Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeDNN Open Source...DNN Open Source...Provider and Extension ForumsProvider and Extension ForumsAuthenticationAuthenticationCombined Public and Active Directory portal - how to?Combined Public and Active Directory portal - how to?
Previous
 
Next
New Post
12/11/2007 6:31 PM
 

I'm working on a replacement for our public website. I want to accomplish the following with dotnetnuke 4.7.

- public users see our public content without being challenged to logon. public users can register and logon if they want to, we want to use this as a way for them to get to customer support content.

- local domain users are authenticated by active directory and automatically logged in, so they can see private content.

Everything I've tried results either in the public user being presented with an IIS logon box, or the private user having to manually login. Is there a way to make this work the way I want? I know I can do private and public on the same portal using DNN authentication but AD is giving me fits.

 
New Post
12/11/2007 11:51 PM
 

Hi Pepper, I've moved your thread over into the AD forum so that it's easier for me to keep track of (I get email notifications on posts to this forum).

Now to answer your question. At this time it isn't possible to get it to work the way that you want but there is a function that might help you in the next release (automatic login for IP address ranges). However as a work around you can do the following. Set up your site so that external users aren't geting the IIS logon box and then If you put links on your site that point to http://<yoursite>/desktopmodules/authenticationservices/activedirectory/windowssignin.aspx your internal users can just click on that link to get logged in. You can see what I mean here (http://www.bus.nait.ca/main/Resources/IDrive/tabid/58/Default.aspx). Even though that site is running the new version of the provider I've left the link there.

 
New Post
12/12/2007 8:25 AM
 

Mike,

How secure is the setup at NAIT?  How is the web server set up in the domain?  Is the web server in the DMZ?  I'm very interested in seeing how NAIT has set this up between their intranet and the public Internet.

My company would like to do exactly the same thing as the Original Poster, but the IT folks will not allow the the DMZ'd web server access to the Active Directory.  This is also the reason why I continue to ask about the LDAP auth provider, as that would be a good workaround (port 389 is not blocked).

Thank you for any help!

 

 
New Post
12/12/2007 6:16 PM
 

I can't speak to the security as I'm not part of the department that handles that but I do know that security consultants from MS were brought in to do an evaluation. The server is in the DMZ and on the domain but there's a security device either before it or between it and the rest of the network that limits where it can go.. It's not much help for you but it's how I understand its setup.

 
New Post
12/13/2007 8:41 AM
 

If it helps with your design questions, here is how I have it setup here:

The IIS server is on the internal network, and is part of the Domain. 

An ISA server sits on the Internet and the Internal domain, and functions as a publishing firewall.

The web server is published to the Internet through the ISA server.

Public (Internet) users can browse the website free of any login prompts.

Domain users can browse the website without logging in, and if desired they can click on one button and they are logged on using their domain account.  Note: This will change once the next release comes out, which will allow us to use auto-login.

 

 

 
Previous
 
Next
HomeHomeDNN Open Source...DNN Open Source...Provider and Extension ForumsProvider and Extension ForumsAuthenticationAuthenticationCombined Public and Active Directory portal - how to?Combined Public and Active Directory portal - how to?


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out