RE: [ActiveDir] [OT][ABUSE] - WAS: Perform gpupdate, start or shut downs through ADUC

2006-04-28 Thread Murray
Can a man not attend an E12 training course without the list descending into chaos the moment he leaves :-) When I saw the post from Robert Lundh my initial thought was that I would have preferred it if he had checked with me first. Generally however I was ok with it because he was posting

RE: [ActiveDir] DCQuery + Remote Site

2006-04-28 Thread neil.ruston
Maybe it's just me but what does ADC mean below? I always thought it meant 'AD connector' [exchange component]. Does it simply mean 'another DC' ? If so, check that all subnets are assigned with the correct site and that DCs are found in the correct sites. ADUC can take some time to open if

[ActiveDir] Monitoring for lingering objects

2006-04-28 Thread neil.ruston
Title: Monitoring for lingering objects Scenario: W2k3 forest in w2k3 FFL Strict replication consistency enabled Let's assume that a lingering object manifests itself via some method I know how to reduce the impact of the lingering object I know how to remove lingering objects

Re: [ActiveDir] Monitoring for lingering objects

2006-04-28 Thread Mark Parris
Neil, Is this covered by eventId 1988? Mark -Original Message- From: [EMAIL PROTECTED] Date: Fri, 28 Apr 2006 09:55:09 To:ActiveDir@mail.activedir.org Subject: [ActiveDir] Monitoring for lingering objects Scenario: W2k3 forest in w2k3 FFL Strict replication consistency enabled

RE: [ActiveDir] Monitoring for lingering objects

2006-04-28 Thread neil.ruston
Yeah - just found it minutes after posting :) Event 1388 for loose and 1988 for strict consistency checking. Thanks Mark and sorry for posting a lame question :) neil -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Mark Parris Sent: 28 April 2006 10:26

Re: [ActiveDir] anyone using IPV6?

2006-04-28 Thread AdamT
On 4/27/06, Thommes, Michael M. [EMAIL PROTECTED] wrote: Has anyone tried IPV6 yet? Production? Or just testbed? Any gotchas? What kind of infrastructure (eg, switches) is needed to support it? How does AD play in this sandbox? On a similar note - is anyone here using 'jumbo' frames on

Re: [ActiveDir] anyone using IPV6?

2006-04-28 Thread xcharbo
Mike: My understanding is that AD does not and will not support IPv6 until the Longhorn server release. In addition, the MS IPv6 stack does not support all features of IPv6 at this time. For example, it only supports AH IPSec packets and not ESP IPSec packets. - John Boling On 4/27/06, Thommes,

Re: [ActiveDir] Is there a way to clear the Netstat -p tcp -s statistics with out rebooting Windows?

2006-04-28 Thread Al Mulnick
Odd. I may have been afflicted with the Joe email malady. I'll have to investigate Is everyone seeing the same thing? Please drop a note off-line if you can read this on the list and it's blank ;) On 4/27/06, joe [EMAIL PROTECTED] wrote: Al, what did you do? All of your posts are no

[ActiveDir] error setting account

2006-04-28 Thread adriaoramos
When I try to enabel trusted for delegationoption for an account I have created, I recieve this error. Your security settings do not allow you to specify whether or not this account is to be trusted for delegation What can I do to solve this? Adriao Ramos

RE: Re: [ActiveDir] Internet Authentication Concepts: Pointers?

2006-04-28 Thread Jef Kazimer
Mylo, Thanks for the information! I have setup ADAM utilizing a custom web UI utilizing AZman for a small project before, but I have concerns about scalabilty. The issues are not with the ADAM instance at all, but the UI that is needed to manage ADAM. ADSIedit is great for someone who

RE: [ActiveDir] OT: Windows Vista - Windows Defender

2006-04-28 Thread Michael B. Smith
Yes. I loaded it two nights ago. Pretty cool. First build Ive found comfortable to use (old POS box no aero). From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Brian Desmond Sent: Friday, April 28, 2006 12:44 AM To: ActiveDir@mail.activedir.org Subject: RE:

RE: Re: [ActiveDir] Internet Authentication Concepts: Pointers?

