hi,
I have come across a bit of a challenge with identity Awareness.
We are using Identity Collector and identity sharing, with 4 gatewas acting as PDP, and several others as PEP.
A new access role was recently created, with access rule on a PEP gateway. this is currently in test, and will be moved to production if successful
For one user, this works just fine, and he gets the correct access.
For other users, they do not hit this access rule at all.
When i run a pep show user query usr <username>, i see that the new access role is not associated with the user at all.
Have tried running the pdp sync and pdp update on the PDP gateway closest to the PEP gateway, but the new access role is not associated at all with the user.
Is this because of the cache on the PDP gateway, as the users will log on again before the 24 hours expire, thus the cached identity is reused?
What would be a potential consequence if we reduce the time limit on the cache before entries are deleted?
The environment is R81.10 with jumbo t66 on top, and there are only appliances in the environment.
Any input here would be appreciated:)