Hello,
We use Business Objects XI3 SP5. Our users and the BO server are in Domain A. They log in to Infoview with SSO. That works fine.
Now we want to migrate our users to Domain B. There is a full two-way trust between the two domains.
To accomplish that we added a AD group from Domain B in CMC under Authentication -> Windows AD.
Furthermore we modified the krb5.ini.
When a user now log in to Domain B en open the link to Infoview we see that single-sign-on tries to login the user, but gets the error that the user is not authorisied to use the application.
We checked that the new AD group has the proper right within BO ( CMC -> Applications).
I can see that the user that tried to log in is created within BO.
We used kinit to verify that kerberos works fine from a Domain B account.
When I manual tries to login I get an error that says the Active Directory Groups for the account cannot be retrieved. The same error I gets when I try to logon with the Desktop Intelligence tool on the server.
Since 1,5 year we see an error in the CMS trace log that says:
assert failure: (.\ADQueryEngine.cpp:375). (0 : WINAD: ADQueryEngine::Query() -- No short name!).
This log grows very fast with this error every day (20 MB in haf an hour).
I do’nt now if this has a realtion with our probleem.
We are now out of options. I hope someone can help us.
Regards,
Oscar