2006-04-28 Thread Stewart, Fitz
That’s a very good point.  Does anyone know of any 3rd parties which improve the ADAM administrative UI “experience”? J. Fitzgerald (Fitz) Stewart Systems Architect IRM/OPS/ENM Worldwide Information Network Systems USAID/DoS IT Infrastructure Collaboration Program [EMAIL

RE: [ActiveDir] Root Place Holder justification

2006-04-28 Thread Rocky Habeeb
Gil, I hear that all the time, plus Hey Rocky, where's Bullwinkle? Hee hee hee. Anyway, for people like me who couldn't see Dean and joe and all the rest of youse guys even if I had the Hubble telescope, because you're so far out there, and who go to bed each night praying, Dear God, thank

RE: [ActiveDir] Root Place Holder justification

2006-04-28 Thread Rocky Habeeb
Gil, I hear that all the time, plus Hey Rocky, where's Bullwinkle? Hee hee hee. Anyway, for people like me who couldn't see Dean and joe and all the rest of youse guys even if I had the Hubble telescope, because you're so far out there, and who go to bed each night praying, Dear God, thank

RE: Re: [ActiveDir] Internet Authentication Concepts: Pointers?

2006-04-28 Thread Jef Kazimer
Since it is "LDAP" I did look at some "friendlier" admin tools, but none really hit the mark for me. I believed that group looked at Softerra's tool, and there is the web based PHP LDAP manager, and also the C# LDAP manager tool. You can Live search the names or I can post the links here if you

[ActiveDir] sites, slow links and AD

2006-04-28 Thread Myke
Hi guys, A environment: up 600 sites the links: 128 kbps (64 is reserved for a QoS for one service) datacenter link: 4mb Each site have 5 up to 8 computers (all computers are stand alone and workstations) all sites have comunication with de datacenter (VPN) In this scenario, how can I deploy a

RE: [ActiveDir] Root Place Holder justification

2006-04-28 Thread neil.ruston
Title: Message I doubt a root domain would represent 'harm' in your terms, but then again, harm may mean different things to different people. From anarchitectural stance, harm means a whole lot more.What about added admin overhead; additional hardware costs, support and maintenance;

[ActiveDir] Sites and Services

2006-04-28 Thread Salandra, Justin A.
Can someone please tell me where I can find the Default Query Policy that you can place on to NTDS Connections within sites? I wanted to find out what that does. Thanks Justin A. Salandra MCSE Windows 2000 2003 Network and Technology Services Manager Catholic Healthcare System

RE: [ActiveDir] OT: Windows Vista - Windows Defender

2006-04-28 Thread Salandra, Justin A.
Will Technet Subcribers get this copy like we did with build 5231 and 5308? Does 5308 have it in it? Justin A. Salandra MCSE Windows 2000 2003 Network and Technology Services Manager Catholic Healthcare System 646.505.3681 - office 917.455.0110 - cell [EMAIL PROTECTED]

Re: Re: [ActiveDir] Internet Authentication Concepts: Pointers?

2006-04-28 Thread Al Mulnick
I suspect you'll want to talk with the Tivoli reps to see what they can do for you. As for management of the identities and third parties, I suspect that a roll-your-own approach is just as good as anything until you have more requirements. There are a ton of vendors that can help with that -

RE: [ActiveDir] Root Place Holder justification

2006-04-28 Thread Jef Kazimer
Neil, In some ways they may be even more harmful. Network outages have their own fixes, hardware failures have replacements, deleted data (should) have backups. Solutions for bad process and policy due to architecture decisions? Not as cut and dry, and could be most costly in the long run as

Re: [ActiveDir] Sites and Services

2006-04-28 Thread Mark Parris
If I recall from a drunken conversation at DEC with Dean it is accessable using Adsiedit and it is parameters control how many records are searched in AD, the ones you don't touch. I think if it is not set, it uses it anyway. I will go away and quantify my statements though. Mark

RE: [ActiveDir] Sites and Services

2006-04-28 Thread joe
You mean this one adfind -config -f name="default query policy" See Slide 58 of the Dean and joe show PPT located at http://www.jadonex.comfor a little more info. -- O'Reilly Active Directory Third Edition - http://www.joeware.net/win/ad3e.htm From: [EMAIL PROTECTED] [mailto:[EMAIL

