Active Directory question

Last post 02-16-2006 3:55 PM by codegalaxy. 3 replies.

Sort Posts:

  • Active Directory question

    02-16-2006, 10:50 AM
    • Contributor
      6,910 point Contributor
    • codegalaxy
    • Member since 06-29-2004, 1:00 PM
    • Topeka (Alma), Kansas
    • Posts 1,475

    I didn't find this in a search here so i'll ask and please direct me to the post if this has been answered.

    My portal is using AD authentication just fine except when I remove a user from AD - they can still log into the portal is this intended is there a way to remove them or unauthorize them if they try to login and AD doesnt find them anymore?

     

    Dylan Barber
    read my stupid blog http://codemypantsoff.com
    Pants Optional!
  • Re: Active Directory question

    02-16-2006, 3:37 PM
    • Participant
      1,025 point Participant
    • mzns1
    • Member since 10-11-2004, 8:43 PM
    • Ventura, CA
    • Posts 205

    Some thoughts....

    1. If the user originally had a DNN account & password BEFORE you turned on AD, then it seems that the use still knows their old password and therefore is simply logging in under forms authentication.
    2. AD authentication would have generated a random password for each user and then use the AD password for authentication.  Since the password would differ, then #1 could not occur.

    I am guessing that #1 is the case and, if so, we (the community) needs to do a couple tests to see what occurs under different configurations...

    mikez

  • Re: Active Directory question

    02-16-2006, 3:52 PM
    • Contributor
      6,910 point Contributor
    • codegalaxy
    • Member since 06-29-2004, 1:00 PM
    • Topeka (Alma), Kansas
    • Posts 1,475

    Good points!

    1. No new portal no previous accounts except host and admin.  Set up the portal went to my machine booted up went to the site and I was automatically logged in and the account was created.  Closed the browser went to AD and deleted the account I had used.  Went back to the machine logged in on different account logged out of the portal and tried to login as the deleted user.  Was able to login as the deleted user - logged in as host and the account is there and active.  The AD part seems to assign all the info from AD to the created portal account including the password. There seems to be no mechinism to deavate accounts if they are removed from AD.

    Is this how it should be ??

    Dylan Barber
    read my stupid blog http://codemypantsoff.com
    Pants Optional!
  • Re: Active Directory question

    02-16-2006, 3:55 PM
    • Contributor
      6,910 point Contributor
    • codegalaxy
    • Member since 06-29-2004, 1:00 PM
    • Topeka (Alma), Kansas
    • Posts 1,475

    I was never able to get the LDAP part to say it worked but the accounts seem to be created in the portal just fine - it could be possible there is something misconfigured so maybe people could give me an idea or two on things to check

    Dylan Barber
    read my stupid blog http://codemypantsoff.com
    Pants Optional!
Page 1 of 1 (4 items)