Configuring pwdkeeplastauthtime in ODSEE 7.0 Fails With Error "The entry cn=Password Policy,cn=config in file /pathTo/dse.ldif is invalid (error 53: DSA is unwilling to perform)" (Doc ID 1437284.1)

Last updated on OCTOBER 01, 2016

Applies to:

Oracle Directory Server Enterprise Edition - Version 6.0 to 11.1.1.5.0 [Release 6.0 to 11gR1]
Information in this document applies to any platform.
***Checked for relevance on 23-Oct-2013***

Symptoms


On : 7.0 version, Configuration

When attempting to configure pwdkeeplastauthtime,
the following error occurs.

ERROR
-----------------------
[26/Jan/2012:22:20:24 -0500] - ERROR<4131> - Bootstrap config - conn=-1 op=-1 msgId=-1 - System error The entry cn=Password Policy,cn=config in file /iplanet/odsee/odstestint/config/dse.ldif is invalid (error 53: DSA is unwilling to perform) - (Password Policy: initialize default policy object) "pwdKeepLastAuthTime: TRUE" is not supported in server mode DS5-compatible-mode ("cn=config" pwdCompat: 0).
[26/Jan/2012:22:20:24 -0500] - ERROR<4128> - Bootstrap config - conn=-1 op=-1 msgId=-1 - Configuration error Could not load configuration file dse.ldif.
[26/Jan/2012:22:20:24 -0500] - ERROR<4129> - Bootstrap config - conn=-1 op=-1 msgId=-1 - Configuration error Please edit the configuration file to correct the reported problems and then restart the server. Server exiting.


STEPS
-----------------------
The issue can be reproduced at will with the following steps:
1. Make sure server is in DS5-compatible-mode by running: dsconf get-server-prop pwd-compat-mode
2. Stop the server.
3. Configure pwdKeepLastAuthTime to a value of TRUE in the dse.ldif.
4. When attempting to start the server the error is logged in the errors log.

BUSINESS IMPACT
-----------------------
The issue has the following business impact:
Due to this issue, administrators/users cannot access the the pwdLastAuthTime value for each user (or the last time the user authenticated successfully).

Cause

Sign In with your My Oracle Support account

Don't have a My Oracle Support account? Click to get started

My Oracle Support provides customers with access to over a
Million Knowledge Articles and hundreds of Community platforms