RE: [ActiveDir] sites, slow links and AD

2006-04-28 Thread joe
If the machines are standalone then AD is pretty much out of the picture for managing them... -- O'Reilly Active Directory Third Edition - http://www.joeware.net/win/ad3e.htm -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Myke Sent: Friday, April

RE: [ActiveDir] OT: Windows Vista - Windows Defender

2006-04-28 Thread joe
I concur, it is very much improved even over 5342. Loaded considerably faster, runs smoother, just gorgeous with glass. eg... though I would really like to have glass windows as well as glass borders. Only place I know you can't get glass windows. :) Actually I want glass windows and also

[ActiveDir] Cleanup of AD accounts

2006-04-28 Thread Rimmerman, Russ
Joe - I sent you an e-mail, I figured maybe going to this list might get more input on this question as well: If I wanted to run an oldcmp -report 120 -users -sort cn -f "((objectcategory=person)(objectclass=user))" -format csv -delim , and then send it out to our remote administrators

RE: [ActiveDir] [OT][ABUSE] - WAS: Perform gpupdate, start or shut downs through ADUC

2006-04-28 Thread joe
Can a man not attend an E12 training course without the list descending into chaos the moment he leaves :-) Absolutely not Murray! -- O'Reilly Active Directory Third Edition - http://www.joeware.net/win/ad3e.htm -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]

RE: [ActiveDir] sites, slow links and AD

2006-04-28 Thread David Adner
You'll probably want to give MS a call and have a detailed discussion on this. Read the Branch Office Deployment Guide, too. -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Myke Sent: Friday, April 28, 2006 9:16 AM To: ActiveDir@mail.activedir.org

[ActiveDir] OT: Network routing/Cisco mailing list

2006-04-28 Thread Danny
Happy Friday to you all. Sorry for the OT - I am looking for a Cisco network routing or just general network routing mailing list. Any suggestions? I did search as well. Thanks, ...D List info : http://www.activedir.org/List.aspx List FAQ: http://www.activedir.org/ListFAQ.aspx List

RE: [ActiveDir] sites, slow links and AD

2006-04-28 Thread neil.ruston
Build a (single domain) AD. Deploy an appropriate site and repl model Create appropriate GPOs Build all machines into the domain neil -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Myke Sent: 28 April 2006 15:16 To: ActiveDir@mail.activedir.org

RE: [ActiveDir] [OT][ABUSE] - WAS: Perform gpupdate, start or shut downs through ADUC

2006-04-28 Thread joe
If you didn't learn about oldcmp on this list, how in the world did you learn about it? I practically developed it on this list. :)I think some of the thoughts about where the lists go is in part just due to growth. It is just like all of the other OT stuff that floats through here that

RE: [ActiveDir] sites, slow links and AD

2006-04-28 Thread Brian Desmond
Should be fine but more info on things like object volume, replication churn, DC/GC placement, etc would help... Thanks, Brian Desmond [EMAIL PROTECTED] c - 312.731.3132 -Original Message- From: [EMAIL PROTECTED] [mailto:ActiveDir- [EMAIL PROTECTED] On Behalf Of Myke Sent:

RE: [ActiveDir] OT: Windows Vista - Windows Defender

2006-04-28 Thread Brian Desmond
Have you tested MCE on it? 5342 MCE on a beefy box is like useless Thanks, Brian Desmond [EMAIL PROTECTED] c - 312.731.3132 From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Michael B. Smith Sent: Friday, April 28, 2006 9:39 AM To:

RE: [ActiveDir] OT: Network routing/Cisco mailing list

2006-04-28 Thread John Exum
cisco-nsp mailing list [EMAIL PROTECTED] https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ It covers more than just routing... -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Danny Sent: Friday,

RE: [ActiveDir] OT: Network routing/Cisco mailing list

2006-04-28 Thread Brian Desmond
cisco-nsp on puck.nether.net is excellent ... if you have a specific question I can take a shot... Thanks, Brian Desmond [EMAIL PROTECTED] c - 312.731.3132 -Original Message- From: [EMAIL PROTECTED] [mailto:ActiveDir- [EMAIL PROTECTED] On Behalf Of Danny Sent: Friday, April 28,

