Oct 19 2018

T28-2017 Unable to Edit Foundation Hub 2017 R2 SP1 User Directory

When a User Directory is saved after editing, the domain name will be set to the first part of the DNS domain name. If the NETBIOS domain name is different, the effect will be that users from that domain will not be able to log in to Foundation or any applications using Foundation for authentication.

Example: The network is configured with the NETBIOS domain name of XYZ and the DNS domain name of ABC.MYCOMPANY.COM. A mismatch exists between XYZ (NETBIOS) and ABC (DNS) and this network will be affected by the issue. The administrator creates a User Directory and sets the domain to XYZ (the NETBIOS name). The initial save occurs correctly and users can log in to the system. Later, the administrator edits the User Directory. When the User Directory is saved the second (and subsequent times), the domain is set to ABC (the first part of the DNS domain name). At this point domain users can no longer log in because their accounts are in domain XYZ, not ABC.
 
How to determine if you are impacted by this issue: Open any Windows client in the domain and open a command prompt and type "set" to see the USERDOMAIN (NETBIOS domain) and USERDNSDOMAIN (DNS domain).  Your Foundation deployment will be affected if the NETBIOS domain and first part of the DNS domain do not match.
 
 
Resolution:
When the network NETBIOS and DNS domain names are mismatched, delete the existing User Directory and create a new User Directory instead of editing the existing User Directory. 
Important: Always make sure a database type Foundation account is available with administrator permissions. Database type accounts will still be able to log in when the domain accounts cannot.

This defect has been entered as SEC-4314 and has been scheduled to be fixed in the next release of BIOVIA Foundation.  Please contact BIOVIA support if you have any questions.