?
Solved

Application can't access active directory domain list

Posted on 2008-06-26
4
Medium Priority
?
587 Views
Last Modified: 2010-05-18
I have a windows-based application that connects to an Oracle database.

When I launch the application, it connects to oracle just fine, and brings up my login-box.  Per the application settings we have configured, it uses an Active Directory login method rather than using an application-specific one.  So you supply the login window with your AD credentials, and there is a drop-down menu from which you can select the domain.  The window looks very similar to the Windows XP login screen.

The problem we're finding is that in a specific part of our building (PCs on the second floor connected to two particular networking closets) the drop-down menu that normally is filled with all the available domains is completely blank.

The application usually takes a few seconds to connect to oracle and then another few seconds to retrieve the domain list and display the AD logon.  Right now it takes about 40 seconds before the AD logon comes up, and then it's blank.

If I use a PC on the 3rd floor, or remote connect to a machine in another building, I can access the domain logon easily.

This same thing happened a few weeks ago and self-corrected after about 3 hours.

The application works just fine if you by-pass the AD logon and use a different connection method.  I am in there and it works just great.  It's not an oracle problem that I'm aware of. As far as I know oracle does absolutely no communication with the AD, that's done client-side and then the client reports back whether the authentication attempt was successful and the server allows you to log in.

The order of events looks something like this when everything is working right:

Open app on client PC
App connects to Oracle database
Oracle database recognizes client and communicates that the client should use an AD logon window to connect
Client connects to AD to retrieve domain info
AD logon window is displayed
Enter AD credentials
AD credentials accepted by DC
Application communicates to Oracle database that authentication was successful for user X
Application logs in to the user account linked to that AD account.

I've tried everything I can think of on the PC side.  Release/renew IPs, flushdns, registerdns and even winsockfix.

XP can connect to the domain just fine.  Nobody has trouble logging into Windows, but all of a sudden the application will no longer find that domain list, and you can't just type the domain name in, because it's not an editable field.

Can anyone think of a reason why I wouldn't be able to retrieve a domain list, or why a 3rd party application wouldn't be able to use AD authentication?

It seems to be limited to a specific part of the network, but our network team tells me there's nothing wrong.  I'm stumped and I have to get this fixed by tomorrow AM
0
Comment
Question by:mslunecka
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
4 Comments
 
LVL 71

Expert Comment

by:Chris Dent
ID: 21879036

Hey there,

What does the domain list look like?

I ask because there are two different formats to deal with two two disparate name resolution techniques.

I suspect it's creating a list of NetBIOS Domains, which means it will rely on on your NetBIOS infrastructure. For that to be true the domains will look like:

YOURDOMAIN
YOUROTHERDOMAIN

Rather than:

yourdomain.com
yourotherdomain.local

Chris
0
 
LVL 6

Author Comment

by:mslunecka
ID: 21882876
Must be the NetBIOS domains list, then.  It shows shorthand names like DOMAIN and OTHERDOMAIN rather than fully qualified DNS names.
0
 
LVL 71

Accepted Solution

by:
Chris Dent earned 2000 total points
ID: 21897943

Hey,

It'll be using NetBIOS and, probably, the Browser Master to build the list of Domains then.

If you run a multi-subnet network do you have WINS configured?

Chris
0
 
LVL 6

Author Closing Comment

by:mslunecka
ID: 31471129
It turns out it was the browser master, which helped me bypass the problem, but I'm still trying to figure out how to prevent it.  I'll start another question for that.
0

Featured Post

Concerto Cloud for Software Providers & ISVs

Can Concerto Cloud Services help you focus on evolving your application offerings, while delivering the best cloud experience to your customers? From DevOps to revenue models and customer support, the answer is yes!

Learn how Concerto can help you.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Did you know that more than 4 billion data records have been recorded as lost or stolen since 2013? It was a staggering number brought to our attention during last week’s ManageEngine webinar, where attendees received a comprehensive look at the ma…
Wouldn't it be nice if objects in Active Directory automatically moved into the correct Organizational Units? This is what AutoAD aims to do and as a plus, it automatically creates Sites, Subnets, and Organizational Units.
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …
Suggested Courses

649 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question