Re: String in Web.config to specify AD connection

From: Joe Kaplan \(MVP - ADSI\) (joseph.e.kaplan_at_removethis.accenture.com)
Date: 04/11/05

  • Next message: Joseph MCAD: "Re: Main form and login form in different folders using Forms Auth"
    Date: Mon, 11 Apr 2005 15:59:23 -0500
    
    

    I'm not sure what either of these has to do with Windows authentication as
    it does not use LDAP or WinNT for authentication. Are you doing forms
    authentication against AD using LDAP?

    In any case, I'd suggest you discover the defaultNamingContext for your
    domain again by binding to RootDSE on your domain controller and reading the
    defaultNamingContext attribute. This will give you the new domain root.

    In general, you should never hard code that in an application but should
    always look it up dynamically from RootDSE.

    HTH,

    Joe K.

    "Frank00" <Frank00@discussions.microsoft.com> wrote in message
    news:19EBF957-08FE-4CE9-9E0B-24116FC02F7B@microsoft.com...
    >I run a .NET based portal product. I am using windows authentication.
    >This
    > mode of authentication and the string specifying the connection to AD is
    > specified in the application's web.config file. This portal has always
    > worked
    > fine, though recently, our infrastructure team changed our internal domain
    > name. Now I can no longer authenticate any users no matter how I change
    > the
    > connect string in the web.config file.
    >
    > For the purposes of this discussion my former domain name is 'abc.com' and
    > my new domain name is '123.abcdefghijklm.com'. The name of the server
    > housing AD is now 'DC1.123.abcdefghijklm.com'. The netbios name had to be
    > truncated to 15 characters to accommodate a couple NT4 servers and its new
    > designation is '123.abcdefghijk'.
    >
    > The previous connect string in web.config which worked with the old domain
    > name:
    > <code><add key="ADdns" value="LDAP://DC1.abc.com/DC=abc, DC=com;
    > WinNT://abc"/></code>
    >
    > I tried the following to accommodate the name change (domain and netBios):
    > <code><add key="ADdns"
    > value="LDAP://DC1.123.abcdefghijklm.com/DC=123.abcdefghijklm, DC=com;
    > WinNT://123.abcdefghijk"/></code>
    >
    > It didn't work. The application generates an error specifying the domain
    > cannot be contacted.
    >
    > Can anyone help me with this one?
    >


  • Next message: Joseph MCAD: "Re: Main form and login form in different folders using Forms Auth"

    Relevant Pages

    • Re: Directory Services, LDAP or similar
      ... In other projects, we managed the user authentication by creating tables that define all users and its allowed capacities, then the application queryies that data to verify if a user has access to some feature or not. ... The above ID and password are sent to the service at login time. ... They are using Novell eDirectory at the enterprise level; yes it's LDAP. ... We already do that for three different DB servers; ...
      (borland.public.delphi.non-technical)
    • Re: noob on slapd with sasl errors
      ... If I may share advice based on my own trials & tribulations with LDAP ... people who need network authentication and the current state of ... context of network authentication, LDAP really is just a protocol used ... I have no idea how sasl works and why it is needed here, or even more, ...
      (Ubuntu)
    • Re: Directory Services, LDAP or similar
      ... we managed the user authentication by creating tables ... The above ID and password are sent to the service at login ... Novell eDirectory at the enterprise level; yes it's LDAP. ... servers; ...
      (borland.public.delphi.non-technical)
    • No more logins after upgrade to deb 5.0
      ... After upgrading from Debian 4.x to 5.x without any further configuration attempts my LDAP Authentication configuration fails. ... If an LDAP Administrator resets that users password and/or as long their ldap password is not expired the user can login anywhere just fine. ...
      (Debian-User)
    • Re: Recommended strategy for providing access to web apps via Inte
      ... LDAP is an ugly solution on the public internet, ... These federated authentication protocols are designed to address these ... Co-author of "The .NET Developer's Guide to Directory Services Programming" ...
      (microsoft.public.windows.server.active_directory)