Hi
I would like to use a single sign-on for two Drupal sites and a legacy system. I thought I start just with the two Drupal sites to keep it simple.
I installed the bakery module in both sites; configured the root domain (‘http://example.com’)
as master, the the sub-domain (http://sub.example.com’) as slave; added the “Cookie domain” with leading dot (‘.example.com’) in both configurations.
When this didn’t work I also updated the two settings.php file with “
# $cookie_domain = '.example.com'.
There is still no change in the way the sites behave, i.e. they still have their individual log-in, unlike http://groups.drupal.org/ which sends you directly to http://drupal.org/user/login.
Can someone tell me what I need to do to get to work like Drupal/Groups.
Many thanks
mike
Comments
Comment #1
juliangb commentedHi Mike,
A few things to check:
- Make sure the "#" is removed from the start of the cookie_domain line in settings.php
- I don't put a "." in front of the cookie_domain for my sites - I'm not sure if this makes a difference.
On the master site, it is expected that the login works as normal.
On the slave site, the login block will work as before (once bakery is working you should hide this), but if you navigate to user/login, you should be redirected to the master site's login page.
Can you provide more details about what happens when you go to user/login on the slave site? That'll help diagnose if there are still problems.
Comment #2
Mike41 commentedHi Julian
Thank you for your reply and suggestions. I followed them as described below.
1. I have verified that I had removed the # sign in both settings.php files
2. I have removed the leading dot in both setting files cookie_domain, as well as in the configuration file (see 5. Setup below)
That is what is looks like: $cookie_domain = 'example.com';
3. I have the default set-up, except on the master home page, a link to the slave.
3.1 After I loginthe Master I use the link to the slave
3.2 The salve displays the default home page “Welcome to your new Drupal website!” with the login on the left.
3.3 At this stage the Slave does not display a user ID
3.4 when use the link to the “administration section” I get the message “Access denied You are not authorized to access this page.”
4 I am using Firefox and clear cache before each test
5 Setup details ___Site configuration ____Bakery_____
* Is this the master site?
- Master: CHECKED
- Slave :UNchecked
* Master site:
- Master: http://example.co.nz/
- Slave: http://example.co.nz/
* Slave sites:
- in both: http://sub.example.com/
* Seconds of age before a cookie is old:
- In both the default : 3600
* Private key for cookie validation:
- in both the default : blank
* Cookie domain:
- in both: .example.com
* Supported profile fields:
- in both the default checks: username, e-mail, all other unckecked
______________________________________
Question:
1. What is the relationship between “Cookie domain:” in the configuration file versus the “cookie_domain “in the settings.php file?
2. Should the Master have an entry in “Master site:” (as I have)?
3. Should the Slave have an entry in "Slave sites: " (as I have)?
Many thanks for
any support.
Mike
Comment #3
juliangb commentedTo your questions:
1) I suggest you also remove the preceding "." from the cookie domain in the admin/settings form. I'm not exactly sure what the relationship is - but best to keep to the same standard throughout. Someone else might be able to explain in more detail.
2) Yes
3) I don't think it matters, but leave the slave sites field blank in each slave.
If you go to http://sub.example.com/user/login, does this redirect to http://www.example.com/user/login ?
Comment #4
gregglesComment #5
Mike41 commentedHi Julian
Thanks again for your reply and input.
In Bakery admin/settings:
1. I have removed the leading dot from the cookie domain in Master and Slave both have the entry “example.com”
2. no change - Master and Slave have the entry “http://example.com” in “Master site:”
3. removed the entry from the slave – there is no No entry in the Slave’s “Slave sites:”, but in the master “http://example.com”
* The Slave displays an additional Menu “Navigation” with a link “Login”
The link is to http://sub.example.com/user/register?destination=node
Behavior
There are the following two behaviors:
A) If not logged in either site:
- from the Slave’s home page (http://sub.example.com) using the “Login” link leads to the
Master’s Login screen (http://example.com/user/login)
- upon logging in at the Master there is NO return to the Slave
- checking the Slave, there is no user logged in.
B) If already logged in at the Master
- The Link from the Slave leads to the Master Login pages
(as above (http://example.com/user/login) )
- BUT does not display the login fields, instead a the message
“Access denied”.
I would appreciate further help
Cheers
Mike
Comment #6
Mike41 commentedHi Greg
Thank you for your interest in my problem with Bakery.
If the status “maintainer needs more info” is not satisfied by my above response to Julian,
please let me know if there is anything I can check, try or provide as further information.
I am very appreciative for any help in getting Bakery to work.
Many thanks
Mike
Comment #7
juliangb commentedHi Mike,
You said previously that the private key field is blank - what if you try putting a value in there?
(same value on both master and slave)
Comment #8
juliangb commentedBTW - isn't it hugely efficient having one of us in the UK and one in NZ!
Comment #9
Mike41 commentedI agree, we could solve an issue before we found it :-)
Comment #10
Mike41 commentedTried that (private key), but did not make any difference.
Just to be sure. You are using Bakery? If yes, when you loggin from the Slave, I assume it goes to the Master, does return to the slave and do you see the user name upon return?
Comment #11
juliangb commentedYes, I'm using Bakery on my sites. It is also the module that sticks together the login on the drupal.org subdomains.
The 'correct' workflow is either:
- That you click login on a slave site, redirect to the master, fill out username and password and are redirected back (logged in) to the slave
- That you login to the master at somepoint, and any slave that you subsequently visit will automatically recognise that you are logged in.
I am somewhat at a loss as to why your installation still isn't working.
The install.txt has a number of instructions on steps to take. Perhaps it would be wise just to double check to ensure all is setup as that instructs.
Also, there are some machine requirements - your browser must be set up to accept cookies (although this is required for a standard drupal login so should be ok), and your server also needs the mcrypt module for PHP. (It also needs PHP 5.1.2 minimum for some functions).
Comment #13
Mike41 commentedI did several re-installations, installed the update, and with the exception of using a longer private key, haven’t changed anything – BUT it works !!
Thank you Julian for your input and Greg for the continuation of maintaining the module. I appreciate it.
As I mentioned in the Description the objective is to establish single sign on for two Drupal sites and a legacy system. That means I can now approach part two, bakery with legacy system. See "Bakery with Legacy system (Information Required)".
Regards
Mike
P.S. I should mentioned that I used different Sequences when configuring the master and slave.
Comment #14
tftaxis commentedHello:
I followed the documents and installed bakery on my test sites. example.com, sub.example.com, but I got such problems:
1, If I have a user both on master and sub site, such as user1, I added it on both site manually with same user name and password, I can login and logout fine on both site, it works fine.
2, If I have user2 in master site only, I can login from the sub.example.com, and I can check it is ok if I refresh example.com. But my web browser still stay in sub.drupal.com, and the status stayed in no-login.
3, If I have user3 on slave only, I can't login.
Can any one give me some suggestion, thanks.(I am a Chinese, hope you guys can understand what I am talking about)
Comment #15
coltrane@tftaxis Please try out the SSO troubleshooting steps at http://drupal.org/node/1113196#sso
Comment #16
tftaxis commentedThanks, now I config bakery on internet, I can login from the master site, then I found the user alao login on the slave site. But all users can't login from the slave site.
I also can't register user or get bask password from the slave site. I don't know if the bakery was configured right, would it work like groups.drupal.org and drupal.org? I mean, users can register on groups.drupal.org, and login on drupal.org?
Comment #17
coltraneYes, users should be able to register on the sub site and login via the master. You may want to try the dev release of 7.x-2.x as there were some recent commits.
Comment #18
coltraneMarking fixed. If there is still a problem please open a new issue.