Software Portal won't display available packages using Domain groups, users work fine
search cancel

Software Portal won't display available packages using Domain groups, users work fine

book

Article ID: 152898

calendar_today

Updated On:

Products

Software Management Solution

Issue/Introduction

User unable to view any available packages in the Software Portal if access is defined using domain groups. If specific users are used available packages are available as expected.

Environment

Software Management Solution 7.0 SP2 MR2

Cause

The issue is caused by a particular method for AD users to logon to the domain.

For example, the domain can be dom1.mydomain.com with all their users & computers defined under the dom1 child domain. The mydomain domain is an empty domain with no defined users or computers, however their user names are defined as mydomain\User. So when the user mydomain\User1 attempts to access the Software Portal the following things occur.

1. We request the FQDN for the domain specified from AD using Microsoft's Directory Services .NET calls which returns mydomain.com
2. We then use the FQDN to perform an LDAP query to get the domain membership information for the user mydomain\User1.  The LDAP query created is

LDAP://mydomain.com(|(& (objectCategory=group)(objectClass=*)(samAccountName=User1)(!distinguishedname=Builtin))(& (objectCategory=person)(objectClass=user)(samAccountName=User1)))

Since no users are defined in the mydomain domain this query returns zero results and the portal returns no packages.

Resolution

This issue is currently under investigation.