I posted a request for help last week, but have more information today...
Scenario:
An AS400 system, which holds user profiles limited to 10 character
usernames. This system will have a "card" installed with W2k server
installed. Specifically, we will be running a Windows server on an
integrated xSeries server which will allow us to "enroll" existing AS400
users and groups on a Windows server. This should allow for a single point
of administration for both AS400 and Windows users. From what I understand,
the AS400 will propagate the W2k server that exists on the box with
username and passwords. These users will have the same username and
password limitations as on the AS400.

We also have a AD server used for domain authentication. This server has
the same "users" only is used in the windows environment. When we setup
this server, we set it up with out limiting the usernames. We didn't
foresee this possible problem.  Our goal is to move towards single sign on.
We have certain applications using this system for authentication
currently, none of which are restricted by username limits.

Has anyone done this before?
Can you make the W2k server on the AS400 system, a child of the current
domain controller? If so, can you link the limited usernames to the
unlimited usernames on the existing W2k server through AD LDAP? Or will I
need to change each username on each system to match the restricted
usernames?
I guess, is there any way around changing all the usernames? The goal is
for all users to exist on one server for a single point of administration,
and to achieve single sign on.  To change usernames on all the systems
involved could be a huge problem.
Your help is greatly appreciated.
*************************************
Sincerely,
Stacey Davis
Wan Technician
Network Services Department
Anderson News Company
Phone (865) 584-9765 ext. 1566
Email [EMAIL PROTECTED]


List info   : http://www.activedir.org/mail_list.htm
List FAQ    : http://www.activedir.org/list_faq.htm
List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/

Reply via email to