Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeDNN Open Source...DNN Open Source...Provider and Extension ForumsProvider and Extension ForumsAuthenticationAuthenticationAD Authentication from web DMZAD Authentication from web DMZ
Previous
 
Next
New Post
1/11/2012 4:21 PM
 
DNN 6.01.02, AD 5.0.2, Server 2003, SQL 2005.  

When the site was on a development box (Domain Member), connected AD with basic settings, worked fine.

Moved site to production server (non-domain member).  User has read only right to the domain.  Made impersonation changes as outlined (page 5 Users Guide).  For testing, we opened the firewall from web DMZ to the network (allow any both ways), can telnet from web server to domain on port 389.

Also tried Authentication Type 'None'. 

We get error, Fail accessing GC, checking root domain, and accessing LDAP, can not access LDAP.

Any ideas would be excellent.  Thank you.

-Jeff
 
New Post
1/13/2012 3:19 PM
 
Hi Jeff

When you setup impersonation were you able to use a domain user? It's been my personal experience that unless the web server was on the domain it could access the AD. However that was always (I assumed) because the account that was trying to read the AD wasn't a domain user.
 
New Post
1/13/2012 6:18 PM
 

While the user on the server is not literally a domain user, I did create the local user account as the same username and password the same as the domain user that is configured in the AD module and of course is the same user that makes AD Auth work on the development server.  This is not a 'real' domain user though, this is an old XP workgroup networking trick that shouldn't work in a domain environment.

 
New Post
1/13/2012 6:21 PM
 
Yeah, I know what you're talking about (I use it myself) but I don't think it'll work with the AD. You could try a program called LDAPBrowser (http://ldapbrowser.com) and see if it'll let you browse the AD using the same credentials that you're using for impersonation.
 
New Post
1/13/2012 6:33 PM
 

I appreciate your feedback.  I'll check out that program as well as other alternatives.

Thanks for your work on this project.

 
Previous
 
Next
HomeHomeDNN Open Source...DNN Open Source...Provider and Extension ForumsProvider and Extension ForumsAuthenticationAuthenticationAD Authentication from web DMZAD Authentication from web DMZ


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out