Nested groups over two directories are not working

Posted on 2011-02-16
Medium Priority
Last Modified: 2013-12-18
In our environment, we have two directories (names1.nsf and names2.nsf) and one directory assistance (da.nsf).
Now in the second directory (names2.nsf) we've a  group (azerty)  who has as member another group (qwerty, one from the first  directory names1.nsf).
The database authorization isn't working for members from the group qwerty (the group from names1.nsf).
Does anyone has a workaround for this problem.
I know that it's a known limitation.
Notes "When authorizing database access, a server can search a group that is nested in a group listed in a database ACL, and search a group nested in the nested group, and so on, as long as all the groups are located in the same directory."
Question by:clomb
LVL 22

Assisted Solution

mbonaci earned 1000 total points
ID: 34906096
AFAIK, there's no way around it.

Can I ask, why do you have two NABs?
LVL 31

Accepted Solution

qwaletee earned 1000 total points
ID: 34912229
Simply list both groups independently in the ACL.Alternatively, create a script so azerty is mirrored in the other directory.

"azerty..."  I guess you are French.

Author Comment

ID: 34913699
We want two NAB for separating the groups.
One NAB is for all the persons and for the department (groups), the other is for creating groups that we'll use for our notes app or for our websphere portal.
Also the security is not the same for the two NAB's, the persons who may create new docs are not the same in both NAB's.
Plus extra advantages..............

List both independently is not a solution, most of the time the two groups are the same.
In the ACL we only use groups, there fore we create for each app several groups.
The responsible can then update the groups and give the people extra rights.
Create a script is one of the possible solutions but we thought may be there is a solution with changing settings so that it isn't necessary to write a script.
PS I'm dutch
The 14th Annual Expert Award Winners

The results are in! Meet the top members of our 2017 Expert Awards. Congratulations to all who qualified!

LVL 22

Expert Comment

ID: 34914073
Separating the groups in two NABs just because they are going to be used for different purposes is IMHO not a real reason for two NABs.
I would instead use some kind of prefix for group names, depending on their purpose/place of usage.

As far as security is concerned, I'd rather use Extended ACL then two NABs:


Which other advantages? Any crucial ones?
LVL 11

Expert Comment

ID: 34916077
how is the directory assistence setup?

Author Comment

ID: 35082918
sorry for the late answer. But for avoiding problems, we've put everything (groups and persons) in one addressbook.


Featured Post

Upgrade your Question Security!

Your question, your audience. Choose who sees your identity—and your question—with question security.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

For Desktop Techs: How to retain a user's Notes configuration data when swapping out the end user's computer. (Assuming that you are not upgrading to a completely different version of Notes client) All you need to do is: 1) install Notes o…
Sometimes clients can lose connectivity with the Lotus Notes Domino Server, but there's not always an obvious answer as to why it happens.   Read this article to follow one of the first experiences I had with Lotus Notes on a client's machine, my…
In response to a need for security and privacy, and to continue fostering an environment members can turn to for support, solutions, and education, Experts Exchange has created anonymous question capabilities. This new feature is available to our Pr…
The video provides a quick and easy steps to migrate MBOX file to well known Outlook PST and Office 365. Besides this, it also supports and migrates more than 20 email clients of MBOX which include AppleMail, Opera, Thunderbird and SeaMonkey effortl…

621 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question