Video Screencast Help
Symantec to Separate Into Two Focused, Industry-Leading Technology Companies. Learn more.

IBM LDAP and DLP

Created: 03 May 2014 | 12 comments

It seems it is not possible to use the built-in ldap script if your base dn has spaces (per SYMC) with IBM LDAP...Can any one please share a sample script that might work for this?

Thanks.

Operating Systems:

Comments 12 CommentsJump to latest comment

yang_zhang's picture

We had run a testing for IBM LDAP, it worked finely.

What is the base DN you used?

If a forum post solves your problem, please flag it as a solution. If you like an article, blog post or download vote it up.
egar2029's picture

Thanks for responding. I should note that it creates the directory connection fine but when I attempt to create the ldap lookup (to pull attributes) it throws a java error. SYMC has told me there is an etrack on this.

As an example (note the spacing): Base DN=Acme Products Company, Subunit Acme company

pete_4u2002's picture

what is the DLP version and the jave error it shows up?

egar2029's picture

This is v11.6. 

Base DN looks like  "ou=acme test one,ou=acme two one,o=large acme,c=ac"

see etrack 3281783 ...apparently it's to be fixed in 12.5

Error:

12 Apr 2014 11:42:30,613- Thread: 21 SEVERE [com.vontu.enforce.workflow.attributes.AttributeLookupLoader] Error loading plugin [IBM_Test]

Cause:

java.lang.reflect.InvocationTargetException

com.vontu.directory.common.InitializationException: Could not connect to the LDAP server.

Reason: java.lang.NullPointerException

java.lang.reflect.InvocationTargetException

                at sun.reflect.NativeConstructorAccessorImpl.newInstance0(Native Method)

---

Please note that it does connect as I am able to add groups in a policy...just does not seem to work for the plugin to pull attributes.

DLP Solutions2's picture

Egar,

This is a known issue and I was the one who actually found this and sent it to SYMC. Unfortunately the only way to get around this is to not use the base DN and go one level higher than what you are using as the base DN. If your base DN has a space in it then it will not work.

dc=companyxyz,dc=corp

I am not 100% sure, but this issue may not exist in 12.0 also I think 12.5 just got released.

Hope this makes sense.

If this solves your questions please marked as solved.

Ronak

Please make sure to mark this as a solution

to your problem, when possible.

Ryan - DLP Techical Support's picture

The space in the DN is still a problem in DLP V12.0, 12.0.1. This has been resolved and verified fixed in 12.5.
 

egar2029's picture

Thanks. Do you have any insight around existing work arounds to get this to work?

Ryan - DLP Techical Support's picture

I believe that you can use %20 in the DN where you have a space in the name and this might work. Otherwise, I don't think there is one. You would need to rename your objects in AD with no spaces, or wait for 12.5 to drop.

DLP Solutions2's picture

I would be surprised is the %20 would work.. let us know if it does.

Please make sure to mark this as a solution

to your problem, when possible.

Ryan - DLP Techical Support's picture

Then you will have to wait for 12.5. I tested this in the beta and it was resolved.