Lawson Security changes not taking effect

Author
Messages
Shaun C
Basic Member
Posts: 4
Basic Member
    We just upgraded to Lawson 10.0.6 and when I add or take away a ROLE in ISS it doesn't seem to be taking affect.  I cleared IOS cache and the server cache in LSA.  I've had it sit all night and in the morning still not in effect.  Once I bounce WAS then it finally will take and work.  I'm at a lost at this point.  The ROLE is showing in both ISS and LSA and ran a report in LSA and it also shows the ROLE is attached to user.  Then you go into Portal can't access forms.  If I bounce WAS it will finally work.
    Jimmy Chiu
    Veteran Member
    Posts: 641
    Veteran Member
      I had a case opened with Infor from Oct 2014 in regard to the same exact problem. I was pretty much given the run around and I gave up on this. My workaround is to use LSA to assign roles instead of ISS for Lawson side of the application. That will take effect within the default 15 mins (900 seconds) server cache refresh interval.

      This problem also applies to lsdump/lsload. If you do lsdump/lsload on security classes, it will throw you an XML error on the newly loaded class when you try to open it. Once you bounce the server, the newly loaded class becomes usable without the XML error.
      JimY
      Veteran Member
      Posts: 510
      Veteran Member
        We are on 10.0.6 and are not experiencing the same problem. Could it be your version of ISS? Did you open a ticket with Infor Support? Does this happen to employee's that are already set up or is it also happening to new setups? Thank you.
        Shaun C
        Basic Member
        Posts: 4
        Basic Member
          Infor Security Administrator 2.0 Build Version : 10.1.0.1428
          Our LSF is Version: 10.0.6.0.676
          Infor Ming.le Foundation 11.1.4.557
          We have a ticket open with Infor and did a webex and right now they are not able to duplicate the issue but a still researching. We also came to the conclusion of just using LSA for any changes etc. Still would like to know why ISS is not working unless I bounce the server in WAS.
          Jimmy Chiu
          Veteran Member
          Posts: 641
          Veteran Member
            In LSA, changes in role security are written to LDAP and lawson automatically check for changes every 900 seconds (default).
            In ISS, changes in role security are written to LDAP correctly. Verified by making changes in ISS then inquire in LSA. They are immediately written to LDAP. But when lawson automatically check for changes every 900 seconds, it fails to see there were any changes. So it's not checking against LDAP.

            So this lead me to think in LSA, it is writing to a cache storage that the automatic check uses and make adjustment accordingly but ISS does not updating this cache storage. This cache resides in websphere. When websphere get bounced, it refreshes the cache, then changes kick in.

            And Infor doesn't get it, so I just use LSA...
            ---