Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeDNN Open Source...DNN Open Source...Provider and Extension ForumsProvider and Extension ForumsAuthenticationAuthenticationRole Synchronization not synching rolesRole Synchronization not synching roles
Previous
 
Next
New Post
3/18/2009 11:29 AM
 

I setup an extranet type portal in DNN 4.9.1 that used AD role synchronization.  I verified that synchronization was working and started working on my site.  Other things drew me away from working on that particular portal and I continued updating DNN and the AD provider (I was actively working on other sites on the same install).  None fo the other sites on the host use role syncrhonization.  I am now using DNN 5.0.1 with the latest AD provider.

I went back to the extranet site yesterday and started actively working on it again.  I have 2 test users in two different Universal Security Groups: rubble is in "Web Sisters" and fudd is in "Web Associates."  Neither one of the users was getting their appropriate content - only content for "Registered Users."  After checking the Roles, I found that both were removed from their roles.  I can't say with certainty, but I think synchronization was still working on DNN 5.0.0.

I've tried the following and all have resulted in removing the user from the role (even after manual addition):

  1. Unchecked synchronize roles, added user to role, logged in and out several times, checked synchronize roles, and was removed
  2. Changed the setup username to a domain admin and repeated 1
  3. Adding user to group and logging out and back in

The only thing that has changed on the domain since going from 4.9.1 -> 5.0.0 -> 5.0.1 is upgrading our Exchange Server from 2003 to 2007.  We're using a Server 2008 domain, with both the forest and domain functional levels at their highest levels.

 
New Post
3/19/2009 11:23 AM
 

I had an additional thought on this:  is there some possibility that the LDAP query might not be returning the information?  If I knew the query it was performing, I could inspect the results and see if they were returning what I needed.

 
New Post
3/19/2009 4:04 PM
 

There was no difference in the provider from 4.9.1 to 5.0.0 (just minor changes to where the settings were stored in 5.0.0). The version in 5.0.1 had a minor change in role synchronization but that because users weren't being removed from DNN roles when they were removed from AD roles. There was never a problem that I know of adding users to roles. Could you do a test and try change the group to a Global Security Group. It shouldn't make a difference but it's worth a shot.

 
New Post
3/19/2009 4:20 PM
 

Mike,

I just solved the problem - and I chalk this one up to not thinking about the simplest solution first.  I grabbed jxplorer to start looking through the LDAP query from my remote server - which is joined to the domain via VPN - and found that it never returned anything.  It just timed out.  So, I started thing, "AH! Firewall!"  Finally, out of exasperation, I restarted the VPN client and everything started moving along.  I couldn't believe how dumb I was - I ran into this 4 months ago and never documented it.  So, I wrote a little PowerShell script that restarts the VPN connection every 24 hours.

But, this does bring up a question: can the AD provider remove you from a role if the query times out?  I imagine that, if you have role synchronization turned on and there's a role synchronization error (in this case a timeout), the provider removes you from the role.  If this assumption is correct, could the provider check for a timeout or...?

Maybe, one day when I have time (in my wildest dreams), I could find the place in the source where this occurs and make a suggestion.

 
New Post
4/30/2009 10:05 AM
 

I'm having the same problem but I am not utilizing a VPN between the DNN web server and the AD provider.  I can't honestly say I don't know if my site is having a timeout issue or not but I have a user that is a member of an AD group but they keep getting removed from it automatically in the DNN role that matches that same name. 

Does anyone have any ideas?

I'm kind of a novice so if it helps, I can provide the AD authentication version number I have installed if someone gave me a quick how-to.

Thanks!

 
Previous
 
Next
HomeHomeDNN Open Source...DNN Open Source...Provider and Extension ForumsProvider and Extension ForumsAuthenticationAuthenticationRole Synchronization not synching rolesRole Synchronization not synching roles


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out