Unlock a world of possibilities! Login now and discover the exclusive benefits awaiting you.
Nov 10, 2020 6:34:35 AM
Feb 5, 2015 9:18:47 AM
When opening AccessPoint, users are not seeing the correct documents even though they are part of the correct groups.
This article outlines how to start troubleshooting this scenario.
After attempting to open AccessPoint, open the web server log (under C:\ProgramData\QlikTech\WebServer\Log).
This should have an entry for when the Web Server contacts the QVS and issues a "GetAdminDocListForUser" request:
015-02-05 14:01:15.5244203 Information <Global method="GetAdminDocListForUser"><UserId>domain\user1</UserId><Type>1</Type><ExtendedDocInfo>1</ExtendedDocInfo><GroupList><string>group1</string></GroupList><GroupListIsNames>true</GroupListIsNames></Global>
The above line shows that user "domain\user1" is a member of "group1". The QVS then uses that information to respond with the appropriate list of documents that the user should be able to see.
The group in the "GetAdminDocListForUser" request can come from:
This can happen if the AccessPoint web application, hosted on QVWS or IIS, has attempted to contact the Directory Service Connector (DSC) but has not received any group information for the user.
Possible reasons for this:
Or it can be checked directly in the C:\ProgramData\QlikTech\WebServer\config.xml where this setting is stored.
This communication could fail for example if Siteminder is being used and intercepts the traffic.
Or if the Application pool account in IIS which runs the AccessPoint does not run as the same user as the other QlikView Services.
So if the group information is wrong, double check that the webticket request contains the correct groups, or none at all.
If no groups are supplied in the webticket request then the AccessPoint web application will instead contact the DSC to get the groups.
If this is the case, then check in the web server log on the line after the "GetAdminDocListForUser" request. This should contain a <DocList> response which should contain the correct documents. If that list does not contain the expected document then check on the QVS side.
For example, in the QMC, looking at the authorization for the document - is the correct group really assigned as a "Users Authorized to Access Document"?
NOTE: There is a performance improvement in the DSC processes to LDAPs which will be included in the 12.20 track and later related to group lookups.