I had IDM30 installed on two NW6.5SP6 servers and Windows 2003 server, with
users, groups and passwords flowing from NDS to NDS ( IDV1 to IDV2 ) then to
AD, one way only, passwords were synched using Distribution passwords.
Everything seemed to be working quite Ok.

Last week I upgrared IDM to 3.5, drivers and all - including NMAS which is
now part of Secure Service 204 now, apparently. Now my passwords would not
synch, not even NDS to NDS - I am getting this error in a Subscriber status
log in IDV1 :

************************************************** ***************************
Message 1:
Wed Apr 11 14:47:13 EST 2007
Warning
<status event-id="pwd-publish" level="warning">Code(-8021) Unable to set
NMAS password, -1697 NMAS_E_INVALID_SPM_REQUEST.<operation-data>
<password-publish-status>
<association>{802149D5-FA95-d511-875B-00508BE7F62D}</association>
</password-publish-status>
</operation-data>
<application>DirXML</application>
<module>eDirectory_Driver</module>
<object-dn>\EMA_TREE\AME\Students\aaastud
(EMA\Students\aaastud)</object-dn>
<component>Publisher</component>
</status>
\EMA_TREE\EMA\Students\aaastud (EMA\Students\aaastud)


Message 2:
Wed Apr 11 14:47:13 EST 2007
Warning
<status event-id="pwd-publish" level="warning">Code(-8009) Error processing
&lt;modify-attr>: java.lang.NumberFormatException: For input string:
"".<application>DirXML</application>
<module>eDirectory_Driver</module>
<object-dn>\EMA_TREE\EMA\Students\aaastud
(EMA\Students\aaastud)</object-dn>
<component>Publisher</component>
</status>
\EMA_TREE\EMA\Students\aaastud (EMA\Students\aaastud)

************************************************** ***************************

If I uncheck "Use Distribution Password for password synchronization" in
IDV2 driver Server Variables ( IDM accepts passwords ( Publisher Channel )
then NDS passwords seem to synch Ok from IDV1 to IDV2, but still no password
change for AD user account, and no errors in the log file - password synch
status is 'not synched' on IDV2 for both NDS and AD passwords, though.

User attributes flow all the way through so it seems to me some kind of
problem with NMAS .. I doublechecked methods were updated as well ( although
NDS method only seems to have a description and no modules for some reason,
so it came up with 'not updated' for eDirectory on Windows which I did in
ConsoleOne. I also can not check password policies for IDV2 on Windows as
some password related tasks are missing in iManager on Windows server. I
only have Check Password Status, View Policy Assignments and Set UP there -
but no Password Policies or Password Synchronization. I did update iManager
to the latest .. 2.6SP3 and NMAS plugin in installed.

Any ideas what else I should check ?

Andrew