RE: [ActiveDir] ADAM-ADSIEDIT and adam-user-based administration.. (ADAM SP1)

2006-10-25 Thread Ansar Mohammed
Use ldapeditor (http://www.ldapeditor.com) Version 3 supports simple binds, ntlm and anonymous logins. New version due in November should support Kerberos and Digest. -Original Message- From: [EMAIL PROTECTED] [mailto:ActiveDir- [EMAIL PROTECTED] On Behalf Of Dmitri Gavrilov Sent:

RE: [ActiveDir] BIND allow-update

2006-10-06 Thread Ansar Mohammed
I believe that that would be a BIND specific situation and allow-update or update-policy can be used, but both directives are per zone. If you have two AD Domains that you want to enable dynamic update on, then yes. But using BIND for AD in all honesty is quite painful. But if you must

RE: [ActiveDir] How are folks setting hidden user attribs?

2006-09-21 Thread Ansar Mohammed
If you are doing it manually you can use a tool like the one at ldapeditor.com to manually add the attributes. _ From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of joe Sent: September 21, 2006 8:12 AM To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] How are folks

RE: [ActiveDir] Search Mailbox

2006-09-21 Thread Ansar Mohammed
http://www.microsoft.com/downloads/details.aspx?FamilyID=55fdffd7-1878-4637-9808-1e21abb3ae37DisplayLang=en MFCMapi From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Dan DeStefano Sent: September 21, 2006 9:02 AM To: activedir@mail.activedir.org Subject:

RE: [ActiveDir] SID History.

2006-09-21 Thread Ansar Mohammed
Matt, Can you elaborate a bit; probably with an example? At what stage are you migrating groups? Is this intra-forest or inter-forest? Also, is the source domain NT4.0 or 200x. And are you using ADMT v 2 or 3? From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of

RE: [ActiveDir] 3rd party vendor and AD for auth

2006-09-20 Thread Ansar Mohammed
You should be looking to ask them. 1. What protocol does your web app use for Auth? 2. Does protocol mentioned above transmit u/p over wire vs Kerberos tickets? 3. If it does transmit u/p over wire how does it secure the creds? 4. Does your app proxy auth requests back to the domain e.g. via ldap

RE: [ActiveDir] Converting OpenLDAP to Active Directory

2006-09-12 Thread Ansar Mohammed
Depends on what you mean converting What are you storing in your AD? Are the users InetOrgPerson or customized? How are you authenticating users? Either way you can check out this tool: http://www.ldapeditor.com it allows you to right click - copy from one directory server to the next. I used

RE: [ActiveDir] Active Directory DN for new setup

2006-09-12 Thread Ansar Mohammed
You can use ADAM for this. ADAM supports X.500 compliant naming contexts. http://technet2.microsoft.com/WindowsServer/en/library/0dcb8e13-4ebb-4fae-98 87-c51d9010bede1033.mspx?mfr=true -Original Message- From: [EMAIL PROTECTED] [mailto:ActiveDir- [EMAIL PROTECTED] On Behalf Of Brian