[ActiveDir] GC Promotion

2006-04-28 Thread Mark Parris
When elevating a DC to be a GC and say there are 3 domains, located say located on 3 continents. Is the GC that already exists in each domain authorative in the elevation of the DC to a GC or does each DC contact a DC in the relevant domain for the GC information? Make sense? Mark List info

Re: [ActiveDir] OT: Network routing/Cisco mailing list

2006-04-28 Thread Irwan Hadi
You can try cisco@groupstudy.com http://www.groupstudy.com/list/cisco.html On 4/28/06, Danny [EMAIL PROTECTED] wrote: Happy Friday to you all. Sorry for the OT - I am looking for a Cisco network routing or just general network routing mailing list. Any suggestions? I did search as well.

Re: [ActiveDir] Sites and Services

2006-04-28 Thread mike kline
It's also viewable using Ntdsutil http://support.microsoft.com/default.aspx?scid=kb;en-us;315071How to view and set LDAP policy in Active Directory by using Ntdsutil.exe Thanks Mike On 4/28/06, joe [EMAIL PROTECTED] wrote: You mean this one adfind -config -f name=default query policy See

RE: [ActiveDir] OT: Windows Vista - Windows Defender

2006-04-28 Thread Jef Kazimer
works nice...but still no Xbox 360 support :( I want to test that piece :) Subject: RE: [ActiveDir] OT: Windows Vista - Windows DefenderDate: Fri, 28 Apr 2006 12:15:52 -0400From: [EMAIL PROTECTED]To: ActiveDir@mail.activedir.org Have you tested MCE on it? 5342 MCE on a beefy box is

[ActiveDir] R2 Upgrade or install?

2006-04-28 Thread Bahta, Nathaniel V CTR USAF NASIC/SCNA
Hey all, I am having a debate and wondering if the following is true: 1)You must upgrade your 2003 servers to SP1 before going to R2. 2)You can upgrade a existing 2003 server to SP1 and then load the components from R2 onto it from R2 disk 2. Or 3)Must you load the R2 disk 1 2003 Operating

Re: [ActiveDir] GC Promotion

2006-04-28 Thread mike kline
From http://support.microsoft.com/default.aspx?scid=kb;en-us;910204sd=rssspid=3198 When a domain controller is selected to host the global catalog, the KCC on the domain controller that is being promoted uses its discretion to build connection objects from source domain controllers that host the

Re: [ActiveDir] GC Promotion

2006-04-28 Thread Matheesha Weerasinghe
I've got a parent-child domain setup here and I have child domain GCs which repls the parent domain NC from another child domain NC. Now I dont know if its possible to make a GC using a DC of the other domain thats not a GC. In a hypothetical setup where all sites were not fully routed this could

Re: [ActiveDir] R2 Upgrade or install?

2006-04-28 Thread mike kline
Yes you have to have SP1, Either way will work. If you installSP1 first then you will only need use Disc 2. If you don't have SP1 installed you need to use both disks which will install SP1 for you. I would install SP1 even if you were not planning to install R2 at this time. If you are

RE: [ActiveDir] R2 Upgrade or install?

2006-04-28 Thread Ken Cornetet
Your scenario 2 works, and our TAM says there is no problem doing it. I have upgraded a couple of servers this way. -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Bahta, Nathaniel V CTR USAF NASIC/SCNA Sent: Friday, April 28, 2006 12:18 PM To:

RE: [ActiveDir] R2 Upgrade or install?

2006-04-28 Thread Stewart, Fitz
My understanding is there is no difference between 1/2 and 3. The R2 Disk one IS W2k3+SP1, so whether you load that or the naked SP gets you to the same point. You can't even run the R2 setup however until you're at SP1. -fitz 703-866-7473 703-626-5741 (cell) -Original Message- From:

RE: [ActiveDir] GC Promotion

2006-04-28 Thread Mark Parris
Anyone know what constitutes domain controller discretion? From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]] On Behalf Of mike kline Sent: 28 April 2006 18:31 To: ActiveDir@mail.activedir.org Subject: Re: [ActiveDir] GC Promotion From

RE: [ActiveDir] GC Promotion

2006-04-28 Thread Tim Vander Kooi
It means if you kiss...You don't tell. :~) From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Mark ParrisSent: Friday, April 28, 2006 1:11 PMTo: ActiveDir@mail.activedir.orgSubject: RE: [ActiveDir] GC Promotion Anyone know what constitutes domain controller discretion?

