eG Administration
 

Validating Parent/Child Domain Configuration

As demonstrated already, the eG Enterprise system provides administrators with a Validate option that helps them check the correctness of the domain configuration when creating that domain, and enables them to make changes to the configuration on-the-fly. This way, the solution prevents the creation of domains with incorrect/invalid details!

Sometimes however, as part of a routine maintenance exercise or owing to a policy requirement, administrators may make some significant changes in the AD environment post the eG manager-AD integration - for example, the domain name can be changed, the domain can be migrated to another server with a different IP address, the login names of domain users can be modified, and so on. Some changes may also occur inadvertently - for instance, a user account may expire or may be locked out, network connection between the eG manager and the AD server could become flaky, etc. Such changes are bound to affect the AD-eG manager integration, causing issues in manager accesses to the AD server, domain user registration with the eG Enterprise system, and even user logins. Therefore, when users to the eG Enterprise system complaint of issues related to the integration, administrators need to rapidly initiate investigations in order to diagnose the reason for this occurrence.

To facilitate this preliminary prognosis, the eG administrative interface provides the DOMAIN VALIDATION page. Using this interface, administrators can quickly check a registered domain's accessibility and the correctness of the connection details provided at the time of domain configuration, from the eG manager itself. In addition, with the help of this page, administrators can quickly view the user groups that are available in a domain and even check the validity of domain user accounts that they intend to add to the eG Enterprise system, without having to physically login to the AD server.

To use this page, do the following:

  1. Right-click on the domain that needs to be investigated, and pick the Validate option from within.
  2. The right panel with some validation settings will appear. First, from the What would you like to validate? drop-down, select the option that indicates what is that you wish to validate. By default, the Is this domain reachable? option is chosen from this list. When users complaint that they are unable to connect to a domain, then, you can select this option to verify whether the domain name that you had provided at the time of domain configuration is still valid or not. If an auto-discovered domain is chosen for validation from the tree-structure, then, selecting the Is this domain reachable? option displays the Display Name and the fully-configured Domain Name of the selected domain. On the other hand, if a manually added domain is chosen for validation from the tree-structure, then, selecting the Is this domain reachable? option displays the Display Name, the fully-configured Domain Name, the Domain IP, and the Port No of that domain. Click the Connect button to check whether the displayed domain is reachable or not. If the domain is reachable, then a message to that effect will appear. If not, then the reasons for the failure will also be indicated.
  3. If the password of the Domain Admin User is changed post domain configuration, then the eG manager will no longer be able to connect to the AD server for creating/validating domain user logins. If users complaint, then administrators can select the Is this domain credential valid? option from the What would you like to validate? list to verify the validity of the Domain Admin Password. Soon after selecting this option, the Domain User, Domain Admin User, and the Domain Admin Password will be displayed. Click the Validate button in the right panel to check validity. The resulting message will indicate whether the displayed connection credentials are valid or not.
  4. Before attempting to register a domain user with the eG Enterprise system, you may want to check whether the user really exists in that domain. For this, select the Does the user exist in this domain? option from the DOMAIN VALIDATION page. Upon selecting this option, the chosen Domain Name will be displayed. Enter the name of the user who needs to be checked in the User Name text box. Finally, click the Validate button. The resulting message will indicate whether the user exists in the domain or not, and if not, suggests a solution for the same.
  5. Domain user logins to the eG Enteprise system may also fail if one of the following is/has become invalid:

    • Domain name
    • User name
    • User password

    To know which one of the above parameters is invalid, select the Is the user able to login to domain? option from the DOMAIN VALIDATION page. Once the chosen Domain Name is displayed, enter the login credentials of the user to be verified, and click the Login button. The resulting message indicates whether the login was successful or not.

  6. The first step to registering a domain user group with the eG Enterprise system is finding which user groups exist in the domain. For this, select the Enumerate domain user groups option from the drop-down list and click the Enumerate button. All user groups available in the chosen domain will then be listed.