Do you want to set the access control on the log archive for authorized local computer groups? (NETIQKB72325)

  • 7772325
  • 19-May-2010
  • 19-May-2010

Environment

log archive server

Security manager 6x

Situation

Modifying or adding a log archive using the log archive configuration tool will result in the following pop-up ?Do you want to set the access control on the log archive for authorized local computer groups?.

Resolution

To test this, follow these steps:

 

  1. Go to the properties\security of the archive volume
  2. Add some local groups
  3. Remove the administrator and onepointconfigadmin
  4. Open the log archive configuration tool
  5. Modify one of the log archives
  6. Click yes on the ?Do you want to set the access control on the log archive for authorized local computer groups? popup box
  7. Restart the LAS service

 

 

Subsequently only the Administrators, OnePointOpConfigAdmins, and OnePointOpSystem should show up under the security tab of the archive volume.

Cause

It sets the ACL for the log archive volume.  If you click yes it will explicitly set the ACL to allow access for three local groups: Administrators, OnePointOpConfigAdmins, and OnePointOpSystem.  If you go to the properties of the archive volume\security tab, those three groups should be the only ones in the list.  If there was previously another group in the list, clicking yes will remove it. 

 

If you click no, the groups that are currently in the ACL of the log archive volume properties security tab will remain in place. 

Additional Information

Formerly known as NETIQKB72325