When logging into NSX with a vIDM user that is a member of multiple vIDM groups with different NSX defined roles applied, permissions from only one role is applied.
book
Article ID: 389963
calendar_today
Updated On:
Products
VMware NSX
Issue/Introduction
When logging into NSX with a user that belongs to multiple vIDM groups that have different NSX roles applied, permissions of only one of the NSX roles getting enforced.
No error occurs related to this, but expected NSX permissions may not be present.
Environment
VMware NSX before version 4.2
VMware Identity Manager
Cause
In the reported scenario, since VIDM groups were mapped to one NSX Role each, NSX creates two separate internal RoleBindings on root path '/'.
While consolidating the Roles for the user, only unique paths were considered along with the roles.
Because of this, the second role entry with the same root path '/' gets ignored.
Remove the extra role binding or group membership so only the needed role gets applied.
Additional Information
This issue needs DEBUG logging to properly identify. Please open a new support request if this confirmation is needed referencing this KB and assistance will be provided to gather the needed DEBUG logging prior to reproducing the issue.