We have configured LDAP in CAPAM and also many groups are imported from ActiveDirectory. We have given 30 min time to auto refresh the LDAP groups. It is happened previously since one year. but since one week it is not happening. We have checked the bind account password also. And it is working fine. We are able to connect LDAP from CAPAM console to import new groups. But auto refreshing only not working after the interval time. If we do refresh LDAP group manually then it is working for some groups and some groups are failed to refresh.
Please find the attached catelina.log logs by debug mode we have generated. And also find the session logs error below.
PAM-LDAP-0004: An exception ( [LDAP: error code 32 - 0000208D: NameErr: DSID-0310020A, problem 2001 (NO_OBJECT), data 0, best match of:
] ) occurred while processing LDAP group CN=Pam User,OU=PAM,OU=Permission Groups,DC=ncellvendor,DC=net,DC=np. LDAP sync for this group will be aborted.
CAPAM version: 3.2.6
Possibly what you describe is due to known issues e.g.
The LDAP importer hangs and prevents group imports, and refreshes until a reboot.
An error occurs importing an LDAP group.
which fixes are already included in the current product release.
Note, PAM r3.2.x is going EOL by end of April hence we recommend you upgrade your PAM appliances accordingly.
Should the issue remain, please do not hesitate to open a formal Support Case with us – provide us with the logs.bin file which will include relevant logs regarding the ldap import.