Unable to set password or Sync password using IDM with LDIF imported password policy

  • 7022876
  • 23-Apr-2018
  • 23-Apr-2018

Environment

Identity Manager - Password Synchronization
iManager 2.7.7
eDirectory

Situation

Create new users in iManager, either directly in iManager, or through a PRD in UserApp, the user is created correctly but the Universal Password is not being set. After login to iManager with the created user, the Universal Password is set.
Also, running pwdiag on a user who is part of a corrupted universal password policy returns the error (-1658): 
-1658 FFFFF986 NMAS E MISSING KEY
Source: NMAS
Explanation: The key attribute for the Login Configuration attribute or the Login Secret attribute is missing or corrupt.

Resolution

Delete the password policy and recreate the password policy in iManager.

Cause

Creating a password policy by importing an LDIF of a password policy from another tree does not configure the password policy correctly.  Always use iManager to create password policies.