This message was deleted.
# citrix-wem
s
This message was deleted.
j
Well that’s kind of strange - if you look in the wem console (legacy one) and run a resultant planning from there, same thing?? Anything been touched with group expansion etc? Looping in @Anthony Shi and @Sharp Guo
d
Hi, I think I found something. I enabled the debug logging and checked the log file.
09:13:26 Event -> HostDirectoryServicesController.RetrieveUserDirectoryServiceGroups() : Found cached user groups for user 'DOMAIN\ctx.test'. Using cached results.
I fully deleted the WEM cache on a test VDA and enabled the following option in the WEM console: Advanced Settings > Agent Options > Enable Cross Domains User Groups Search now it work…
💯 1
m
Good find in the debug logs. I had a similar situation happen with upgrading the WEM service agent from 2309.1 to 2310.1. The only security contexts a log on returned was 'Everyone' and the user ID. We rolled back to 2309 and by time the ticket bounced around Citrix support, the next time we tried upgrading the agent to 2310, it wasn't a problem. Really strange
s
upgrade to the same release and the issue is fixed? strange. do you clear the cache?
m
I did not clear the cache. Is that a best practice when an agent upgrade is performed?
s
the agent refreshes the cache according to your configuration. so it is not neede unless you want to make agents refresh it instantly.
m
I just encountered this again updating from WEM Service agent 2310 to 2312. Clearing and updating the cache alone did not fix the issue. I had to enable the agent setting Dennis mentioned above and re-clear the cache and refresh it. The odd thing is the image I updated to 2312 is used in two environments. Both environments use the Cloud based WEM Service as management. One of the environments had the problem and the other did not. Both environments use the same configuration set.
Quick update on this. With the "Enable cross domains user group search" option selected on my configuration set, I restarted the WEM Agent Host Service, refreshed the cache, and refreshed the agent settings. I didn't need to delete the cache database. My domain is flat, with one domain, one forest, and no trusts. The problem has spawned it self after updating the WEM Service agent, once with 2310 and now with 2312. I'm going to try uninstalling and re-installing the service agent and see if that clears up the issue.
s
there is a configuration for the Directory Services Timeout. The timeout value for directory services on the Agent Host machine, after which the agent uses its own internal cache of user group associations. The default value is 15000 milliseconds. Maybe you can increase it to make sure the agent can query the AD information.
There is the AD cache in the agent side. It will be refreshed every hours. You can clear it manually if needed. the database file is under C:\Program Files (x86)\Citrix\Workspace Environment Management Agent\Local Databases.
d
Yes, I’m aware of that. I already increased the timeout value. Regarding the cache, we use PVS, the WEM cache is located on the client cache drive. It’s getting refreshed at startup.