Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeDNN Open Source...DNN Open Source...Provider and Extension ForumsProvider and Extension ForumsAuthenticationAuthenticationSome Roles Not SynchronizingSome Roles Not Synchronizing
Previous
 
Next
New Post
5/4/2012 3:11 PM
 

Howdy!

I am using DNN 6.1.5 on Windows 2008 R2 server (IIS7.5). This is a new install on a new VM using Web Services Platform (with SQLExpress 2008).  I have downloaded and installed the AD authentication module (5.0.4).  I have followed the instructions to configure it (including the app pool settings, folder permissions, windowslogon.aspx, etc...). I am an old DNN warrior back in the 3.x and 4.x days.  But now I am trying to get back into the DNN world again.

Almost everything works,  AD logons are processed, accounts are created dynamically, etc..  My problem is with role synchronization (which I have enabled in the module settings).  I have three roles:

Domain Users

CE-S Web Site Staff

CE-S Web Site Faculty

I have created these three Security Roles within DNN - I have triple checked the names.  These are all Global Security Groups in AD (the Domain Users is the built-in group). I am using a test account that is a member of the first two groups (in essence a staff user), but not the third.  When I logon with the test account, the user account is created within DNN, but I am only put in the 'Domain Users' role.

Since I am put into the Domain Users role, I can rule out underlying connectivity and site\module settings.  But for the life of me I cannot understand the difference between the groups (other than one was built-in to Windows and the others were created by me).

I've looked through the forums and not found anything too helpful so far (the issues were not applicable to my situation for one reason or another).

Thanks in advance.


 
New Post
5/4/2012 3:24 PM
 
When you look at the group properties using the Active Directory Users and Computers mmc, under the General tab, is the pre-Windows 2000 name the same as you've posted above? When they're not is the only time I've seen role synchronization go sideways.
 
New Post
5/4/2012 6:02 PM
 
Yes. As a matter of fact, after it first failed, I cut and paste the name(s) from the pre-windows 2000 field into the DNN groups page just to make sure there wasn't anything funny that I was not seeing in the name.
 
New Post
5/4/2012 6:05 PM
 
Al three groups are in the same active directory container (Users) in case that was your next question. :) They all have the same security permissions, also.
 
New Post
5/7/2012 9:56 AM
 
I think I have fixed my situation. It appears to work correctly when I use the LDAP method of specifying the domain instead of the dc=domain method. I got it working by pointing the LDAP string to my specific AD domain controller (LDAP://server.domain.com).

I am not sure why this works.

I am in a large university setting. My department is a sub-domain from the forest root (the university itself is the forest root). This may be a clue.
 
Previous
 
Next
HomeHomeDNN Open Source...DNN Open Source...Provider and Extension ForumsProvider and Extension ForumsAuthenticationAuthenticationSome Roles Not SynchronizingSome Roles Not Synchronizing


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out