Small width layout Medium width layout Maximum width layout Small text Medium text Large text
     Search
Downloads Downloads Directory Directory Forums Forums Forge Forge Blogs Blogs        Marketplace Marketplace Careers Program Careers
Community › Forums Register  |  

$4.95 Windows Hosting at Webhost4life.com
  Need Help?  
Professional technical support for DotNetNuke is available from DotNetNuke Corporation.
 


  Ads  
Iron Speed Designer is a software development tool for building database, reporting, and forms applications for .NET without hand-coding.
 


  Sponsors  

Meet Our Sponsors

R2integrated - formerly bi4ce
Jango Studios - Skins, Modules and Hosting for DotNetNuke
eUKhost.com is commited to offer exceptional UK Windows Web Hosting solutions with quality 24x7 technical support.Our plans support ASP.Net, ASP, ASP.NET Ajax extensions, XML, MSSQL, MySQL, PHP,DNN, multiple domains and Shared SSL as standard.
SmarterTools
The Official Microsoft ASP.NET Website
Portal Webhosting - Hosting For Developers
 


DotNetNuke Forums
 
  Forum  DotNetNuke® Pro...  Authentication ...  Intro to Active Directory and DNN
Previous Previous
 
Next Next
New Post 5/31/2006 12:47 PM
User is offline Marc Calder
43 posts
www.worxoft.com
10th Ranked


Re: Intro to Active Directory and DNN 

I actually got AD/DNN group synchronization working (wonder of wonders).  I had to ensure that the DNN role name EXACTLY matched the AD group name *including the domain*.  So rather than having a DNN role called Developers, I needed to create a role called MYDOMAIN\Developers.  I came across this when I saw that all new AD-sourced DNN accounts were being created with the domain name prefixed to the user name. 

Hope that helps.


Marc Calder
www.worxoft.com
 
New Post 6/4/2006 2:06 PM
User is offline Edward Beck
190 posts
9th Ranked


Re: Intro to Active Directory and DNN 

Interesting that you had to include the domain name.  I did not in mine, and am worried about cross-domain overlap if any objects are named the same (only 1-2 are for me). 

The exact full name was the key for me to get this to work (security groups and OU's - I haven't tested DL's). 

 
New Post 6/6/2006 6:14 AM
User is offline Joseph Hamilton
29 posts
10th Ranked


Re: Intro to Active Directory and DNN 

I have a question...I went through all the steps up to un-commenting the web.config line, and I had set up a "Windows Logon" link on the main page...it's been working beautifully, but I wanted the auto-login now.  I uncommented the line, saved the file, and re-loaded, but we can't get the auto-login now.  It'll just act exactly the same as before.

Any ideas?

 
New Post 6/6/2006 3:10 PM
User is offline Edward Beck
190 posts
9th Ranked


Re: Intro to Active Directory and DNN 

for auto login, you'd need the IIS settings to use integrated windows, and remove anon from the windowssignin.aspx - this is for vers 4.x I believe and previous versions used a different setup (WinLogin.aspx).  I am finding out the hard way that many tips do not apply to 4.x based on .net 2.0 (such as RDudley's mixed mode fixes and others posted here). 

Once you have these set, basically forcing hte NTLM dialog, then add the site to the "Local Intranet Sites" (not trusted).  It should then auto-login when using a machine on the domain.  I had to undo this, because it kept logging me off as host and giving me errors on permissions (since my domain account only has admin rights, not host). 

Hope this helps.  I did not have to touch the webconfig file at all to get this working, so you may have to re-comment the settings you changed.  Tam has a post earlier that details the settings.

 
New Post 6/6/2006 4:15 PM
User is offline Edward Beck
190 posts
9th Ranked


Re: Intro to Active Directory and DNN 

I have noticed that between portals if the roles are not replicated, rights will not function properly.  I'm not sure if this is an issue with DNN rights controls or with AD synch. 

Case:

  • Both portal A & B use AD with Role Synch. 
  • User is in both portals
  • User is not admin in either site
  • Portal B has Role "Blogger" with Blog module on one page, and rights to edit (create blogs) set for role "Blogger" only (admin defaults in of course)
  • User signes in on portal A with AD credentials, then navigates to portal B
  • Portal B is already synched with AD and user, so he does not have to log in again, but continues working
  • On blog module, user can not create his blog - despite role assignment
  • User checks membership and blogger role does not show (not sure if it should if not public)
  • User logs off
  • User logs back on to Portal B directly
  • User then goes to blog page with module and can now edit/create his blog
  • user logs off and returns back to Portal A to log in there
  • User logs in portal A then navigates to Portal B
  • again - user remains logged in as expected, but now does not have rights to blog

This implies that rights follow based on the portal logged into first (session). Not sure if this is by design with the new membership in 4.x, but this is what I observe.  Once I replicate the role of "Blogger" to Portal A, then everything works on teh blog module for his rights as expected, regardless of where he first logged in.  

This is an issue only in the fact that different portals will provide different roles for each user (I assume).  I am thinking of turning off the role synch - since it doesn't really provide much in my case, and I have seen reported issues of non-AD roles getting stripped, but I have not seen that so far. 

Hope this helps. 

 
Previous Previous
 
Next Next
  Forum  DotNetNuke® Pro...  Authentication ...  Intro to Active Directory and DNN
 


Forum Policy

These Discussion Forums are dedicated to the discussion of the DotNetNuke Web Application Framework.

For the benefit of the community and to protect the integrity of the project, please observe the following posting guidelines:

1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DotNetNuke.
2. Discussion or promotion of DotNetNuke product releases under a different brand name are strictly prohibited.
3. No Flaming or Trolling.
4. No Profanity, Racism, or Prejudice.
5. Site Moderators have the final word on approving/removing a thread or post or comment.
6. English language posting only, please.

 


Cygnusoft Custom Software
Cygnusoft has been providing cutting-edge custom software solutions for 20 years. Cygnusoft is also a leading start-up incubator, helping our partners build successful new businesses.
www.cygnusoft.com
Digicon: DotNetNuke design and development
Digicon is based in Brisbane, Queensland, Australia
digicon.com.au
Live Visitor Tracking & Live Chat For DotNetNuke
Track your visitors in real time and add live chat for sales & support. Free Trial.
www.whoson.com

DotNetNuke Corporation   Terms Of Use  Privacy Statement
DotNetNuke®, DNN®, and the DotNetNuke logo are trademarks of DotNetNuke Corporation
Hosted by MaximumASP