The user files are missing "tcptunnel" on servers that had an ACL push done after the upgrade.
vs (after 8.6SP1)
If you manually put that back in, does it work ?
Adding the "tcptunnel" command like we had to do pre-8.6 allows for tcptunnel but breaks everything else, like in pre-8.6... It seems like a regression bug.
I forget what the changes were for this – in 8.5 i think we explicitly pushed this out no matter what and it didn’t act like the other command auths, but thought for 8.6 that behavior was going to change so it wouldn’t need to be there at all. either was seems like a problem… do you have a ticket open ?
Not yet - I will work on submitting a ticket this morning.
In 8.6 and 8.6 P1 - simply having the "Server.TCPTunnel" permission was needed to be able to use TCPTunnel, so no separate role was required.