Strange issue with group access

Greetings

Recently I’ve had a few calls from users that say they cannot modify an access group they are owners for and for people who have lost access to databases even though they are still in the group.

For example; We have a group called xyz. The owner of that group is xyzAdmin. A user is a member of xyzAdmin and has been able to edit the xyz group previously. They call to say they can no longer edit xyz. Looking in the Domino Directory they are still a member of xyzAdmin but that is not being picked up when they log in. Restarting the client does not fix the issue. Adding and removing the user from xyzAdmin and restarting the client does not fix the issue. Doing an updall -R does not fix the issue. Adding the user as an individual to the Owner allows them to edit the xyz group. The only way to fix the issue has been to delete the xyzAdmin group and recreate it with the same settings. This is also the resolution for users who have lost access to certain databases (recreate the access group and copy and paste the members back in).

We have recently upgraded to Domino 8.5.1FP3 (soon to be 8.5.2) and the clients are on 6.5.1 (soon to be 8.5.2). It’s like Domino or the client is not seeing all the groups a user is a member of. It seems to have only happened within the past couple of weeks and is random and intermittant. We have been on 8.5.1FP3 for at least a couple of months so it doesn’t appear to be related to the upgrade, although I’ve not seen anything like it when we were on 6.5.

Anyway it’s a bit of a mystery and was wondering if other s have seen anything like it or could point me towards some trouble shooting tips. I’ve already tried sh nlcache reset but it does not help. It’s very bizarre…

Cheers

Peter

Subject: fixup / updall

try running fixup and updall on your domino directory.

Subject: Been there done that

Hi There

Thank you for your response. Yep done fixup, compact and updall offline as well as updall -R online. No change.

Cheers

Subject: create new replica

try creating a new replica?

Subject: My last resort

Hi Paul

Thank you for your reply. Being names.nsf I wanted to leave that as a last resort, but if I can’t resolve it any other way then it may be my only option. I’ve got 40 servers that I would need to copy the new replica to.

Cheers Peter

Subject: We’ve also seen this…

This has started happening with us as well in a Notes/Domino 8.5.1 environment. An application that created ACL groups for mail-in databases stopped working due to the same issue (users listed in ACL group as admin but unable to edit). We found that getting the Notes admin to edit the group, change the Group type, save and close, re-edit, change the Group type back again, save and close, fixed the problem. Annoying and inexplicable but we can live with it due to the small number of groups involved.

Subject: Upgrading soon

We’ve scheduled in the upgrade to 8.5.2 (with IF1) in a couple of weeks, so will see if that resolves any of the issues.

Peter

Subject: Problem occured with 8.5.2

We have the problem since we upgraded from 8.5.1 to 8.5.2! Nothing proposed helps, only recreating the groups.