RE: [ActiveDir] R2 Upgrade or install?

2006-04-28 Thread Tim Vander Kooi
If you are asking if there is anything special about Disk 1 of the R2 install set, then the answer is no. Whether you install Windows 2003 Server SP1 from the R2 set or you have 2003 SP1 already installed, it makes no difference. -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL

RE: [ActiveDir] GC Promotion

2006-04-28 Thread joe
Yes a GC promotion can/will source readonly NCs from another GC, it does not have to go back to a DC that maintains a writeable replica. If the DC is already replicating with a DC that is also a GC, it is likely that it will start pulling the additional NCs from that GC. joe -- O'Reilly

RE: [ActiveDir] GC Promotion

2006-04-28 Thread Lee, Wook
I thought that if there is a writable NC in the same site, it would try to use that, but maybe that's just for PAS replication. Wook -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of joe Sent: Friday, April 28, 2006 11:55 AM To:

RE: [ActiveDir] OT: Windows Vista - Windows Defender

2006-04-28 Thread joe
If someone would just write some XBOX 360 Admin tools for Active Directory we would have a whole giant pool of amazing AD Admins. The way my brothers and cousins master those games it would be amazing to see them go after AD that way. Haven't tried the MCE stuff yet but was going to play

RE: [ActiveDir] Root Place Holder justification

2006-04-28 Thread joe
I read your post as You need good policy and procedures and actually adhere to them. I 100% agree, doesn't matter if you have 1 domain or 30 domains (and that could be 29 full or empty or any combination domains). I recently had to sit in on a meeting to listen to some folks discuss a

RE: [ActiveDir] Sites and Services

2006-04-28 Thread joe
True, but only the default. If you create additional policies NTDSUTIL will not help you with them. However creating and using additional policies is such an incredibly unusual thing in my opinion I probably shouldn't even mention it. In fact look into my eyes...you are getting very

RE: [ActiveDir] Cleanup of AD accounts

2006-04-28 Thread joe
And I look and see that I received it. Glad you like oldcmp btw... :) First off, you don't need the -f option with the user filter in there, the -users will take care of that for you. Second off, no there is no mechanism in it right now to allow you to exclude accounts based on a text

RE: Re: [ActiveDir] ADAM Management Tool REQs and Desires...... WAS: Internet Authentication Concepts: Pointers?

2006-04-28 Thread joe
I have some curiosity in this realm... What would everyone consider good things and requirements for an ADAM management tool. Even assuming, cough, GUI. joe -- O'Reilly Active Directory Third Edition - http://www.joeware.net/win/ad3e.htm From: [EMAIL PROTECTED] [mailto:[EMAIL

Re: [ActiveDir] Cleanup of AD accounts

2006-04-28 Thread Kamlesh Parmar
I suppose you can use DN from that modified file and feed it to dsmod.exe or admod.exeOn 4/28/06, Rimmerman, Russ [EMAIL PROTECTED] wrote: Joe - I sent you an e-mail, I figured maybe going to this list might get more input on this question as well: If I wanted to run an oldcmp -report 120

RE: [ActiveDir] Monitoring for lingering objects

2006-04-28 Thread joe
Title: Monitoring for lingering objects I guess you could schedule a run of gcchk which will find possible lingering objects. -- O'Reilly Active Directory Third Edition - http://www.joeware.net/win/ad3e.htm From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of [EMAIL

RE: [ActiveDir] DCQuery + Remote Site

2006-04-28 Thread joe
I wondered the same thing. I thought 1 DC, 2 AD Connector Servers and Exchange... Head for the hills! -- O'Reilly Active Directory Third Edition - http://www.joeware.net/win/ad3e.htm -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of [EMAIL PROTECTED]

Re: [ActiveDir] unable to modify personal info

2006-04-28 Thread Tom Kern
Points taken. Thanks Just one rehash- Due to the adminSDHolder, account operators cannot modify other account operators. But why should this be true as well for modifying their own properties? Why shouldn't an account op change his/her phone # or address or displayname etc? Is it just due to

RE: Re: [ActiveDir] ADAM Management Tool REQs and Desires...... WAS: Internet Authentication Concepts: Pointers?

