Change Internet Password with Directory Assistance enabled

Hi

I have a web server which has DA enabled to look up the internal users. When we use the “force users to change password” setting, they are prompted for the change and the change is accepted however in the Admin Requests log on the external server we have a failed process and the error below:

Error: A person document for either the request’s signer or the ‘Name(s) acted upon’ was not found in any local trusted directories for which this server is the Administration Server.

I understand why this is happening however as the servers are in different domains, we aren’t replicating the admin4 database and don’t want to set the admin server to be the same on both names.nsf databases. They need to be different for each domain.

Can anyone assist?

Also, if anyone knows how to apply internet password quality then that would be helpful also.

Thanks Steven

Subject: Cross Domain…

Hi

I am assuming you already have Cross certificate enabled between those servers. I think you are missing the Cross Domain configuration in your admin4.nsf databases.

You just nened to create a document with the other domain and the things its allowed to “order” to the adminp.

Subject: Re: Cross Domain…

Thanks for your help and yes I was missing the cross domain config. However I have them created and I notice that there is actually no “change http password” option therefore I have tried the “rename person” but I’m still getting a error. The 2 servers I am trying this with can connect and have the cross certificates etc so connectivity is fine.

Any other ideas?

Subject: …

Now that I see the error again, does the second names have the Current Server listed as the Administration Server in the ACL? It’s in advanced.

Subject: 2nd acl

No, because they both are admin servers for their respective domains. Just to summarise.

Ext Domain = Server 1 as admin

Int Domain = Server 2 as admin

Ext domain has Directory Assistance for Int domain and connects via Server 3.

Cross domain documents:

Outbound set in Ext Domain for Int Domain.

Inbound set in Int domain for Ext Domain.

User in Int domain only and reset http password set in Int domain.

User logs into Ext domain and is prompted for password change which Ext accepts new password.

Error within Ext Domain admin requests and console.

I can’t set the server 1 to be the admin server for Int Domain as 1) we don’t want too & 2) there is no connectivity between server 1 and server 3.

Thanks for your help.

Subject: same problem here, any solution?

Subject: SOLVED!

The problem was that some of the users persondocuments in names.nsf had 2 fields that caused the problem with Admin Process: Received the following error performing a Change HTTP Password in Domino Directory request on (Path: names.nsf): A person document for either the request’s signer or the ‘Name(s) acted upon’ was not found in any local trusted directories for which this server is the Administration Server.

When deleted the fields $ReplicaID and $ConflictAction from the persondocs the adminp worked as it should.