Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeDNN Open Source...DNN Open Source...Provider and Extension ForumsProvider and Extension ForumsAuthenticationAuthenticationRoles not being syncRoles not being sync
Previous
 
Next
New Post
6/19/2009 1:25 PM
 

Roles aren't being synced with AD.

I am running DNN 4.9.1 and AD Provider 1.5.x.x (downloaded and installed today).

I can login via AD fine to DNN but roles aren't synced.

Site was upgraded from early version of 4.3.

AD Groups are security groups.

Have tried unchecking and rechecking the sync roles checkbox, have cleared the cache.

Not doing impersonation.

At a lost, any suggestion?

Thanks,
Stuart


Hilbert Solutions, LLC
Owner, Hilbert Solutions, LLC
http://www.HilbertSolutions.com
A DNN Service Provider
From Module Development to DNN Upgrades, your one stop DNN Shop
 
New Post
6/19/2009 1:49 PM
 

You may have to go with impersonation Stuart. The original synchronization code (which was based on a lot of your 3.x sync code) had to be revamped because it wouldn't work with a Windows 2000 domain.

Edit: Oh, and how many AD groups/roles are we talking about here (including an average number of groups a user belongs to in the AD)

 
New Post
6/24/2009 4:22 PM
 

Mike,

Sorry for the delay.  I turned on impersonation and I am still not getting the role sync to work.

Here is the number of users in the roles:

Group                                                                  Total
Admin                                                                     4
Faculty                                                                    81
All(others) + Faculty + Admin    57 + 4 + 81 = 142

Do you think an upgrade to DNN 5.1 with the DNN 5.1 Authentication Provider might solve the issue?  I have seen other threads where something similiar has done the trick.

Thanks,
Stuart


Hilbert Solutions, LLC
Owner, Hilbert Solutions, LLC
http://www.HilbertSolutions.com
A DNN Service Provider
From Module Development to DNN Upgrades, your one stop DNN Shop
 
New Post
6/24/2009 5:22 PM
 

So it's just the Admin and Faculty that you're trying to pull across?

It's not so much the number of users in a role it's how many roles there are in the DNN site and how many groups (including parent groups) a user belongs to in the AD.

I'm going off of memory here but the role synch essentially works like this:

  1. Arraylist populated with all DNN roles
  2. Arraylist populated with all DNN roles user belongs to
  3. Arraylist populated with all AD groups user belongs to (this is including any parent groups of groups they belong to)
  4. #1 is compared against #3 to create an arraylist of matches.
  5. #4 is compared against #2 to find out what roles the user should or shouldn't be a part of.

I'm not sure if upgrading to 5.1 will make a difference as the role synching code hasn't changed since AD 01.00.05 but if you can setup a test install somewhere it might be worth a shot (in case it's something else entirely that's causing the problem). Stefan Cullman has sent me some code that he thinks should streamline the role synching but I haven't had a chance to look at it yet.

 
New Post
6/25/2009 11:07 AM
 

Been trying to do an upgrade to 5.1 but have been getting tons of errors.

To answer another question the users are only assigned to about 10 groups.

I would say that these groups that we are trying to sync are stored pretty far down the tree:  domain.test.edu/in/in-test/Groups

I have AD configured to point to just domain.test.edu for the user login.

Stuart

 


Hilbert Solutions, LLC
Owner, Hilbert Solutions, LLC
http://www.HilbertSolutions.com
A DNN Service Provider
From Module Development to DNN Upgrades, your one stop DNN Shop
 
Previous
 
Next
HomeHomeDNN Open Source...DNN Open Source...Provider and Extension ForumsProvider and Extension ForumsAuthenticationAuthenticationRoles not being syncRoles not being sync


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out