Identity Manager support for ASLR on Windows

  • 7012940
  • 25-Jul-2013
  • 25-Jul-2013

Environment

NetIQ Identity Manager 4.0
NetIQ Identity Manager - Remote Loader
NetIQ Identity Manager Driver - Active Directory
Microsoft Windows 2003
Microsoft Windows 2008
Microsoft Windows 2008 R2
Microsoft Windows 2012

Situation

ASLR (Address Space Layout Randomization) have been enabled for all applications.

Publisher Thread does not start.

In the trace the following is seen:

DirXML: [07/05/13 13:04:06.51]: ADDriver: rootDSE information needed.
DirXML: [07/05/13 13:04:06.51]: ADDriver: Make unauthenticated connection to rootDSE
DirXML: [07/05/13 13:04:06.62]: ADDriver: unauthenticated connection to rootDSE succeeded
DirXML: [07/05/13 13:04:06.62]: ADDriver: read rootDSE information
DirXML: [07/05/13 13:04:06.76]: 
DirXML Log Event -------------------
    Driver  = \MYTREE\system\driverset1\ADDriver
    Thread  = Publisher Channel
    Level   = fatal
    Message = Exception caused by PublicationShim->start()

Resolution

Using the 32bit Remote Loader and Active Directory Driver can possibly be used to workaround the issue.

Another option is to only enable ASLR for application which support ASLR.

This have been reported to engineering, and might be changed in a future release.

Cause

NetIQ Identity Manager does not support ASLR.