Environment
NetIQ Access Manager 3.2.0
NetIQ Access Manager 3.2.1
NetIQ Access Manager 3.2.2
NetIQ Access Manager 4.0.0
NetIQ Access Manager 4.0.1
NetIQ Access Manager 3.2.1
NetIQ Access Manager 3.2.2
NetIQ Access Manager 4.0.0
NetIQ Access Manager 4.0.1
Situation
Lets say I want to have a user provisioned who's cn attribute is a single value such as: urn:oid:1.3.6.1.1.1.1.0. When configuring this in SAML 2.0 > Identity Provider > User Identification Method > Attribute Matching > Provisioning Settings, on step 3 of 5 Define user name creation, in Automatically create user name it is looking for values in 2 segments to create the user name during provisioning. If I configure Segment 1 with Attribute cn and length of "All", and Segment 2 with length of "0" as shown below, the end result will be a user being provisioned with a cn of urn:oid:1.3.6.1.1.1.1.0urn:oid:1.3.6.1.1.1.1.0.
Resolution
In the case where you only want one value as the user name, you need to
set Segment 1 with the length of "0" and use Segment 2 as the single
value. This should provision the user with cn of urn:oid:1.3.6.1.1.1.1.0.
Cause
This is a defect and has been reported to engineering
Bug Number
876637