'Unable to Verify the group name' when configuring Automated User Assignment for a remote Domain

book

Article ID: 100048653

calendar_today

Updated On:

Description

Error Message

 

Cause

The Trust in place between the DLO server Domain\Forest and the remote Domain\Forest, is a Transitive Trust.

The 'netgetdcname' API, used to query the remote Domain\Forest information can fail to enumerate correctly across Transitive Trusts.

 

Resolution

The issue was fully addressed in DLO 9.5.

The 'netgetdcname' API has now been replaced with 'DSGetDcName' API

 

A supported hotfix was made available for the earlier versions listed below. Please contact Veritas Technical Support if you need to obtain this fix, although it is recommended to upgrade to DLO 9.5 to resolve this issue. 

DLO Version(s):
DLO 9.3.2
DLO 9.3.3
DLO 9.4

Issue/Introduction

When configuring an Automated User Assignment (AUA) profile in Desktop and Laptop Option (DLO), the error 'Unable to Verify the group name' may be displayed. This occurs if reading the AD Group from a remote Domain\Forest, different to the Domain\Forest the DLO server is in. This will prevent the Profile being configured. This can occur even if there is a Two-Way Trust between the Domain\Forest.

Additional Information

ETrack: 3968873 JIRA: DLO-3455