Zenworks App Objects rights Through User Group Assignment
Zenworks App Objects Rights Through User Group Assignment
We have been dealing with users randomly losing group-inherited file rights and un-associating / re-associating the user with the group from which those rights were granted has worked, but it still appears not to be permanent. TID 7002509 "Users losing rights (file or object) inherited from associated groups" seems to describe our problem, and using iManager instead of ConsoleOne for group associations seems to work for standard file rights. The ConsoleOne solution of clicking apply between each subtraction and addition of group membership as mentioned in the TID doesn't apply as these rights are randomly being lost, not necessarily at a point of changing the user's memberships.
Even though we find it more cumbersome and slower to work with memberships in iManager as opposed to ConsoleOne, we can do that and it works... sort of.
The problem we're still facing now is when adding or removing memberships in iManager, it doesn't take into account Zenworks Application Objects. We have app objects which give rights to users based on the files needed by the app object (such as SnAppShots). Many of these app objects are associated to users via groups. If we add a user to a group that is associated to an app object, iManager doesn't appear to push the app object's rights down to the user. Having to assign rights manually as a separate process just isn't a solution for us. Also, we'd need to have users lose those rights when removed from a group.
We'd like to get to the root of the problem with users losing rights randomly, but if ours is the problem in the TID mentioned above, then Novell Engineering already knows about this problem. We need a solution or at least a good work around for now.
Has anyone run into this? Is there something we're missing? Any assistance is greatly appreciated.
Thanks,
Dave
|