Hi everyone,
I’ve been renaming some users in order to move them to a new certifer (placed them in an OU).
I discovered that this can cause problems if a user is active during the process - it seems that the name gets changed first, and then the ACLs change later, so users can have problems opening databases for a while.
Anyway, this weekend I thought I’d be smart and rename some users on Friday evening. This way, I figured Adminp would have all weekend to make all the changes, and everything would be done by today (long weekend in Canada!).
Unfortunately, it seems that AdminP somehow uses the Notes client for doing the rename. The rename in the directory happened on Friday, but none of the other tasks (rename in ACL, rename in busytime, rename in calendar) started to complete until this morning. It’s now 8 hours later, and some of the users still have not been completely renamed. This is causing problems (for ex. accept a meeting request from one of these users, and you get a failure because the name exists twice in the directory).
So, I have a couple of questions:
-
is it possible to get the server to do the rename without the client being active (I can only assume that is why nothing happened till this morning)
-
is it possible to kickstart AdminP and make this process happen more quickly?
Also, I’ve come accross this;
http://www-10.lotus.com/ldd/nd6forum.nsf/55c38d716d632d9b8525689b005ba1c0/751d955b16cb2d5b85256e920057d72b?OpenDocument
and I think some users are experiencing this problem. It mentions re-signing the mail file as a fix. I’m not sure how to do this…do they mean using the ‘Files - Sign…’ menu in Administrator?
thanks,
Dan
Subject: Rename user - any way to speed up the process?
Dan, Check out the excellent diagram linked below from the admin help, I found it when I was on the same issue. It illustrates the problem, that the process is dependent on the user accepting the change. If this could be automated somehow, “tell adminp process all” and “tell adminp process time” might help speed the rest along:-jmw
http://www-12.lotus.com/ldd/doc/domino_notes/6.5.1/help65_admin.nsf/855dc7fcfd5fec9a85256b870069c0ab/69782c57bf1bf17b85256dff004b5cb0?OpenDocument&Highlight=0,rename
Subject: It’s like shampooing…
You know: lather, rinse, repeat
But in this case what you do is:
“tell adminp process all”
replicate (both names.nsf and admin4.nsf)
repeat
As far as I know the user must actively accept the intial name change before the rest of the name change process takes place. Once they accept the name change, you can ‘speed up’ things by using the above process.
Problem is, manually invoking adminp can be a drag on your server performance, plus, not all the adminp changes take place on the same server.
For example, the name change, and group updates, may take place on Server A, but mail file, ACL changes, etc. may happen on other servers. In other words, you might have to ‘lather, rinse, repeat’ on a lot of servers to get the process fully complete.
Luckily the Admin client makes this easy, because you can easily resend console commands to different servers, or send a command to multiple servers at once.
Subject: RE: It’s like shampooing…
Thanks guys.
Actually, with Notes 6.5, the user doesn’t have to accept the change…it seems that is optional now.
Anyway, I’ll try the ‘process all’ and see how it goes. All of the renaming is happening on one server, and the load is getting lighter this time of day so I’ll give it a try.
Subject: RE: It’s like shampooing…
Hello
Yes you are right, the acceptation is automatic but in order to be able to process, after the first request (rename in public address book), the user has to log on.
Then, AdminP creates a few other requests that executes depending on some parameters in the AdminP tab of the server document. You can set the delay there.
If you want to process requests quickly, you can use “tell adminP process all” as suggested, but you will have to do that a few times (3 times I think) because some requests are created only when the predecessors have finished and so you have to send a “tell adminp process all” command. You should have to replicate with your administration server too cause some requests executes on the administration server and some on the “end-user” server.
I use this to rename some people and it is transparent for the user. No need anymore to accept any name change. You can add a parameter in the notes client menus to prompt the user to accept the name change :
File - Security - User Security - Your Identity - Your Certificates - Other Actions - Request Name Changes - Accept Name Changes to your ID file
Hope this can help !
Gerald
Subject: RE: It’s like shampooing…
Right…that’s what I’m seeing. No response is needed, but the client still needs to login. (which seems a little redundant and silly, but oh well :))
Thanks for the tips. The ‘process all’ seems to make things much smoother.
In regard to this issue here:
http://www-10.lotus.com/ldd/nd6forum.nsf/55c38d716d632d9b8525689b005ba1c0/751d955b16cb2d5b85256e920057d72b?OpenDocument
Do you know what steps are being referred to when ‘re-signing’ the mail file?
thanks,
Dan
Subject: RE: It’s like shampooing…
In the Admin client, go to the files tab, select one or more databases, and from the Tools, choose the Sign utility. You’ll need to select either the Server ID or an ID with sufficient access to run agents, etc., and that will not cause ECL alerts in the Notes client.