Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

secWinAD plugin failed to look up the account

Status
Not open for further replies.

pelajhia

Programmer
May 19, 1999
592
US
Trying to set up single sign on here, getting excruciatingly close, but still failing at a certain point.
Windows 2003, asp.net, XI R2,SP2. Setting up a new test lab instance.

I have an admin account in AD which I've added to the auth. page. I am able to pull in the main domain associated with the root, however we have many other domains which I can not map.

I am using the same syntax.
example, the main domain: maindomain\bobj-production comes in just fine. the secondary domains: xxdomain\bobj-production do not.
The account is set up this way: domain\bobj-administrator
default domain: 'domain' (set up in root)

I get this error: The secWinAD plugin failed to look up the account for the group "xxdomain\bobj-production"

Since I can get the "main" domain in, I am thinking the basic set up is ok on the bobj side, and that there's something up with the bobj-administrator id in AD: it can not see the other domains, or alternately with the sub-domains. I am not an AD admin, so my technical knowledge here is very limited. I have only been able to go in and verify that things in production (which is working) are the same as what I see in this new test lab.

any suggestions would be great!
 
Hello,

I'm sorry my solution won't be perfect as I have done this the last time years ago...

If I remember correctly, the user I used in the CMC/AD was member of the Enterprise Administrators group in AD which can cross all domains and child domains in the AD Forest.

I may had to start the CMS with this user account but test without first.

Maybe somebody else has another solution but the one above worked for me.

Let me know how it went.

Business Objects Consultant and Trainer
BOCP - BOE and CR & Official Migration Specialist

BI Toolkit - Offices in UK and Holland
 
turns out there exists a wins database on our production side which points the boe server at the various domains; in lieu of this in our test arena we were able to add the domain fully qual. names to the ip properties and this allowed the boe server/cms to 'see' these domains.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top