    com.ibm.ws.wim.registry.util.UniqueIdBridge.getUniqueUserId(Uniq
    ueIdBridge.java:202)
     at
    com.ibm.ws.wim.registry.WIMUserRegistry$6.run(WIMUserRegistry.ja
    va:568)
     at
    com.ibm.ws.security.auth.ContextManagerImpl.runAs(ContextManager
    Impl.java:5445)
    

Local fix

Problem summary

  • ****************************************************************
    * USERS AFFECTED:  All users of IBM WebSphere Application      *
    *                  Server                                      *
    ****************************************************************
    * PROBLEM DESCRIPTION: Virtual member manager (VMM) throws     *
    *                      InvalidUniqueNameException when the     *
    *                      login attribute value contains an       *
    *                      equal sign "=".                         *
    ****************************************************************
    * RECOMMENDATION:                                              *
    ****************************************************************
    VMM throws InvalidUniqueNameException when the login attribute
    value contains a "=". When an equal sign "=" is encountered in
    the login name for example 'tw=admin', VMM treats this as a
    distinguished name (DN) and hence the login fails.
    

Problem conclusion

  • You need to set a custom property using the following
    command
    
    $AdminTask configureAdminWIMUserRegistry {-customProperties
    {"com.ibm.ws.wim.registry.allowDNPrincipalNameAsLiteral
    =true"} }
    
    When this property is set, VMM determines whether the login
    name ends with a baseEntry. If the login name does not end
    with a baseEntry it is not treated as a DN and the login is
    successful.
    
    The fix for this APAR is currently targeted for inclusion in
    fix packs 8.0.0.4 and 8.5.0.1.  Please refer to the
    Recommended Updates page for delivery information:
    http://www.ibm.com/support/docview.wss?rs=180&uid=swg27004980
    

Temporary fix

Comments

APAR Information

  • APAR number

    PM66670

  • Reported component name

    WEBS APP SERV N

  • Reported component ID

    5724H8800

  • Reported release

    800

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt

  • Submitted date

    2012-06-13

  • Closed date

    2012-07-13

  • Last modified date

    2012-07-13

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    WEBS APP SERV N

  • Fixed component ID

    5724H8800

Applicable component levels

  • R800 PSY

       UP

  • R850 PSY

       UP

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSEQTP","label":"WebSphere Application Server"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"8.0","Line of Business":{"code":"LOB45","label":"Automation"}}]

Document Information

Modified date:
29 October 2021