BenjaminLloyd Posted November 23, 2018 Posted November 23, 2018 Hi All, I've recently taken over a site that runs HAP+, and they're having some issues with it. It seems that users are only able to see their home drive. After further investigation, I changed one of our shared drives to map to 'All' and users are able to see it. Would anyone be able to suggest where I could start looking to get this issue sorted, please? Any help is much appreciated. Many thanks, Ben
Peter_TVS Posted December 4, 2018 Posted December 4, 2018 (edited) I am wondering whether the Group Builder sees the group you are trying to target the drive at or not... If you go to /HAP/setup.aspx, fill in the password for the delegate user under the Active Directory tab and click away from the field. The "Base Settings" should display a tick, so you know that the setup page will now be able to enumerate your AD. You should now be able to go to the My Files tab, click on a drive and in the Enable Write To or Enable Read To box, use the Group Builder. Click the Search icon and it should let you browse through your AD for the security group. Does it show the list of security groups correctly? Are you able to re-select the target security group and save the settings? Edited December 4, 2018 by Peter_TVS added images
BenjaminLloyd Posted December 6, 2018 Author Posted December 6, 2018 Hi Peter, Thanks for your reply. Yep I'm able to see the security groups when doing this, I've tried clearing the security groups for a mapped drive and re-selecting them but that seems to have done nothing. Interestingly, domain admins should be able to get to /hap/setup.aspx however no domain admin account seems to be able to access it - Looks like HAP can't read any security groups? Many thanks, Ben
Peter_TVS Posted December 12, 2018 Posted December 12, 2018 Can you get to setup.aspx with any account at all? (I know this sounds silly, but with a non-domain admin account?) Are you able to post your Web.config, with any private information scrubbed out?
timbo343 Posted January 31, 2019 Posted January 31, 2019 (edited) We too have this issue now i've found where the problem lies. HAP is not looking up AD groups for some reason. Is anyone able to help? I've spent days and nights on this issue and the SLT are getting impatient. Here is our web.config which is running on Server 2016 in IIS10 Edited January 31, 2019 by timbo343
timbo343 Posted January 31, 2019 Posted January 31, 2019 @nickbro are you able to shead any light on this issue? AD groups not being detected and drive permissions only applying when ALL is set in folder permissions. It's happening on the current server, new servers, with 10.0 and 10.5.
nickbro Posted January 31, 2019 Posted January 31, 2019 It's an odd one as to why 10.6 isn't working as I think I had fixes in 10.6 for the roles not being populated. You can check which roles hap is finding by going to /hap/api/ad/roles/$username. You can try replacing the hap.ad.dll with the one from 10.6
timbo343 Posted January 31, 2019 Posted January 31, 2019 Will try it now and let you know. I mist admit it is a very strange issue. I have tried hap.ad.dll from 10.6 and it knew the group membership but it wouldnt populate the files.
nickbro Posted January 31, 2019 Posted January 31, 2019 Also try turning off writechecks in the config
timbo343 Posted January 31, 2019 Posted January 31, 2019 Also try turning off writechecks in the config That's not made any difference
timbo343 Posted February 1, 2019 Posted February 1, 2019 (edited) @nickbro Thanks again for your help last night but i now have one user who when i test against hap/api/ad/roles/%username%, their account comes back as [authenticated Users]. I have tested a numerous of other accounts and they all display the correct groups - this is using 10.5 by the way. Any indication on why this user wouldn't be detected by HAP yet everyone else is fine? EDIT: Nevermind - it's now picked the user up now - i didn't do anything :S Edited February 1, 2019 by timbo343
nickbro Posted February 12, 2019 Posted February 12, 2019 It's something to do with the way AD sends the list of groups to HAP+. v10.6 has a fix for this, but it breaks some other things for some reason
ctstone Posted October 21, 2020 Posted October 21, 2020 Hi All, Did anyone get any further with this? We experience this issue when we switch one of our old 2008 DCs off. We also tried to setup a brand new HAP Server running 10.6 and this server has the exact same issue. If you set the permissions to "All" then it works fine. If you set it to anything on the Domain then it breaks. LDAP is on the new 2019 domain controller. I think I've worked it down to being an issue with the Domain Controllers rather than a HAP issue. Any support on this would be quite useful as we are relying on HAP heavily for remote learning,
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now