# Active Directory domain integrated system restored to new system, new domain users cannot create CI accounts

**URL:** https://www.finalbuilder.com/forums/t/active-directory-domain-integrated-system-restored-to-new-system-new-domain-users-cannot-create-ci-accounts/5453
**Category:** Discussion
**Created:** [February 1, 2016, 7:42am UTC](https://www.finalbuilder.com/forums/t/active-directory-domain-integrated-system-restored-to-new-system-new-domain-users-cannot-create-ci-accounts/5453 "2016-02-01T07:42:48Z")
**Posts on this page:** 8
**Page:** 1

<div class="post-metadata">

### Author: ![braindead](https://www.finalbuilder.com/forums/letter_avatar_proxy/v4/letter/b/6f9a4e/32.png) [@braindead](https://www.finalbuilder.com/forums/u/braindead)
#### Post date: [February 1, 2016, 7:42am UTC](https://www.finalbuilder.com/forums/t/active-directory-domain-integrated-system-restored-to-new-system-new-domain-users-cannot-create-ci-accounts/5453/1 "2016-02-01T07:42:48Z")

</div>

I’m able to login using my domain credentials, and I believe the LDAP integration is working properly.&nbsp; We had a new (to CI) user try to login, he gets the ‘Welcome to Continua’ ‘dialog’ however when pressing start using continua nothing happens except a momentary hourglass.  
  
I noted the message on the Welcome dialog says "Continua has found the curent user ‘’ in an Active Directory group linked to a registered user group…’.&nbsp; Not sure why the current user is a blank string.  
  
CI logs the following error when the '‘start using continua’ button is pressed:  
  
The web server reported the following error:  
Exception: FaultException`1 <br>Message: PartialEvalException (NullReferenceException ("Object reference not set to an instance of an object."), null.ToLowerInvariant()) <br>Stack Trace: <br>Server stack trace: <br>at System.ServiceModel.Channels.ServiceChannel.HandleReply(ProxyOperationRuntime operation, ProxyRpc&amp; rpc) <br>at System.ServiceModel.Channels.ServiceChannel.Call(String action, Boolean oneway, ProxyOperationRuntime operation, Object&#91;&#93; ins, Object&#91;&#93; outs, TimeSpan timeout) <br>at System.ServiceModel.Channels.ServiceChannelProxy.InvokeService(IMethodCallMessage methodCall, ProxyOperationRuntime operation) <br>at System.ServiceModel.Channels.ServiceChannelProxy.Invoke(IMessage message) <br><br>Exception rethrown at &#91;0&#93;: <br>at System.Runtime.Remoting.Proxies.RealProxy.HandleReturnMessage(IMessage reqMsg, IMessage retMsg) <br>at System.Runtime.Remoting.Proxies.RealProxy.PrivateInvoke(MessageData&amp; msgData, Int32 type) <br>at Continua.Common.Services.Contracts.IMembershipService.RegisterLdapUser(String sid, UserDTO userDTO, Boolean firstUser) <br>at Continua.Web.Controllers.AccountController.<>c __DisplayClass13_0.<welcome>b__ 0(IMembershipService x) in W:\CI_WS\Ws\733589\Source\CT_Source\Source\Continua.Web\Controllers\AccountController.cs:line 384 <br>at Continua.Web.ContinuaController.With&#91;TService&#93;(Action`1 action, ServiceEndpointOptions options) in W:\CI\_WS\Ws\733589\Source\CT\_Source\Source\Continua.Web\Controllers\ContinuaController.cs:line 825   
at Continua.Web.Controllers.AccountController.Welcome(WelcomeModel model) in W:\CI\_WS\Ws\733589\Source\CT\_Source\Source\Continua.Web\Controllers\AccountController.cs:line 388  
  
  
We suspect this may be due to backing up on one server and restoring to another.&nbsp; I reviewed the postgresql backup file and didn’t see any obvious problem.&nbsp; The linkage to our admin group seems to be correct, and that’s the only LDAP group linked to CI at this time.&nbsp;   
  
I had that user try from IE on a domain connected PC and a non-domain connected PC, same result either time.&nbsp; Another developer had tested the LDAP integration prior to restoring the database and he had no problem getting back the ‘Welcome’ dialog so I’m fairly sure out IIS and service configuration are correct.

---

<div class="post-metadata">

### Author: ![braindead](https://www.finalbuilder.com/forums/letter_avatar_proxy/v4/letter/b/6f9a4e/32.png) [@braindead](https://www.finalbuilder.com/forums/u/braindead)
#### Post date: [February 1, 2016, 10:14am UTC](https://www.finalbuilder.com/forums/t/active-directory-domain-integrated-system-restored-to-new-system-new-domain-users-cannot-create-ci-accounts/5453/2 "2016-02-01T10:14:04Z")

</div>

As a test one of my coworkers just reinstalled Continua and created a new DB. That resolves the problem, however now we have to either re-create the builds we have manually… or figure out how to import just the project configuration. In our case we only have a few setup so it’s not a big deal, however I think it would be nice to know how to backup and restore to a different server without breaking this.

