# Cannot Update password from Keycloak

**URL:** <https://forum.keycloak.org/t/cannot-update-password-from-keycloak/10796>\
**Category:** Miscellanaeous\
**Created:** [August 31, 2021, 9:12pm UTC](https://forum.keycloak.org/t/cannot-update-password-from-keycloak/10796 "2021-08-31T21:12:43Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![jsalameh](https://avatars.discourse-cdn.com/v4/letter/j/e36b37/32.png) [@jsalameh](https://forum.keycloak.org/u/jsalameh)\
**Post date:** [August 31, 2021, 9:12pm UTC](https://forum.keycloak.org/t/cannot-update-password-from-keycloak/10796/1 "2021-08-31T21:12:43Z")

</div>

Hello Everyone,

I wanted to see if I can get some help or if someone has come across this before. We currently have AWS Managed Active Directory setup for one of our regions. When a user from our Canadian region tried to reset their password from Keycloak, they get the following error: Could not modify attribute for DN[CN=user,CN=Users,DC=domain,DC=com]  
I have setup Enable Server-Side LDAPS for Your AWS Managed Microsoft AD Directory using the instructions in the following link: [How to Enable Server-Side LDAPS for Your AWS Managed Microsoft AD Directory | AWS Security Blog](https://aws.amazon.com/blogs/security/how-to-enable-ldaps-for-your-aws-microsoft-ad-directory/) and was able to confirm the LDAPS connection  
However, when I go to User Federation and setup LDAP for that Canada region. I keep getting an error when I want to add the Connection URL. It keeps telling that I have an issue with the Trust Store. I made sure that my certificates are up to date and I even add the certificate in the TrustStore but I have no luck.
