14.1 - Provide Managed System Administrator Passwords

This section is relevant when you define a new Application or when you set a new Managed System Administrator in SailPoint.

The RACF Connector does not save the Managed System Administrator passwords in a file, as most of the other Connectors do.

When a new Managed System Administrator is defined in Application definition in IdentityIQ or in Source definition in IdentityNow, the Managed System Administrator password or phrase is required for verification, unless a protected user is defined as the Managed System Administrator. The Managed System Administrator User ID and password or phrase are sent from SailPoint to the RACF Connector where the password or phrase is verified. After verification, the password or phrase is not saved anywhere on the Connector's platform or in SailPoint.

Before setting the managed System Administrator user and password or phrase in SailPoint, ensure that the password or phrase of the user is not expired . If the password or phrase is expired, the password or phrase verification done by RACF Connector will fail. If a protected user is defined as the Managed System Administrator, add the ALLOW_ADMIN_WITHOUT_PSWD parameter to the RSSPARM with a value of Y.