Your achievements

Level 1

0% to

Level 2

Tip /
Sign in

Sign in to Community

to gain points, level up, and earn exciting badges like the new
Bedrock Mission!

Learn more

View all

Sign in to view all badges

LDAP user sync - CanonicalName is null

Level 4
Level 4

I need to setup user sync from LDAP to LiveCycle. It seems to be very intuitive and easy, but ...

I can connect LDAP well, but no users are transfered. I found the LDAP query was OK and LDAP response was OK. LiveCycle complains about:

This record is missing a required attribute and cannot be used. Specifically CanonicalName is null. Common Name: Adam Agama

The LDAP entry is:

dn: cn=Adam Agama, ou=Users, o=My org,c=CZ

o: My org

givenName: Adam

sn: Agama

ou: Users


userCertificate;binary:: MIIIODCCB....

objectClass: top

objectClass: person

objectClass: organizationalPerson

objectClass: inetOrgPerson

objectClass: opencaEmailAddress

objectClass: pkiUser


cn: Adam Agama

What does the LiveCycle mean by CanonicalName? I have not seen such an attribute anywhere.

Any help would be appreciated.

--- Jaroslav Pavlicek
2 Replies
Level 4
Level 4
I reply myself:

When configuring LDAP connection, there are predefined templates for various LDAP types: SunOne, ActiveDirectory, IBM Domino, ...

You probably must select one. If you don't, "Unique identifier" field would not appear on following page and you are not allowed to edit it. And also you would have no idea, what the Unique identifier is expected to be 🙂
Level 4
Level 4
Hi Jaroslav

For more details on what constitutes a uniqueId have a look at

And canonical name => Unique Identifier.