You are viewing limited content. For full access, please sign in.

Question

Question

Forms System Administrator user

asked on May 4, 2021 Show version history

Issue: on Forms Config page setting the Forms System Administrator to use an AD account outside of the domain where LFDS is located throws error.

Situation: a group of like entities formed an IT shared services company (IT) to provide services for the needs of all member entities.  Part of the services provided is Laserfiche Rio and Forms.  Each entity purchases their Laserfiche licensing through IT and the LFDS resides in the domain of IT (Domain A).  Each member also has their own domain.  There is a one way trust between Domain A and all other domains.  We are working with Domain H to change the configuration of Forms and trying to assign a Domain H user (H\user) that is an LFDS AD User assigned a full license, a member of the LFDS organization (LF_H) associated with Domain H, and is a member of an LFDS group (H Forms Group) with permissions to log into Domain H Forms.  When we try to save after setting H\user as Forms System Administrator, we get error:
"Cannot find the specified username in the Laserfiche Directory Server site.  Please check that the username is in the Directory Server and is a member of a group allowed to sign in to forms.  Also, verify that your Forms server has a valid license file and is registered properly in Laserfiche Directory Server.  Finally, ensure that Forms is authorized to view users from all appropriate organizations. [LFF3007-InvalidLFDSCredential]"

Currently, H\user can log into Forms and the repository, and we can view the user in LFDS and see that it is assigned a Full license and a member of the LF_H organization and the H Forms Group.  We can see the instance of Forms in LFDS and regenerated the license for Forms without any change in the behavior.  As a test, we tried multiple users from the H domain with the same results. We were able to assign a LFDS Laserfiche user as Forms System Administrator, but Domain H does not want to have LFDS LF users.

For another test, we tried to assign A\user as Forms System Administrator and the error changed that A\user did not have permissions to log in.  Looking at A\user in LFDS, we find A\user is a member of the Root organization and has a Full license assigned.  We put A\user into H Forms Group and tried again.  This time, the error pointed at the Organization membership.  We then moved A\user from Root into the LF_H organization and then were able to set them as Forms System Administrator.

Problem: It appears that a domain user must be a member of the domain where LFDS resides or have Bi-directional trust (unable to test this) between domains in order to be set as LF Forms System Administrator.  It also appears that Root uses cannot be used as the Forms System Administrator for sub organizations.

Request:  Since all users are vetted through LFDS, we would ask that if the user is in LFDS, has a license, is a member of a LFDS group with permissions to log into forms, and is a member of the Forms Organization or above (Root), that it be allowed to be set as Forms System Administrator.

 

As a side question, besides being able to do the initial login to forms before users are set up, does the Forms System Administrator account have any more rights/privilege's than a user with the System Administer role?  Does Forms use the Forms System Administrator account for any processes or functions?

1 0

Replies

replied on May 4, 2021

In my experience, the Forms System Admin defined in the config does not have any additional rights over another account set with the System Administrator Role. We commonly use a temporary service account created as a Repository User, even in Directory Server environments, even successfully de-licensing the account immediately after configuring forms.

So far, have never run into any issues syncing with the repository or DS afterwards. Seems the account is only used to create an initial Admin account and set things up, or restore access in the future if all access is lost.

1 0
You are not allowed to follow up in this post.

Sign in to reply to this post.