Serwer terminali Winflector - alternatywa dla aplikacji Zdalny Pulpit, Citrix XenApp

Forum > Product technical support > Active Directory

Autor: Bob
Data: 2013-01-15 04:51:48

Downloaded the latest version to test for a client.  I set it up using Active Directory and found the following:

  • Domain is Server 2008 R2 native.
  • I must use a computer local group (not domain group) for the program to be able to enumerate the users.
  • The users show up with a format of user@localcomputername even if they are domain users
  • Users in group have been granted administrator access to the computer.
  • When using non-AD authentication everything works.

When using AD authenticatin the authentication seems to work but the authorization for application seems to fail.  Here is the line from the log file:

[VTWFC v1021 |W32] 2013.01.14 21:49:31: ERR:02074 INFO:00000, [VTEConnect::GetAllowedApps] "There are no applications available for user on the server. "

The users are configured to allow all applications with two applications defined.  As I stated above when not using AD there are no issues.

What are your thoughts on the issue?

Autor: Bozena (staff)
Data: 2013-01-16 12:13:12

Looks like a bug. It will be fixed next week. Thank you very much for reporting this.

Autor: Bob
Data: 2013-01-23 23:33:13

Has the fix for this been released?

Autor: Bozena (staff)
Data: 2013-01-24 11:40:45

Not yet. I will let you know here when it is ready.

Autor: Bob
Data: 2013-02-04 22:51:16

Do you have an estimated date when this will be ready?

 

Thanks

Autor: Bozena (staff)
Data: 2013-02-05 14:13:10

The next release (with the requested patch) is planned for Friday.

Autor: Bozena (staff)
Data: 2013-02-08 13:27:31

Please download Winflector 3.5.1.0 with AD fixes.

Autor: Bob
Data: 2013-02-11 00:32:40

I tested the new version and found the following:

  • Domain is Server 2008 R2 native.
  • If I do not choose "Assign applications to Windows\AD Users" the program words as expected.  If I choose that option and try to login with a domain account it tells me there are no applications available for me on the server.  Once I uncheck the box to assign applications then it works fine.
  • If I check the box to "Assign applications to Windows\AD Users" and then click the "Update Users" button it will not list domain users.

I guess the trouble seems to be with enumerating domain users from group membership and then trying to apply specific applications to each user.  In the previous version the application would enumerate the domain users and allow me to assign specific apps to a specific domain user account but it would fail on authentication\authorization.  The new version authenticates fine but does not allow me to assign apps to users.

Could you verify you are seeing the same thing I?

Thanks

Autor: Mirek (staff)
Data: 2013-02-11 11:42:33

Do you have filled in both "Domain 1" and "PDC" text boxes on the "users" form?

Autor: Bob
Data: 2013-02-11 22:38:50

The domain info is filled out...the program works with permitting access based on group (to all applications) but it does not work when trying to lockdown applications to specific users.  That tells me that AD authentication is working (if I try it with an AD account outside the permitted group I get an error) so I think we are OK there.  The problem seems to be enumerating domain members of the local group -- for some reason it cannot enumerate them.  It will, for example, enumerate local accounts (administrator, etc) but just has issues with the domain members.

Autor: Mirek (staff)
Data: 2013-02-12 12:32:11

You should run wfserver.exe on domain account with domain administrator rights. To get domain members list, wfserver cannot be run on local user or administrator. In such a case it is able to read only local computer accounts.

Autor: Bob
Data: 2013-02-12 23:52:47

Thanks Mirek...when testing I tried a variety of different methods.  The last method was to use a domain admin account and it still did not work.  If you are seeing different results that I then it could be something specific to my domain configuration rather than the software.  I am running in Server 2008 R2 native mode (not mixed) in my test environment.  The weird thing is this piece worked prior to the upgrade (although I couldn't connect from the client) and nothing in my test domain has changed.

Autor: Bozena (staff)
Data: 2013-02-13 12:04:51

Some changes concerning Active Directory users has been introduced in version 3.5.1.0b. Could you please download and test this version? Thank you.

Autor: Bob
Data: 2013-03-05 01:44:07

Sorry I haven't responded -- I have been traveling the last couple of weeks.  I just tested 3.5.2.0.a and there are still issues resolving domain usernames when trying to assign specific applications.  It will resolve any local users that are members of the group but it will not resolve domain usernames.  This piece did work in the version that was available on 1/15 (although there were other issues).  I have tested this on both a 2008 R2 domain and a 2003 domain and both have the same result.  Is there a server side debug mode where we can capture where it is failing?

Autor: Mirek (staff)
Data: 2013-03-05 14:33:00

Try to create the group directly on your domain controller and add some users to it. Try to synchronize accounts and assign some applications. Please send us log files from your Winflector server.



Zaloguj się aby móc pisać na forum.