Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeDNN Open Source...DNN Open Source...Provider and Extension ForumsProvider and Extension ForumsAuthenticationAuthenticationSecurity Group No Longer SyncsSecurity Group No Longer Syncs
Previous
 
Next
New Post
5/8/2008 2:41 PM
 


  I am currently running DNN 4.7 with AD Authentication on a production server.  I have many  DNN portals running all using AD Auth. It has been working great for 1.5 years then last Thursday (May 1st  2008) one of the instances stopped sync'ing roles so everyone using that security role could no longer login. I had other security roles on that same portal instance continue to work so this obviously points some change made to those roles on the AD side of the fence, not the DNN side.

I do not have access to admin the AD roles so I always go through a Sys Admin to do so. My question is what do I tell him to look for specifically? 

I told him another security role that was still sync'ing correctly to compare against and he stated they looked the same as far as settings. I also did the obvious and double checked the names of the roles had not changed. The network environment has many AD servers so could of a MS patch messed it up -  I assume not since the other instances are still working correctly.

 

Any guidance would be much appreciated.

PS: For now I turned off Sync Roles on that portal and created a script to add them back.

Craig

 

 
New Post
5/12/2008 11:53 AM
 

At this point all I can think of is to check IIS logs/DNN event viewer logs/server event logs/etc. to see if they have any clues as to why that role is no longer synching.

 
New Post
5/22/2008 11:53 PM
 

Craig, I just posted a new beta with new role sync code. Could you test it and let me know if it works (http://www.dotnetnuke.com/Community/Forums/tabid/795/forumid/89/threadid/229419/scope/posts/Default.aspx)

 
New Post
5/23/2008 11:22 AM
 

Thanks Mike I will do that!

Also on my orginal post I stated that I had a few roles that all of a sudden stopped working while other roles where syncing just fine. I was told there was no differences in the settings but after further investigation we discovered the the working roles were Universal while the none working where Global distribution.  It seems like a no brainer to switch them to Universal but can you add any insight based on your knowledge level of AD. Any reason not to do it.  The bottom line I am a developer asking a System Admin to do something without having the knowledge to back up my claim of why. Thanks again.

 
New Post
5/23/2008 11:38 AM
 

You shouldn't have to switch them. I just checked mine on my test domain at home and all the groups are Global. I'd give the beta a try first to see if the groups now get sync'd first and then go from there.

 
Previous
 
Next
HomeHomeDNN Open Source...DNN Open Source...Provider and Extension ForumsProvider and Extension ForumsAuthenticationAuthenticationSecurity Group No Longer SyncsSecurity Group No Longer Syncs


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out