Okay I have a case opened with Astaro that is going really slow, and I am throwing this out to the community to possibly get some help. I am trying to understand how the AD Authentication works with respect to Auto create users.
Here is our situation, we have around 50,000 users in AD that could potentially login to the End User Portal. I have the "Active Directory configuration" properly connected to AD. At first I had the End User Portal (EUP), setup to allow all users, however the only way I could get a user to log in was to "pre-fetch" the user. If any of you have tested this with large directories s you will notice a significant slow down in logging into ASG and managing the system anytime the caching of objects is required. I got up to about 3400 users pre-fetched and at that point it would literally take 3 minutes to log into the WebAdmin, and we are running an Active-Active cluster on some pretty big hardware.
The support person told me that with a large AD environment like this that we should use SSO or groups in the groups section of Astaro that point back to AD. Okay, I configured SSO, and the ASG was then added to the domain, but this did absolutely nothing to assist logging in. I then proceeded to configure the EUP for only certain groups, and mapped those out in the group section t point to the respective AD groups. This works fine, but I still have the users getting created on the Astaro side. So I was then told to disable the "Auto Creation of Users" feature so the users would not get created, now the users can no longer login in again to the EUP.
So my big question is, are you supposed to be able to have users login to the EUP without having objects created for them on the Astaro side?
This thread was automatically locked due to age.