|
What is the easiest way to unlock multiple
user accounts in Active Directory? Random accounts locked up today and I need
a way to unlock them without having to go user by user. Is there a tool or
script already written? Any help would be appreciated. Robert From:
[EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Gasper, Rick I am looking that up now Rick Gasper From:
[EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Mulnick, Al This stands out Pre-authentication failed: From:
[EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Gasper, Rick The program uses apache, I am still
working with the vendor on this. This is the error from the DC: Event Type:
Failure Audit Event Source: Security Event
Category:
Account Logon Event
ID: 675 Date:
8/5/2004 Time:
3:15:59 PM User:
NT AUTHORITY\SYSTEM Computer:
KINGS-DC01 Description: Pre-authentication failed:
User Name: ricktest
User
ID:
KINGS\ricktest
Service Name: krbtgt/KINGS.EDU
Pre-Authentication Type:
0x0
Failure Code: 0x19
Client Address: 10.1.18.48 For more information, see Help and Rick Gasper From:
[EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Mulnick, Al There are tools to monitor kerberos
conversations (capture), but I think you're likely better off using
success/failure audit logging to see what's going on, what's being attempted
and where authentication is failing. I think the following is most likely to be
helpful http://support.microsoft.com/default.aspx?kbid=326985 From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On
Behalf Of Gasper, Rick Question,: is there a utility that would
use Kerberos to login (Kind of like a test login utility)? We are not experiencing any problem with
logins anywhere (except as mentioned).. This is the first non windows
application we are deploying that uses Kerberos (outside of windows). IT does
recognize a bad password as a bad password, but throws an error with the
correct password is given: ERROR(1006) Rick Gasper From:
[EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Mulnick, Al So that leads to the next question then:
do you have a problem going on? If so, can you give some details? Al From:
[EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Gasper, Rick The application is called WebCT. www.webct.com. It is a distance learning app
that runs off a web server. Their documentation is some what lacking, and their
support is not really that good. I do have everything set up as they
request, so I was thinking that my problem is on my end. I do have a support call scheduled with
them later today. I wanted to try to rule out a AD problem. Thanks Rick Gasper From:
[EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Mulnick, Al Sorry Rick. Thread overlap. :) Whether or not you need to make a change
depends on the application. For example, if they use the operating system
to handle the authentication calls, then it should work fine, right? If they do
something else, they should have documented it and should tell you what is
needed. What is the application saying they need to do? Which
application is it out of curiosity? Al From:
[EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Gasper, Rick I think we have a miscom here: I have no
5.5 server-- I assume that you mean exchange 5.5 (we are all ex2k3). More details: I have an app that runs on a win2k3 that
uses either LDAP or Kerberos to authenticate it’s users against our 2003
active directory. The app server is part of our domain but the app that runs on
it is a third party app that says it can authenticate using Kerberos or LDAP. My question is: Do I need to do anything
to our Domain controller to allow the app to talk to the domain controller? Thanks, Rick Gasper From:
[EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Mulnick, Al Before going any further, how about trying
to get the information from a 5.5 server locally using the admin utility? The goal of looking there is to isolate
whether the problem is on the 5.5 side or if the problem is elsewhere; just
need to rule out there's a problem with the 5.5 admin :) Al From:
[EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Gasper, Rick It is also windows 2003, but the software
is a web app (webct). I am confused as the whether the OS it doing the
authentication or the app is. Rick Gasper From:
[EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Mulnick, Al What OS is the remote system and how is it
connected? From:
[EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Gasper, Rick Quick
question: Does
anyone have place they could point me to? I have the Kerberos trouble shooting
guide and am working through this. Thanks Rick Gasper |
Title: Kerberos question
- Re: [ActiveDir] Unlock user account in mass Robert N. Leali
- Re: [ActiveDir] Unlock user account in mass James_Day
- RE: [ActiveDir] Unlock user account in mass Brian Desmond
- RE: [ActiveDir] Unlock user account in mass Robert N. Leali