2006-04-28 Thread Jerry Welch
ME ! Jerry Welch CPS Systems US/Canada: 888-666-0277 International: +1 703 827 0919 (-5 GMT) IP Phone (Skype): Jerry_Welch ( www.skype.net ) IP Phone (VOIP):Jerry_Welch ( www.voipstunt.com ) VOIP to Landline: callto:+1-703-827-0919 From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On

RE: [ActiveDir] User Accounts

2006-04-28 Thread joe
This is a good thread, I should have kept up with it. :) I think some of the problem is resulting from language interpretation. When I visualize AD in regards to the topics in this thread I think of it sort of like --- | | | AD | | | --- | | | DBLAYER

[ActiveDir] FW: Sending mail to AOL and Yahoo

2006-04-28 Thread Salandra, Justin A.
Justin A. Salandra MCSE Windows 2000 2003 Network and Technology Services Manager Catholic Healthcare System 646.505.3681 - office 917.455.0110 - cell [EMAIL PROTECTED] From: Salandra, Justin A. Sent: Friday, April 28, 2006 4:16 PM To: [EMAIL PROTECTED] Subject:

RE: Re: [ActiveDir] ADAM Management Tool REQs and Desires...... WAS: Internet Authentication Concepts: Pointers?

2006-04-28 Thread joe
I am not quite sure what question that response was intended to answer Was that, you would like a good ADAM management tool? If so, describe that tool. If Murray isn't happy, we can take it offlist. I can do this through personal email or spin up a forum on my website for it. I am

RE: Re: [ActiveDir] ADAM Management Tool REQs and Desires...... WAS: Internet Authentication Concepts: Pointers?

2006-04-28 Thread Stewart, Fitz
Heck, just give a user the ability to create and otherwise manage objects – users, groups, the basics.  Name, etc.  Nothing fancy, just not the command-line-ishness of ADSIEDIT. -fitz 703-866-7473 703-626-5741 (cell) From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]

RE: [ActiveDir] unable to modify personal info

2006-04-28 Thread joe
The ACL is modified and all of the answers for what people can and can't do in AD is a story well told by theACL of the object in question. The adminSDHolder ACL on my test domain (I don't think I have touched it) looks like G:\TEMPadfind -default -f name=adminsdholder

RE: [ActiveDir] Cleanup of AD accounts

2006-04-28 Thread joe
Correct, definitely another option. However consider what I wrote in my previous note, do you want to go through this check every time? Maybe the answer is yes, but that one time it gets dropped somehow and you have to explain why you were told 10 times over the last24 months that it

RE: [ActiveDir] Cleanup of AD accounts

2006-04-28 Thread Rimmerman, Russ
Is there an attribute that's generallysafe to use, or are you suggesting we request an OID from Microsoftand make our own boolean "ourcompanyServiceAccount" attribute? From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of joeSent: Friday, April 28, 2006 2:44 PMTo:

RE: Re: [ActiveDir] ADAM Management Tool REQs and Desires...... WAS: Internet Authentication Concepts: Pointers?

2006-04-28 Thread Jef Kazimer
Joe, Good question. I would assume something similar to ADUC (dsa.msc) where you can use a standardized interface to manage users and the associated attributes. The problem I suppose is that ADAM can be utilized for many custom scenarios, that it would be hard to have a "standard" interface.

RE: [ActiveDir] Exchange rights slow to become available

2006-04-28 Thread joe
You work this out? To me, if I had to pose a guess, it is a combination of replication latency combined with token updates. Tokens don't update for interactive auths. They can get updated for remote work. I previously sent a rather long and probably dry email about this to the list you may

Re: [ActiveDir] FW: Sending mail to AOL and Yahoo

2006-04-28 Thread Frederic Woodbridge, III
Do you have any sort of anti-virus scanning your outbound email--specifically Norton 10--on your server? This could be causing problems with sending emails. The same thing happened to us some time ago and that was the issue. On 4/28/06, Salandra, Justin A. [EMAIL PROTECTED] wrote: [edit] Is

