DA and Group Authentication

I have the following setup:

  • 5 Domino Domains

  • Each Domino domain runs an extended directory catalog on it’s server. The contents of each catalog is the aggregate of the remaining 4 domain address books. For example, on /DomainA, the Extended dircat would contain /DomainB, /DomainC, /DomainD, and /DomainE.

  • Directory Assistance is configured and Group Authentication is enabled for this extended directory catalog.

My problem is as follows. If I add a group from the extended directory catalog to a group in the primary Domino Address book, authentication fails.

For example, in /DomainA, I have a group called Domain Admins. In that group I have added admins for the local domain, and as well, I want to add the admin group from /DomainB. The problem is, is that this does not work. As well, the group from /DomainB is in the relavent fields in the Address Book of /DomainA, and in the ACL as well. Still I cannot be authenticated.

Is there something wrong with this setup?

Subject: DA and Group Authentication

see the Admin 6.5 Help:“Directory assistance and group lookups for database authorization”

Nesting groups used for database authorization

When authorizing database access, a server can search a group that is nested in a group listed in a database ACL, and search a group nested in the nested group, and so on, as long as all of the groups are located in the SAME directory.

If you enable “Group Authorization” for a secondary Domino Directory or an Extended Directory Catalog, a server always searches nested groups in the directory.

The last sentence of the first paragraph also applies in case you have setup directory assistance

axel