Hi there,
I am wondering if anyone else has had an issue with their RBA after
upgrading. We recently upgraded from 8.7 Sp3 to 8.7 Sp5. Ever since
then anyone that has their LANDesk rights delegated via RBA has lost them
all. Any user who has their rights given via LANDesk implicitly is fine.
So far I have checked the COM+ accounts. I have even created a new
account that has full Domain Admin rights and entered it into both the COM+
areas fro LANDesk and LANDesk1. You can see that the users have their
rights implicitly applied when you look at them in the Users console.
We are getting by just now by delegating rights to specific users but would
like to have RBA back up and running again.
Thanks for any help/advice.
So are you saying you are using RBA and LDAP integration? The reason I ask is that you mention COM+ and Domain Credentials. There was a long post a couple of days ago about issues with nested AD groups by ryse and it turned out to be a multiple domain issue. AD Groups inside LANDesk Managment suite group
Could be an issue with the upgrade, not sure. So are there any error messages or are they simply without the rights?
Thanks for the quick reply zman.
Yes we are using RBA and LDAP interogation.
Users can log into both the 32bit Console and the Web Console with no issues.
The users simple have no rights. We had no error's during the entire upgrade and everything looked to be great. Infact even beetter than before. Systems that were failing to report back just started reporting today with nor problems now.
We followed the recommended upgrade path as defined in the LANDesk documentation.
I have looked through the post you are talking about. Thankfully we have a single domain.
We are assigning users their rights within LANDesk itself just now to get around the AD/LDAP issue.
Sorry have to ask but is the account used for LDAP integration valid and not locked out (Login to Active Directory in Users)?
Also is there anything of interest in the Console.exe.log or UserValidatorErrLog.txt logs?
I would have asked the sma equestion.
The account is fine. You can login to the server and view AD with no issues.
You can even see all the AD rights being assigned to the user profiles in the User tab in LANDesk. Why they are not being used is the $64k question.
As for the loggs. They do not have anything strange in them.
Sounds like you should open a case with support.
Just for S&Gs, remove all the rights from one user, logoff and back into the console, reapply the rights. See if that will help, howeverm I'm not confident that it will.
Also it will be interesting to RDP into the core and have one of the users who's rights are whacked login into the console and see if the rights are there.
An update.
I have opened a call for this issue. As soon as it is resolved I will post.
Thanks zman for all the help.
|
|||||