|
Are you publishing a CRL? If so then it must use the path to
the CRL that's specified in the certificate or it bombs out (latency to the
hosting CRL server will kill it too..forgot the exact value). Why do you
need CRL checking on your DC's? Doesn't that make you question who is on your
DC's that would make you revoke a cert among other things? I would modify the
template (if your using a Enterprise CA) and reissue the certs without
a CRL and make sure the clients have the public key to your Root CA in their
trusted root store. Something to ponder.
-Brandon From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Thommes, Michael M. Sent: Tuesday, August 22, 2006 10:36 AM To: [email protected] Subject: RE: [ActiveDir] Secure LDAP queries from the outside Hi
Robert, Yes,
the command is *exactly* the
same. We are thinking that our CRL location is not available outside of
the firewall. We generate our own certificates; we don’t use a “well
known” provider. Mike
Thommes From:
[EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]
On Behalf Of Williams,
Robert Hey
Mike, When you say “It works
fine behind our firewall”, are you meaning that the *exact same* command line works and you get
the object returned? I tried using adfind to
connect to my test DC using port 636 and got the exact same error…but I don’t
have a cert installed on my DC so I’d expect mine not to
work. Robert
Williams From:
[EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]
On Behalf Of Hi, We are trying to set up
secure LDAP queries from the outside to AD for pulling email addresses but are
running into an issue. Port 636 has been opened up to our DCs but we get a
0x51 error like the one shown below in this example of using
“adfind”: adfind -h dc1.abc.com:636 -u
[EMAIL PROTECTED] -up * -default -nodn -f sn=thommes
extensionAttribute2 AdFind V01.26.00cpp Joe Richards
([EMAIL PROTECTED]) February 2005 LDAP_BIND: [rhino221.anl.gov] Error
0x51 (81) - Server Down Terminating
program. (extensionAttribute2 is used for
email address) Portqry shows that the DC is
listening on port 636. Using “ldp”, the bind operation seems to want to
default to port 389 (which is not open). It works fine behind our
firewall. Is there some other port that needs to be open (besides
389)? Or maybe some security feature (we are running w2k3/sp1 on our DCs)
that is getting in the way? Any help is
appreciated! TIA, Mike
Thommes 2006-08-22, 10:35:32 |
- [ActiveDir] Secure LDAP queries from the outside Thommes, Michael M.
- Re: [ActiveDir] Secure LDAP queries from the o... Matheesha Weerasinghe
- RE: [ActiveDir] Secure LDAP queries from the o... Williams, Robert
- RE: [ActiveDir] Secure LDAP queries from t... Thommes, Michael M.
- RE: [ActiveDir] Secure LDAP queries fr... Williams, Robert
- RE: [ActiveDir] Secure LDAP queries fr... Thommes, Michael M.
- Re: [ActiveDir] Secure LDAP queries from the o... Tomasz Onyszko
- RE: [ActiveDir] Secure LDAP queries from the o... joe
- RE: [ActiveDir] Secure LDAP queries from the o... Bernier, Brandon \(.\)
- Re: [ActiveDir] Secure LDAP queries from t... steve patrick
- [ActiveDir] Exchange question Ramon Linan
- RE: [ActiveDir] Exchange question Akomolafe, Deji
- RE: [ActiveDir] Exchange ques... Ramon Linan
- Re: [ActiveDir] Exchange ... Al Mulnick
- RE: [ActiveDir] Excha... Ramon Linan
- RE: [ActiveDir] Excha... Brandon Pierce
- RE: [ActiveDir] Excha... Ramon Linan
- Re: [ActiveDir] Excha... Al Mulnick
- RE: [ActiveDir] Excha... Ramon Linan
