Symantec Management Platform (Notification Server)

 View Only
Expand all | Collapse all

Task Details Restricted for Users on Machines They Manage

Migration User

Migration UserFeb 01, 2011 11:45 AM

Migration User

Migration UserAug 10, 2011 06:59 PM

  • 1.  Task Details Restricted for Users on Machines They Manage

    Posted Jan 27, 2011 04:36 PM

    Our distributed IT personnel have full management rights to computers they manage rights applied to the AD import based organizational groups (right click AD Group then Manage Security > Assign Management Rights). These users are not admin users and all permissions are customized.

    When they run tasks on these machines and try to click the details icon of that task they are presented with the error "The user doesn't have permission to get this information." I investigated the NS logs and the error generated was this:

    <event date="Jan 27 21:23:07 +00:00" severity="1" hostName="NSNAME" source="Altiris.TaskManagement.ClientTask.*" module="w3wp.exe" process="w3wp" pid="25668" thread="301" tickCount="210929578"><![CDATA[BaseXmlHttpCallback Exception: Altiris.NS.Exceptions.AeXSecurityException: User doesn't have permission to view the computer related to this instance.

     

       at Altiris.TaskManagement.UI.XmlCallback.GetTaskInstanceDrilldown.WriteResponse(StringWriter sw)
       at Altiris.TaskManagement.Common.XmlHttp.BaseTextXmlHttpCallback.WriteResponseRaw(XmlTextWriter xwr)
       at Altiris.TaskManagement.Common.XmlHttp.BaseXmlHttpCallback.ProcessRequest(HttpContext context)]]></event>
     
    Thinking this may because permissions were assigned to one of the AD import groups, I moved one of the computers into a manually created Organizational Group and assigned full management rights but the error still persists. This does not make sense because the user clearly has full management rights to the computer (I double checked).
     
    Anyone have any ideas which permissions are needed to allow these users to view task detail information?


  • 2.  RE: Task Details Restricted for Users on Machines They Manage

    Posted Feb 01, 2011 11:45 AM

    Any thoughts on this before I contact support?



  • 3.  RE: Task Details Restricted for Users on Machines They Manage

    Posted Feb 01, 2011 12:21 PM

    I saw some crazy stuff awhile back in regards to specific dataclasses not being available to custom security roles. I believe this was for agent pushes, but even though the role had enough rights as checked, they would get denied by not having access to a hidden dataclass that only admins would have right too.

    I suspect it's something similar, but I have nothing concreate to offer, sorry.



  • 4.  RE: Task Details Restricted for Users on Machines They Manage

    Posted Feb 02, 2011 01:28 PM

    I am looking through these now and the most likely culprits at first blush seemed to be "Task Summary by Resource" and "Task Summary by Task."  However, the role I am looking at has read access to these so that can't be it.



  • 5.  RE: Task Details Restricted for Users on Machines They Manage

    Posted Mar 30, 2011 02:38 PM

    I'm having the same issue. I've given read and resource read access to everything that looks like it could be blocking this, but I still get the same error as above.

    Anybody find a solution for this?



  • 6.  RE: Task Details Restricted for Users on Machines They Manage

    Posted Apr 14, 2011 09:18 AM

    CMS 7.1

    "14.04.2011 14:43:48","BaseXmlHttpCallback Exception: Altiris.NS.Exceptions.AeXUnauthorizedAccessException: The current user does not have required permission 'read' to load item '37b0ac4c-bdc1-4fb8-ba4b-eaa1bff30ecb'.
       at Altiris.NS.ItemManagement.Item.RaiseItemLoadFlagsSecurityException(String message)
       at Altiris.NS.ItemManagement.Item.CheckCanGetItem(IItem item, IEnumerable`1 accessPermissions, ItemLoadFlags itemLoadFlags)
       at Altiris.NS.ItemManagement.Item.GetItemInternal(Guid itemGuid, IEnumerable`1 accessPermissions, ItemLoadFlags itemLoadFlags)
       at Altiris.NS.ItemManagement.Item.GetItem[T](Guid itemGuid, IEnumerable`1 accessPermissions, ItemLoadFlags itemLoadFlags)
       at Altiris.NS.ItemManagement.Item.GetItem[T](Guid itemGuid)
       at Altiris.NS.ItemManagement.Item.GetItem(Guid itemGuid)
       at Altiris.TaskManagement.ClientTask.BaseWeb.RegisterTaskServer.WriteResponse(XmlTextWriter wr)
       at Altiris.TaskManagement.Common.XmlHttp.BaseXmlXmlHttpCallback.WriteResponseRaw(XmlTextWriter xwr)
       at Altiris.TaskManagement.Common.XmlHttp.BaseXmlHttpCallback.ProcessRequest(HttpContext context)","Altiris.TaskManagement.ClientTask.*","w3wp","7"
     



