Unable to create certificates using the nds2nds wizard - Error 613

  • 3503660
  • 17-Jan-2007
  • 19-Jun-2012

Environment

Novell Nsure Identity Manager 2.0
Novell Identity Manager 3.0
Novell iManager 2.6
eDirectory to eDirectory Driver
eDirectory 8.7.3
eDirectory 8.8

Situation

Unable to complete the nds2nds certificate creation wizard
"-613 Syntax Violation"

"Unable to create the certificates. The following error occurred: -613"
Cross-Signing Certificates using the nds2nds driver certificates wizard

Resolution

The wizard names the new certificate using the name of the driver object and will append (servername_kmo) - including the brackets, to the name. The maximum number of characters allowed is 46, otherwise the procedure will fail with a -613 syntax violation.


Ensure the resulting name will not exceed this limit before running the wizard, or follow the procedure to manually create the certificates found here.

Another workaround is to create two new temporary eDirectory drivers, one in each tree. Do not specify any valid information. Name the drivers different from the current drivers but something like TREEb-2-TREEa. Assign the drivers to the same servers and driver sets. Once the two drivers are created, run the certificate wizard for the two dummy drivers. Once the certificate wizard is completed, copy the Authentication ID field from the dummy driver in Tree A and put it into the eDirectory production driver's authentication ID for Tree A. Do the same for the driver in Tree B. Do not delete the newly created certificates. Delete the dummy drivers once verification of the production drivers working has been confirmed.

Additional Information

Formerly known as TID# 10094113