Solved

Nested groups over two directories are not working

Posted on 2011-02-16
6
779 Views
Last Modified: 2013-12-18
In our environment, we have two directories (names1.nsf and names2.nsf) and one directory assistance (da.nsf).
Now in the second directory (names2.nsf) we've a  group (azerty)  who has as member another group (qwerty, one from the first  directory names1.nsf).
The database authorization isn't working for members from the group qwerty (the group from names1.nsf).
Does anyone has a workaround for this problem.
I know that it's a known limitation.
Notes "When authorizing database access, a server can search a group that is nested in a group listed in a database ACL, and search a group nested in the nested group, and so on, as long as all the groups are located in the same directory."
0
Comment
Question by:clomb
6 Comments
 
LVL 22

Assisted Solution

by:mbonaci
mbonaci earned 250 total points
ID: 34906096
AFAIK, there's no way around it.

Can I ask, why do you have two NABs?
0
 
LVL 31

Accepted Solution

by:
qwaletee earned 250 total points
ID: 34912229
Simply list both groups independently in the ACL.Alternatively, create a script so azerty is mirrored in the other directory.

"azerty..."  I guess you are French.
0
 

Author Comment

by:clomb
ID: 34913699
mbonaci,
We want two NAB for separating the groups.
One NAB is for all the persons and for the department (groups), the other is for creating groups that we'll use for our notes app or for our websphere portal.
Also the security is not the same for the two NAB's, the persons who may create new docs are not the same in both NAB's.
Plus extra advantages..............

qwaletee,
List both independently is not a solution, most of the time the two groups are the same.
In the ACL we only use groups, there fore we create for each app several groups.
The responsible can then update the groups and give the people extra rights.
Create a script is one of the possible solutions but we thought may be there is a solution with changing settings so that it isn't necessary to write a script.
PS I'm dutch
0
Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

 
LVL 22

Expert Comment

by:mbonaci
ID: 34914073
Separating the groups in two NABs just because they are going to be used for different purposes is IMHO not a real reason for two NABs.
I would instead use some kind of prefix for group names, depending on their purpose/place of usage.

As far as security is concerned, I'd rather use Extended ACL then two NABs:

http://publib.boulder.ibm.com/infocenter/domhelp/v8r0/topic/com.ibm.help.domino.admin85.doc/H_EXTENDED_ACLS_OVER.html

Which other advantages? Any crucial ones?
0
 
LVL 10

Expert Comment

by:larsberntrop
ID: 34916077
how is the directory assistence setup?
0
 

Author Comment

by:clomb
ID: 35082918
sorry for the late answer. But for avoiding problems, we've put everything (groups and persons) in one addressbook.

0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Notes Document Link used by IBM Notes is a link file which aids in the sharing of links to documents in email and webpages. The posts describe the importance and steps to create a Lotus Notes NDL file in brief.
Article by: Rob
Notes 8.5 Archiving Steps and Tips This article covers setting up a Notes archive, and helps understand some of the menu choices making setting up and maintaining a Notes archive file easier.
This tutorial demonstrates a quick way of adding group price to multiple Magento products.
A short film showing how OnPage and Connectwise integration works.

932 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now