DNN Forums

Ask questions about your website to get help learning DNN and help resolve issues.

Problem with DNN AD provider

 1 Replies
 0 Subscribed to this topic
 40 Subscribed to this forum
Sort:
Author
Messages
Veteran Member
Posts: 1182
Veteran Member
MVP
MVP
You're an MVP!

Hi all,

I upgraded a site from DNN 7.4.2 to 8.0.4 (on the way to go to 9.4+).

The settings for the AD Provider are:

Enabled: [X]
Hide Login Controls: [ ]
Synchronze Role: [ ]
Synchronze Photo: [ ]
Enable Auto Login: [ ]
Do Not Automatically Create Users: [ ]
Enable Debug mode: [ ]
Provider: ASDIAuthenticationProvider
Authentication Type: Delegation
Root Domain: dc=intra,dc=local
Username: DOMAIN\Username
Password: **********
Email Domain: @somewhere.com
Default.domain: intra.local
Auto-login IP Address (Optional): 10.0.0.1-10.255.255.255
Allowed Serch Bots: gsa-crawler;MS Search 5.0 Robot

There are users that are not domain members, they access the intranet site via a WAF, and are not authenticated in the intranet. That is OK, and worked fine in 7.4.2 (and before).

After the upgrade, it did not auto-login the users from the internal IP addresses anymore. I activated the "Enable Auto Login" checkbox, and it worked again, but now, these external users can't login anymore. I need a quick solution to fix that, any ideas?

Happy DNNing!
Michael

Michael Tobisch
DNN★MVP

DNN Connect
Veteran Member
Posts: 1182
Veteran Member
MVP
MVP
You're an MVP!

Problem solved.

There is obviously a change in the logic of the provider settings:

  1. "Enable Auto Login" must be activated to take the IP-Address range into account
  2. If a client can't automatically login, it is not considered as anonymous, but gets a login-popup (from the Windows server, not a DNN Login)

After changing the IP-Address range and excluded the IP addresses of the WAF and the transfer domains, everything works fine.

Happy DNNing!
Michael

Michael Tobisch
DNN★MVP

DNN Connect

These Forums are for the discussion of the open source CMS DNN platform and ecosystem.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. If you have (suspected) security issues, please DO NOT post them in the forums but instead follow the official DNN security policy
  2. No Advertising. This includes the promotion of commercial and non-commercial products or services which are not directly related to DNN.
  3. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  4. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  5. No Flaming or Trolling.
  6. No Profanity, Racism, or Prejudice.
  7. Site Moderators have the final word on approving / removing a thread or post or comment.
  8. English language posting only, please.

Would you like to help us?

Awesome! Simply post in the forums using the link below and we'll get you started.

Get Involved