Imanami Community

Join or create discussions about common issues and solutions.
Welcome to Imanami Community Sign in | Join | Help
in Search

DL owner unable to make changes to his list

Last post 11-29-2007, 9:07 PM by Robert Haaverson. 8 replies.
Sort Posts: Previous Next
  •  11-20-2007, 10:41 AM 425

    DL owner unable to make changes to his list

    We've had several cases where a user was unable to make changes to a DL's membership even though he's the owner. To solve this Sys Admins have had to explicitely grant te necessary permissions or did the add/change of the DL for the user.  Does granting a user DL ownership not automatically mean that user has full rights to maintain membership of that DL?

     Any ideas why this could happen? Thanks.

  •  11-20-2007, 3:21 PM 426 in reply to 425

    Re: DL owner unable to make changes to his list

    Hello henrychan,

     There is a setting in Active Directory that will need to be checked in order to allow the group owner/manager to update the membership list.  See attached screenshot.  The "Manager can update memberhsip list" checkbox has been added the feature list for consideration in the next release of WebDir 5.0.

  •  11-21-2007, 1:24 PM 427 in reply to 426

    Re: DL owner unable to make changes to his list

    Robin,

    We've had other users who were assigned DL ownership from within WebDir and they were able to add & delete members without having syadmins check the box in ADUC (what you refererred to). In order words they've had full self-service capability to manage their own DLs (one of the primary reasons for implementing WebDir) without IT's involvement.  I believe that's how WebDir is supposed to work so your response about the ADUC checkbox and inclusion of this feature in WebDir 5 is confusing me.

    The issue we're experiencing with a few users here and there and that's what we can't understand.  The majority of users are able to update their DL memberships without problems.

    Am I misunderstanding your response?

     

    Thanks,

    Henry

     

  •  11-26-2007, 8:12 AM 429 in reply to 427

    Re: DL owner unable to make changes to his list

    Hello Henry,

     Sorry, I misread the issue you are experiencing.  Are the users that can successfully manage their distribution list and the users that cannot manage their distribution list logging into the same virtual server? 

     

  •  11-27-2007, 10:01 AM 433 in reply to 429

    Re: DL owner unable to make changes to his list

    Robin,

     Yes, in this situation all users are in the same virtual server.  As I mentioned not all users experience the issue but this has now happened at least four times that we're aware of, when users call IT saying they're the owners of the DL and yet can't add/delete members.  The way we get around it is to grant them explicit permissions via ADUC which defeats the purpose of providing users with WebDir self-service.

    Any ideas? 

    Thanks,

    Henry

  •  11-27-2007, 10:11 AM 434 in reply to 433

    Re: DL owner unable to make changes to his list

    Hello Henry,

    Check the permissions given to the WebDir Service Account.  The WebDir Service account is used for delegating permissions to authenticated WebDir users.  You can locate the name of the account by opening WebDir's System Manager console.  Then select the "Directory" tab for the virtual server under the server node.  We recommend the account have Domain Admin rights within Active Directory to prevent permission issues that may occur. 

  •  11-27-2007, 10:31 AM 435 in reply to 433

    Re: DL owner unable to make changes to his list

    Hi Robin & Henry,

    Button visibility is controlled by WebDir, so if the buttons are not showing up it is probably not caused by service account permisions.  However, if the buttons are visible but the members are never added or removed then I would suspect service account permissions.

    Is the problem consistent or intermittent? For example, if User A is the owner of Group 1 and Group 2, is User A always unable to manage Group 1 or just sometimes?  Is User A able to manage Group B?  Are User A, Group 1 and group Group 2 int he same domain/forest? 

    --Robert

  •  11-28-2007, 11:15 AM 436 in reply to 435

    Re: DL owner unable to make changes to his list

    Hi Robin & Robert,

     

    Our WebDir service account is a member of Domain Admins.

    The problem doesn't happen for all users, just a couple. But for them it happns consistently with the problem DLs.

    We only have one forest and one domain.

     

    Thanks,

    Henry

  •  11-29-2007, 9:07 PM 438 in reply to 436

    Re: DL owner unable to make changes to his list

    WebDir matches the logged on user's DN to the group owner's DN to determine whether the Owner security rule applies.  For this problem to occur consistently with the same group and user, the user is either not specified in the ManagedBy attribute of the group or WebDir is failing to match them. 

     Either way, I think we can resolve this faster with a call to support.  Please call support 925-371-3000 option 3.

    --Robert
     

View as RSS news feed in XML
Powered by Community Server (Personal Edition), by Telligent Systems