  • 7.  RE: Task Details Restricted for Users on Machines They Manage
    Best Answer

    Posted Aug 09, 2011 10:12 AM

    I had this problem as well...

    Log File Name: C:\Windows\system32\Altiris Logs\a.log
    Priority: 1
    Help and Support:
    Date: 8/8/2011 3:20:09 PM
    Tick Count: 26696248
    Host Name: Process: w3wp (4480)
    Thread ID: 4
    Module: w3wp.exe
    Source: Altiris.TaskManagement.ClientTask.*
    Description: BaseXmlHttpCallback Exception: Altiris.NS.Exceptions.AeXUnauthorizedAccessException: The current user does not have required permission 'read' to load item 'Task Service (37b0ac4c-bdc1-4fb8-ba4b-eaa1bff30ecb)'.
       at Altiris.NS.ItemManagement.Item.RaiseItemLoadFlagsSecurityException(String message)
       at Altiris.NS.ItemManagement.Item.CheckCanGetItem(IItem item, IEnumerable`1 accessPermissions, ItemLoadFlags itemLoadFlags)
       at Altiris.NS.ItemManagement.Item.GetItemInternal(Guid itemGuid, IEnumerable`1 accessPermissions, ItemLoadFlags itemLoadFlags)
       at Altiris.NS.ItemManagement.Item.GetItem[T](Guid itemGuid, IEnumerable`1 accessPermissions, ItemLoadFlags itemLoadFlags)
       at Altiris.NS.ItemManagement.Item.GetItem[T](Guid itemGuid)
       at Altiris.NS.ItemManagement.Item.GetItem(Guid itemGuid)
       at Altiris.TaskManagement.ClientTask.BaseWeb.RegisterTaskServer.WriteResponse(XmlTextWriter wr)
       at Altiris.TaskManagement.Common.XmlHttp.BaseXmlXmlHttpCallback.WriteResponseRaw(XmlTextWriter xwr)
       at Altiris.TaskManagement.Common.XmlHttp.BaseXmlHttpCallback.ProcessRequest(HttpContext context)

     

    It turned out being a bad task service installed on two site servers.  I ran the task server install package manually and it removed the task service successfully and the log cleared up.
     



  • 8.  RE: Task Details Restricted for Users on Machines They Manage

    Posted Aug 10, 2011 06:59 PM

    Did you ever solve this issue?



  • 9.  RE: Task Details Restricted for Users on Machines They Manage

    Posted Aug 11, 2011 10:03 AM

    I did yes...the solution was at the end of my last post.



  • 10.  RE: Task Details Restricted for Users on Machines They Manage

    Posted Aug 15, 2011 12:36 PM

    MRenfrow, it looks like the error in your logs is different from powellbc. Are you suggesting that re-installing the task service on the task servers clears the error in the original post? How did you identify the two task servers that had the bad task service?



  • 11.  RE: Task Details Restricted for Users on Machines They Manage

    Posted Aug 31, 2011 04:36 PM

    We had to completey rebuild our NS last April, and in the process redeployed the task server agents to our site servers. It does seem to have fixed the problem!



  • 12.  RE: Task Details Restricted for Users on Machines They Manage

    Posted Aug 31, 2011 07:46 PM

    So might be simply fault task server agents then? I'd hate to rebuild my whole NS just to fix this problem. :(



  • 13.  RE: Task Details Restricted for Users on Machines They Manage

    Posted Sep 01, 2011 08:23 AM

    Hi EMercado,

    You should not need to rebuild the entire NS. Just use the Site Server management functions to remove the agents from all site servers, then redeploy your task agents one by one back to the site servers.

    We had to rebuild our NS for a different reason (out of control database), not because of this task issue. It's just that the rebuild led us to the same conclusion as MRenfrow above.

    Cheers,

    Bryan