RE: [ActiveDir] Cleanup of AD accounts

2006-04-28 Thread Jef Kazimer
We use "employeeType" with values of EMPLOYEE CONTRACTOR VENDOR SERVICE OTHER ADMIN Jef Subject: RE: [ActiveDir] Cleanup of AD accountsDate: Fri, 28 Apr 2006 16:04:42 -0500From: [EMAIL PROTECTED]To: ActiveDir@mail.activedir.org Is there an attribute that's generallysafe to use, or are you

RE: [ActiveDir] Tombstone attributes

2006-04-28 Thread joe
I don't consider storing the PW in a tombstone a particularily high risk I agree with Guido here. I expect I wouldn't think twice about doing this if it came up. When you reanimate even if you set pwdLastSet to be recovered it won't be. It won't be stripped on the tombstoning process, it will be

Re: [ActiveDir] FW: Sending mail to AOL and Yahoo

2006-04-28 Thread Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP]
Dynamic IP or you are on a IP blocking range perhaps? Set up a special AOL/Yahoo SMTP connector.. bounce the email through your ISP's smarthost.. those two email address ranges are a pain. Salandra, Justin A. wrote: Justin A. Salandra MCSE Windows 2000 2003 Network and Technology

RE: [ActiveDir] How Secure is a Domain Controller?

2006-04-28 Thread joe
This is old, I sort of apologize. This is a topic some of us have debated in circles over on the MVP / MS Private Security List Server multiple times as well. It is always fun because the opinions are all over. I have some thoughts for it. 1. A passphrase is just like a password only you have

RE: [ActiveDir] OT: Windows Vista - Windows Defender

2006-04-28 Thread Brian Desmond
Do you have access to connect? If you do you can nominate yourself to test said functionality. Thanks, Brian Desmond [EMAIL PROTECTED] c - 312.731.3132 From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Jef Kazimer Sent: Friday, April 28, 2006 1:17 PM

RE: [ActiveDir] R2 Upgrade or install?

2006-04-28 Thread Brian Desmond
I do option 2 for existing installs that need it and option 3 for anything that needs a rebuild excuse or is fresh. Thanks, Brian Desmond [EMAIL PROTECTED] c - 312.731.3132 -Original Message- From: [EMAIL PROTECTED] [mailto:ActiveDir- [EMAIL PROTECTED] On Behalf Of Bahta,

RE: [ActiveDir] OT: Windows Vista - Windows Defender

2006-04-28 Thread Brian Desmond
What is it youre going to put on the command prompt background anyway? A semi transparent playboy centerfold to look at while you program? Im downloading 5365 now since I busted my MCE Im either going to fix it with that or revert to SP2. Thanks, Brian Desmond [EMAIL PROTECTED]

RE: [ActiveDir] FW: Sending mail to AOL and Yahoo

2006-04-28 Thread Brian Desmond
I dont see anything on NANOGusually a good barometer for this sort of thing. Thanks, Brian Desmond [EMAIL PROTECTED] c - 312.731.3132 From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Salandra, Justin A. Sent: Friday, April 28, 2006 4:37 PM To:

RE: [ActiveDir] FW: Sending mail to AOL and Yahoo

2006-04-28 Thread Salandra, Justin A.
I have Trend Micro Scan Mail and it is configured the same way it has always been for the past 2 years and only yesterday this started. -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Frederic Woodbridge, III Sent: Friday, April 28, 2006 5:25 PM To:

RE: [ActiveDir] FW: Sending mail to AOL and Yahoo

2006-04-28 Thread Salandra, Justin A.
I don't understand what you mean by my ISP's smart host? I use a static natted address for my mail server. I know how to create a new SMTP Connector, but why should I have to do this just for AOL and Yahoo all of a sudden? -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL

RE: [ActiveDir] FW: Sending mail to AOL and Yahoo

2006-04-28 Thread Brian Desmond
What kind of aggregate mail volume are you doing? I've seen some weird throughput bugs in Scanmail in high volume environments. Thanks, Brian Desmond [EMAIL PROTECTED] c - 312.731.3132 -Original Message- From: [EMAIL PROTECTED] [mailto:ActiveDir- [EMAIL PROTECTED] On Behalf Of

