Active Directory Password Synch Fails Connecting To OIM Over SSL (Doc ID 1202003.1)

Last updated on AUGUST 08, 2017

Applies to:

Identity Manager Connector - Version 9.1 and later
Information in this document applies to any platform.
Checked for Relevance on 10-Dec-2012

Symptoms

Active Directory Password Synchronization connector has been installed and configured on a domain controller. The connector can successfully access OIM over non-SSL, but when SSL is enabled the passwords fail to propagate from AD to OIM and the following messages appear in the log file:

Debug [8/17/2010 12:00:01 AM] Start getting config parameters from registry
Debug [8/17/2010 12:00:01 AM] oimhost is
Debug [8/17/2010 12:00:01 AM] oim.example.com
Debug [8/17/2010 12:00:01 AM]
Debug [8/17/2010 12:00:01 AM] oimport is
Debug [8/17/2010 12:00:01 AM] 7002
Debug [8/17/2010 12:00:01 AM]
Debug [8/17/2010 12:00:01 AM] oimsslclient is
Debug [8/17/2010 12:00:01 AM] oim.example.com
Debug [8/17/2010 12:00:01 AM]
Debug [8/17/2010 12:00:01 AM] oimuserattr is
Debug [8/17/2010 12:00:01 AM] Users.User ID
Debug [8/17/2010 12:00:01 AM]
Debug [8/17/2010 12:00:01 AM] oimusessl is
Debug [8/17/2010 12:00:01 AM] Y
Debug [8/17/2010 12:00:01 AM]
Debug [8/17/2010 12:00:01 AM] oimappservertype is
Debug [8/17/2010 12:00:01 AM] 1
...
Debug [8/17/2010 12:00:01 AM] /spmlws/OIMProvisioning
...
Debug [8/17/2010 12:00:02 AM] Inside sgsloidiOIMDownErrorHandler
...
Debug [8/17/2010 12:00:02 AM] MAX_RETRY LIMIT count is not updated: OIM is down


A message similar to the following may be logged to the Windows Event Log when this issue occurs:

Unable to update isr. The OIM SPML Web Service is unreachable. Please verify the availability of the web service or the configuration parameters. Unable to establish WinHttpSendRequest. Error Code: 12175



Cause

Sign In with your My Oracle Support account

Don't have a My Oracle Support account? Click to get started

My Oracle Support provides customers with access to over a
Million Knowledge Articles and hundreds of Community platforms