Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeDNN Open Source...DNN Open Source...Provider and Extension ForumsProvider and Extension ForumsAuthenticationAuthenticationActive Directory 01.00.04.33298 Beta Active Directory 01.00.04.33298 Beta
Previous
 
Next
New Post
5/27/2008 10:38 PM
 

Mike,

thanks for your work on this. It is working better now.  However, at one time when I synched, it would sync Security and Distribution groups. (i would like to do this because i don't want to created duplicate groups (although slight difference in name) to get the group to sync.  currently, only security groups sync.  Is there a way to fix this? Or should I change my approach?

Tom

 
New Post
5/28/2008 1:34 AM
 

Hmmm I've read about this (it may have even been in the link I posted earlier) that when a search is done using TokenGroups that distribution groups aren't pulled in. I'll do some checking to see if there's a way to get that information as well.

 
New Post
6/2/2008 1:29 PM
 

TokenGroups is the best way to get security groups, including nested groups and the primary group, all in a single call. In the old days at least, getting distribution groups required recursing backward through the memberOf attribute. Not trivial. This is the kind of thing you might want to do after the rest of the login is completed. Or maybe do it as a scheduled once-a-day kind of thing at 3:00 AM. That would be sufficient for most things, I'd think. "You get partial access right now, but you don't get full access until tomorrow" would be okay for most of us, I imagine.

That said, this beta version fixed all of my problems. I now am huge strides further ahead of where I was on the weekend. Brilliant piece of work, Mike. I most certainly do appreciate it.

 
New Post
6/4/2008 3:20 PM
 

On Server 2008 with IIS 7 the provider fails @ the method DotNetNuke.Authentication.ActiveDirectory.Settings.CheckPipelineMode() with the error message "System.Runtime.InteropServices.COMException (0x80070005): Access is denied".  Looks like there should be a try/catch around something in this method and it should return a default value if it can't determine pipeline mode.  I've tryed running the app pool in both classic and integrated mode.  The pool runs as Network Service, which does have access to AD on our domain.  .NET is running in full trust mode.  Do I need to give something access to whatever the method above is trying to access?

 
New Post
6/5/2008 12:24 AM
 

Someone else had the same error message (but at a different spot) with Server 2008 but I've never been able to get a copy to test with so I can't recreate/debug the error. However I just did some google searching on the error and one suggestion (though not a good one imho) is to use an administrator account in the impersonation. I don't know if you can use that account in the AppPool or if it has to be used in the web.config impersonation line. Can you give that a try and let me know if it fixes it?

 
Previous
 
Next
HomeHomeDNN Open Source...DNN Open Source...Provider and Extension ForumsProvider and Extension ForumsAuthenticationAuthenticationActive Directory 01.00.04.33298 Beta Active Directory 01.00.04.33298 Beta


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out