Re: [ActiveDir] FW: Sending mail to AOL and Yahoo

2006-04-28 Thread Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP]
If they suddenly see you as a bad IP. Have you checked to see if you are on a SORBs list? Salandra, Justin A. wrote: I don't understand what you mean by my ISP's smart host? I use a static natted address for my mail server. I know how to create a new SMTP Connector, but why should I have to

RE: [ActiveDir] FW: Sending mail to AOL and Yahoo

2006-04-28 Thread Brian Desmond
Who do you purchase your transit from (aka who is/are your ISP(s)) where you work? Tell me offlist if need be. Thanks, Brian Desmond [EMAIL PROTECTED] c - 312.731.3132 -Original Message- From: [EMAIL PROTECTED] [mailto:ActiveDir- [EMAIL PROTECTED] On Behalf Of Salandra, Justin

RE: [ActiveDir] FW: Sending mail to AOL and Yahoo

2006-04-28 Thread Salandra, Justin A.
We do a lot of e-mail each day, not sure of specific numbers. But Trend Micro is set to scan all messages and to also scan the SMTP traffic -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Brian Desmond Sent: Friday, April 28, 2006 10:41 PM To:

RE: [ActiveDir] FW: Sending mail to AOL and Yahoo

2006-04-28 Thread Salandra, Justin A.
Also I am getting on the delay notifications a Status of 4.7.7 -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Brian Desmond Sent: Friday, April 28, 2006 10:41 PM To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] FW: Sending mail to AOL and Yahoo

RE: [ActiveDir] FW: Sending mail to AOL and Yahoo

2006-04-28 Thread Salandra, Justin A.
I am not on any blacklist. I did a search on 147 known RBLs and I am not listed on any -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP] Sent: Friday, April 28, 2006 10:48 PM To: ActiveDir@mail.activedir.org

Re: [ActiveDir] FW: Sending mail to AOL and Yahoo

2006-04-28 Thread Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP]
Google Groups: microsoft.public.exchange2000.win2000:

RE: [ActiveDir] OT: Windows Vista - Windows Defender

2006-04-28 Thread Jef Kazimer
You have me salivating What is the program name? I do not see it under the availiable programs listing. Subject: RE: [ActiveDir] OT: Windows Vista - Windows DefenderDate: Fri, 28 Apr 2006 19:00:32 -0400From: [EMAIL PROTECTED]To: ActiveDir@mail.activedir.org Do you have access to

RE: [ActiveDir] OT: Windows Vista - Windows Defender

2006-04-28 Thread Jef Kazimer
Just curious Does the Vista MCE allow Divx playback for the extender? The MCE Transcoder is a life saver to play Divx and Xvid on the Xbox 360 MCE-E. Subject: RE: [ActiveDir] OT: Windows Vista - Windows DefenderDate: Fri, 28 Apr 2006 19:03:07 -0400From: [EMAIL PROTECTED]To:

RE: [ActiveDir] FW: Sending mail to AOL and Yahoo

2006-04-28 Thread Salandra, Justin A.
Thanks it was 4.4.7. If the problem is with AOL and Yahoo then there is nothing that I can do right? -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP] Sent: Friday, April 28, 2006 11:39 PM To:

RE: [ActiveDir] FW: Sending mail to AOL and Yahoo

2006-04-28 Thread Salandra, Justin A.
You are not going to believe this, but the fix to this was to increase the DNS packet size on my pix firewall from 512 K to 1024 K. Once I did that all traffic started to go through for AOL and Yahoo. -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of

Re: [ActiveDir] FW: Sending mail to AOL and Yahoo

2006-04-28 Thread Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP]
I'm not surprised... we're seeing MTU packet issues ever since 05-019 and other security fixes. Salandra, Justin A. wrote: You are not going to believe this, but the fix to this was to increase the DNS packet size on my pix firewall from 512 K to 1024 K. Once I did that all traffic started to

Re: Re: [ActiveDir] ADAM Management Tool REQs and Desires...... WAS: Internet Authentication Concepts: Pointers?

2006-04-28 Thread Joe Kaplan
The difficulty with building a tool like this is that it is a huge leap to go from a low level editing tool like ADSI Edit to a high level, task-based UI like ADUC. The problem is that it is nearly impossible to infer the semantic meaning of attributes in the directory in a generic way such