Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeDNN Open Source...DNN Open Source...Provider and Extension ForumsProvider and Extension ForumsAuthenticationAuthenticationNo automatic login (DNN 05.01.00, AD Provider 05.00.02)No automatic login (DNN 05.01.00, AD Provider 05.00.02)
Previous
 
Next
New Post
7/2/2009 6:51 PM
 

This is where I'm stuck too.

I have the AD authentication working, since users can log in with their domain accounts. The problem is they are not automatically logged in.

I've added the site to the trusted sites location and followed the other instructions in the documentation.  I have not commented out the AD authentication bit in web.config and I have changed the rights to the WindowsSignIn.aspx and also the folder that was previosuly mentioned but still no luck.  I have turned off impersonation as I found that didn't make any difference.

I'm also on Win2008 server.

Any help would be great, thanks :)

Marcus

 
New Post
7/3/2009 11:08 AM
 

Is anything getting written to the DNN Event log or anything popping up in your IIS logs?

 
New Post
7/6/2009 2:07 PM
 

Mike,

I posted the message from (DNN's) error log already, so there is no need to re-post it.

In the IIS log files, I found that there is an automated forward to WindowsSignin.aspx, and the DOMAIN\UserName appears in the log. I tested this with Classic and Integrated mode, both in full trust.

In the meantime, I found out that you posted something about this. You wrote:

[QUOTE from here]

  1. The IIS 6 Metabase Compatibilty needs to be installed (I installed all but the IIS 6 Management console). Otherwise an error appears on the Settings page an the provider is unable to test whether the site is running under the correct pipeline.
  2. Impersonation has to be used (see the documentation for instructions on using impersonation).
  3. The user used in the impersonation has to be part of the administators group on the server.

[/QUOTE]

Well, I do not like the idea in 1), but if it works...

... and I do not like the idea in 2), but if it works...

... but 3) is not acceptable. This would mean that every user has administrative rights on a server in the company's infrastructure. No, no, and again: NO.

Hope you can fix this. And the two others as well.

Best wishes
Michael


Michael Tobisch
DNN★MVP

dnn-Connect.org - The most vibrant community around the DNN-platform
 
New Post
7/6/2009 3:23 PM
 

Re: # 3.... No every user doesn't have admin rights. One user (the user account you use for the site to run under) has admin rights on the server. When you use impersonation in a web.config you can assign a single users credentials to it. All it does is change the site from running under NETWORK SERVICE to running under that single user.

I don't like #3 either by a long shot and am trying to find a more suitable solution to it but so far Server 2008 locks down permissions to a number of directories making it impossible to change the permissions on them.

For #1 and #2, I was working on a solution when I was coding the 05.00.02 release but it was causing some issues with the core code. Because the core code was in beta at the time and the architects were under a time crunch trying to get a release done and I was also under a time crunch because of breaking changes that affected the AD provider I didn't investigate it any further. I'm hoping to get some time in the next couple of weeks to revisit the problem.

 
New Post
7/6/2009 9:35 PM
 

hey Mike,

Thanks for the clarification. Mine works now.
I turned Impersonation back on (it was off since I didn't notice any difference) and also set the Classic App Pool. This was the important bit.
I hadn't set this already since I am very unused to the new IIS7 interface and it took a bit of fiddling. It turned out to be pretty much where the old version was in the end :)

To reassure the others on here, with impersonation on, the users still are detected as themselves and their own rights are carried through.

Thanks again, this is a great module :)

 
Previous
 
Next
HomeHomeDNN Open Source...DNN Open Source...Provider and Extension ForumsProvider and Extension ForumsAuthenticationAuthenticationNo automatic login (DNN 05.01.00, AD Provider 05.00.02)No automatic login (DNN 05.01.00, AD Provider 05.00.02)


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out