---

<div class="post-metadata">

### Author: ![braindead](https://www.finalbuilder.com/forums/letter_avatar_proxy/v4/letter/b/6f9a4e/32.png) [@braindead](https://www.finalbuilder.com/forums/u/braindead)
#### Post date: [February 2, 2016, 2:57am UTC](https://www.finalbuilder.com/forums/t/active-directory-domain-integrated-system-restored-to-new-system-new-domain-users-cannot-create-ci-accounts/5453/3 "2016-02-02T02:57:49Z")

</div>

Problem appears to be specific to one user (so far). The user in question has the same domain privileges as I do (mine worked fine). We’re at a loss as to what is going on, however at this point it appears to be a bug in ContinuaCI 1.7.1.177

---

<div class="post-metadata">

### Author: ![braindead](https://www.finalbuilder.com/forums/letter_avatar_proxy/v4/letter/b/6f9a4e/32.png) [@braindead](https://www.finalbuilder.com/forums/u/braindead)
#### Post date: [February 2, 2016, 5:10am UTC](https://www.finalbuilder.com/forums/t/active-directory-domain-integrated-system-restored-to-new-system-new-domain-users-cannot-create-ci-accounts/5453/4 "2016-02-02T05:10:15Z")

</div>

More information. ContinuaCI is unable to see some domain users, others no problem. That seems likely the source of the original problem and the missing user name in the message. We’re asking our IT guys to look into permissions/privileges on the domain user that ContinuaCI runs as.

---

<div class="post-metadata">

### Author: ![braindead](https://www.finalbuilder.com/forums/letter_avatar_proxy/v4/letter/b/6f9a4e/32.png) [@braindead](https://www.finalbuilder.com/forums/u/braindead)
#### Post date: [February 2, 2016, 6:17am UTC](https://www.finalbuilder.com/forums/t/active-directory-domain-integrated-system-restored-to-new-system-new-domain-users-cannot-create-ci-accounts/5453/5 "2016-02-02T06:17:58Z")

</div>

Got our domain admins involved, they found that CI is searching on “User logon name” field in Active Directory, theory is that some migration (these accounts are from NT server days, probably 3.x 😉 didn’t fill that value in.   
  
 I think that CI should raise an error rather than displaying the ‘Welcome to Continua’ page, OR fall back to a different field when ‘User logon name’ is empty? Not my call of course, just documenting what I know.   
  
 Problem we were having is gone now that our domain admins filled in that field.

---

<div class="post-metadata">

### Author: ![Vincent](https://www.finalbuilder.com/forums/user_avatar/www.finalbuilder.com/vincent/32/938_2.png) [@Vincent](https://www.finalbuilder.com/forums/u/Vincent)
#### Post date: [February 2, 2016, 11:37am UTC](https://www.finalbuilder.com/forums/t/active-directory-domain-integrated-system-restored-to-new-system-new-domain-users-cannot-create-ci-accounts/5453/6 "2016-02-02T11:37:54Z")

</div>

Hi   
  
 Apologies for the delay in replying. Glad you got past the problem, obivously there is something we need to handle better. It’s difficult to test because AD will not let us define a user without a user logon name. We’ll look into it.

---

<div class="post-metadata">

### Author: ![braindead](https://www.finalbuilder.com/forums/letter_avatar_proxy/v4/letter/b/6f9a4e/32.png) [@braindead](https://www.finalbuilder.com/forums/u/braindead)
#### Post date: [February 2, 2016, 11:46am UTC](https://www.finalbuilder.com/forums/t/active-directory-domain-integrated-system-restored-to-new-system-new-domain-users-cannot-create-ci-accounts/5453/7 "2016-02-02T11:46:07Z")

</div>

Thanks. These users have been with the company for 30+ years. If you could catch that the information is missing and just display an error about the problem, I think this is a pretty extreme edge case to not likely to be an issue for many.   
  
 At least this thread should provide some documentation of the problem, might help someone else down the line.

---

<div class="post-metadata">

### Author: ![Sparky](https://www.finalbuilder.com/forums/user_avatar/www.finalbuilder.com/sparky/32/10_2.png) [@Sparky](https://www.finalbuilder.com/forums/u/Sparky)
#### Post date: [February 3, 2016, 2:53am UTC](https://www.finalbuilder.com/forums/t/active-directory-domain-integrated-system-restored-to-new-system-new-domain-users-cannot-create-ci-accounts/5453/8 "2016-02-03T02:53:00Z")

</div>

Hi,  
  
We have now updated the code to display a descriptive error message if the Active Directory user does have a “user logon name”. This will be included in the next version.   
  
Thank you for reporting this.  
  
&nbsp;
