With OpenSSO Enterprise configured with the Access Manager SDK (AMSDK) plug-in, the session service assigned to a new role has a conflict resolution level attribute issue. Changing the conflict resolution level doesn't take effect on a user assigned with the role.
Workaround: Replace the cospriority attribute using a utility such as ldapmodify. For example:
ldapmodify -p 50389 -h dshost -D"cn=directory manager" -w dmpassword -c -f /tmp/mod
where /tmp/mod is:
dn:cn="cn=sfo1,dc=opensso,dc=java,dc=net", cn=iPlanetAMSessionService,dc=opensso,dc=java,dc=net changetype:modify replace:cospriority cospriority:4