Changing the AD authentication from one domain to another

If you are having a problem using Vault, post a message here.

Moderator: SourceGear

Post Reply
popezilla
Posts: 57
Joined: Tue Jul 13, 2004 1:17 pm
Location: MD
Contact:

Changing the AD authentication from one domain to another

Post by popezilla » Tue Aug 26, 2008 12:29 pm

My Vault server currently authenticates with DOMAIN-A and I want to change it so that it authenticates with DOMAIN-B. DOMAIN-A and DOMAIN-B do not currently share any trust relationships.
I understand the correct DNS records for accessing DOMAIN-B need to be in accessible from the Vault server, that will be taken care of. Is this as simple as changing the domain name in the Vault Admin tool?

Note that I am using Vault 3.1.9 currently and I have plans in place to upgrade to Vault 4.1.2, but I'd rather get this domain authentication change done with 3.1.9 first. Are there any differences between the 2 versions as far as changing the AD domain authentication?

Beth
Posts: 8550
Joined: Wed Jun 21, 2006 8:24 pm
Location: SourceGear
Contact:

Re: Changing the AD authentication from one domain to another

Post by Beth » Tue Aug 26, 2008 3:47 pm

There's no real difference, except that there is now an additional database called sgmaster.
You may find an uninstall (but keeping the database) and a reinstall (reuse the same database) may be the easiest way to go rather than manually change each permission.
Beth Kieler
SourceGear Technical Support

popezilla
Posts: 57
Joined: Tue Jul 13, 2004 1:17 pm
Location: MD
Contact:

Re: Changing the AD authentication from one domain to another

Post by popezilla » Tue Aug 26, 2008 4:01 pm

Changing each permission?

I can find only one place in the admin tool to specify the authenticating domain name. Are you saying that I need to open each user's properties, uncheck AD authentication, save, recheck AD authentication and resave?

Beth
Posts: 8550
Joined: Wed Jun 21, 2006 8:24 pm
Location: SourceGear
Contact:

Re: Changing the AD authentication from one domain to another

Post by Beth » Thu Aug 28, 2008 2:33 pm

In order for Vault to authenticate against AD, it needs to run under an AD account that has permissions on that domain. If you switch domains, I am assuming that the user you are running Vault under does not have permissions on the other domain. That is why I mentioned the uninstall and reinstall. It's an easy way to switch the user Vault runs under.

If you have a trust where the current user that Vault runs under can authenticate to the second domain, then you are probably fine not switching that, but without knowing more, I couldn't tell you what you have going.

Then, you would go into the Admin web page and switch the domain it authenticates to.

Next, you need to know if the logins are the same on the second domain as the first. If they are, then you don't have to do anything, but if they aren't, then you have to change all the user logins to match what they are on the second domain.
Beth Kieler
SourceGear Technical Support

popezilla
Posts: 57
Joined: Tue Jul 13, 2004 1:17 pm
Location: MD
Contact:

Re: Changing the AD authentication from one domain to another

Post by popezilla » Thu Aug 28, 2008 3:32 pm

Ahhh. I see, thank you.

Beth
Posts: 8550
Joined: Wed Jun 21, 2006 8:24 pm
Location: SourceGear
Contact:

Re: Changing the AD authentication from one domain to another

Post by Beth » Fri Aug 29, 2008 3:14 pm

Feel free to ask more questions if any part doesn't make sense.
Beth Kieler
SourceGear Technical Support

Post Reply