I'm working on an application that uses some kind of single sign on with Active Directory.
On my side, I'm trying to get some groups to see if the user is member of them.
Sometimes, I get the following error:
The server is not operational
The DirectoryEntry object is created like this:
using(DirectoryEntry ldapConnection = new DirectoryEntry(ldapDomain))
{ Path = ldapPath, AuthenticationType = AuthenticationTypes.Secure }
where ldapDomain is x.y.corp and the ldapPath is
LDAP://OU=someAppId,OU=someGroupName,OU=someClusterName,OU=someResourceName,DC=x,DC=y,DC=corp
After some analysis with the AD team we find out that the controller was removed from the x.y.corp domain but for some reason the Domain Controller is still redirecting to it but the server is down. This generates the error message shown above.
My questions are:
- is there any possible retry mechanism or error handling on my side? (The exception is indeed catch now but is thrown further)
- is there a way to tell the domain controller to not use the server anymore from backend code?
- is there a problem with the construction of the
DirectoryEntry? Is it possible to request the "DC" parameters one at a time and to redirect outside the domain...? - is there any cache on my side for domain controllers?
Thank you!