Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeDNN Open Source...DNN Open Source...Provider and Extension ForumsProvider and Extension ForumsAuthenticationAuthenticationAD issue: random login request AD issue: random login request
Previous
 
Next
New Post
4/17/2009 8:44 AM
 

Hi to all,

On the intranet we developped (DNN 4.09) we have an AD authentication (provider 1.0.4) with AD group sync.
This has always worked fine on the test servers with a limited number of users. We put the intranet in the production environment yesterday and things started not going so well. We have about 300 users connected at the same time, and potentially 500.

People were randomly logged off the site, with the login window appearing. About 5 people out of 100 connected were calling for this issue. The only way to log back on was to manually log on again or to wait about 10 - 15 minutes and try again. These same people were able to navigate fine (with the sync working fine) before they got logged off.

After investigation on this forum, it seems that this problem might be due to the AD group sync. We have users who belong to potentially up to 20 AD groups and we have about 35 DNN roles.
After turning off the sync, it seems that the users to not get logged off anymore, but the problem is... there is no sync !!

Has anyone experienced the same issue and solved it ? Any clue would help a lot.

Thanks
Cheers

 

 

 
New Post
4/17/2009 11:30 AM
 

Is that 35 DNN roles with an additional 20 roles to match the AD groups or are the 20 AD groups part of that 35? There's a known issue when there gets to be around 50 roles to sync that I haven't found a way around yet. I'm looking at trying to make it a service for DNN 5 that will run in the background to sync the roles but haven't had time to flesh it out yet. Whether I can backport it to DNN 4.x is unknown.

You could also try the 01.00.05 release of the provider. I don't have my changelog handy but I did make some changes to the syncronization code at in that release.

 
New Post
4/23/2009 11:00 AM
 

Hi Mike, thanks for your answer.

I'll try to be clearer: on the site there is a total of 35 DNN roles, 7 of these roles can be synchronised with 7 AD security groups. The AD has a total of 750 groups (security groups + distribution lists) and each user can be part of up to 20 AD security groups.
The synchronisation is made so each user can be linked automatically to one DNN role so he is able to see a specific part of the intranet.
We have up to 650 users who connect to the site every day.

Having the synch disabled and the application pools of the site recycled 4 times a day seem to help a lot in the stability of our intranet.
So in the meantime, all new users are linked manually to the DNN roles instead of beeing synched automatically.

The ideal would be to have the sync run in the background like you mentionned, so I will be looking out for this update.
Otherwise, I will test the 01.00.05 release of the provider, but my main problem is that there is no way to test it in the same condition as in production.

 
Previous
 
Next
HomeHomeDNN Open Source...DNN Open Source...Provider and Extension ForumsProvider and Extension ForumsAuthenticationAuthenticationAD issue: random login request AD issue: random login request


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out