Effective Access dialogue - strange problem

There are more Domino Administrators (lets say A1, A2, A3,…) with the same group membership and similar access to Domino system databases.

For A1 - the effective access dialogue lists group membership of the analyzed user (this si expeceted and correct behaviour)

For A2 - the effective acces dialogue lists group membership for every other users except A2! Only his name (without group membership resp. roles) is showed for A2!

This issue was reproduced from more different PC’s and more different ACL’s of databases… Did you see something similar? Waht could be root of problem?

Thanks in advance…

Subject: > John: 9.0.1…

Release 9.0.1

Revision 20131022.1138 (Release 9.0.1)
Standard Configuration
L-GHUS-968PRV

Subject: Domino Directory Server

Are all the Notes Clients pointing to the same Domino Directory Server? It’s specified in the Location Record under Servers Tab…

If Domino Directory Server not specified it uses the Directory on the Mail Server if Mail Server is specified.

Make sure all clients are using an Online Connection so they can reach either a Directory Server or Mail Server.

What Notes Client Version are you running?

jpaganet@us.ibm.com

Subject: I’ve only seen one oddity in the effective access dialog.

I’m struggling to know exactly what you’re observing. Could you tell me, what are A1, A2? Are they person names?

Next, by “same group membership”, you mean they’re members in identical groups in the NAB?

Are either listed individually elsewhere, such as in “administrator access” on the Server doc?

In any event, here is the oddity I ran into with the Effective Access dialog: when the group is listed as a “person group” and the capitalization isn’t the same on an ACL as it is in the group, the Effective Access dialog can miss the group. I’m not entirely sure what the exact situation is, but I found it was pretty easy to reproduce. The group name I ran into, it was all alphabetics & spaces. The group itself was listed as “multi-purpose” on the NAB.

Subject: John, thanks for answer, but…

…unfortunatelly - it’s not related to Location settings as we are testing this behaviour from the same Location settings:

We are simple switching via File-Security - Switch ID between A1 and A2 and effective access results are different!

P.S: Environment is IBM Notes/Administrator R9.0.1 standard client on Win64

Subject: Explained…

Mike, thank you for sharing your experience - however, our problem was not related to person vs group duplicity…

After deep investigation, we have found out that:

When the administrator A2 was lisetd in Full Acces Administration of Server document, the effective Access dialogue for him (A2), didn’t show his group membership.

For every other analyzed user (even the other Full Access Administrator) the Effective Access dialogue showed group membership!.

Note: The Full Access mode was node enabled during this observation…

Really strange, but reproducible (at least at our Domino system) :slight_smile:

Subject: What Version of Notes Client are you using?

jpaganet@us.ibm.com