Re: [cifs-protocol] Status: SRX091220600031 [MS-ADTS] 7.1.6.7.3 msDs-supportedEncryptionTypes usage

2010-01-11 Thread Matthieu Patou
Hello Bill, Sorry for the late answer, holidays holidays and holidays ... So this email brings some answers to some of my questions some remains not clear for me. First this page

[cifs-protocol] DPAPI interaction with Active Directory

2010-01-11 Thread Matthieu Patou
Hello, In this page http://msdn.microsoft.com/en-us/library/ms995355.aspx it is stated: When a computer is a member of a domain, DPAPI has a backup mechanism to allow unprotection of the data. When a MasterKey is generated, DPAPI talks to a Domain Controller. Domain Controllers have a

Re: [cifs-protocol] FW: FW: Inconsistencies in ad-schema docs and text files SRX090109601490

2010-01-11 Thread Hongwei Sun
Andrew, Most of the issues mentioned in your mail have been fixed in the latest released MS-ADSC or MS-ADA3. The following is a summary. 1. cn: Computer - Schema pulled from Windows 2008R2 shows two additional attributes for systemMayContain msTSSecondaryDesktopBL, msTSPrimaryDesktopBL.

[cifs-protocol] [REG:110011157366122] Initial Response

2010-01-11 Thread Hongwei Sun
Hello Matthieu, Thanks for your question. We will investigate it and let you know if we need any additional clarification. Best Regards, Hongwei Sun Email: hongw...@microsoft.com Phone: +1 (469) 7757027 Time zone: (UTC-06:00) Central Time (US and Canada) -Original Message- From:

Re: [cifs-protocol] FW: FW: Inconsistencies in ad-schema docs and text files SRX090109601490

2010-01-11 Thread Hongwei Sun
Tridge Andrew, I am owning this request now. I will investigate it and let you know. Bt the way, I already responded to the initial questions from Andrew in a separate mail. Thanks! Hongwei -Original Message- From: cifs-protocol-boun...@cifs.org

Re: [cifs-protocol] FW: FW: Inconsistencies in ad-schema docs and text files SRX090109601490

2010-01-11 Thread Andrew Bartlett
On Mon, 2010-01-11 at 15:23 +, Hongwei Sun wrote: Andrew, Most of the issues mentioned in your mail have been fixed in the latest released MS-ADSC or MS-ADA3. The following is a summary. The schema of Windows 2008 R2 we sent you in 04/24/2009 doesn't incorporate the above

Re: [cifs-protocol] FW: FW: Inconsistencies in ad-schema docs and text files SRX090109601490

2010-01-11 Thread Hongwei Sun
Andrew, At this moment, I am now going through the diff reports pointed by Tridge. For adminDescription and adminDisplayName, it looks like that they are already included in the schema file (MS-AD_Schema_2K8_R2_Attributes.txt). Have I missed something ? cn: Admin-Description

Re: [cifs-protocol] FW: FW: Inconsistencies in ad-schema docs and text files SRX090109601490

2010-01-11 Thread tridge
Hi Hongwei, For adminDescription and adminDisplayName, it looks like that they are already included in the schema file (MS-AD_Schema_2K8_R2_Attributes.txt). Have I missed something ? Each attribute and class in the schema should have an adminDescription and adminDisplayName

Re: [cifs-protocol] FW: FW: Inconsistencies in ad-schema docs and text files SRX090109601490

2010-01-11 Thread Hongwei Sun
Trige, According to schema class document (MS-ADSC), The adminDescription and AdminDisplayName are listed as systemMayContain instead of SystemMustContain in cn:Top. The sub-level class attributeSchema and classSchema also don't require these two attributes as SystemMustContain.

Re: [cifs-protocol] FW: FW: Inconsistencies in ad-schema docs and text files SRX090109601490

2010-01-11 Thread tridge
Hi Hongwei, According to schema class document (MS-ADSC), The adminDescription and AdminDisplayName are listed as systemMayContain instead of SystemMustContain in cn:Top. yep The sub-level class attributeSchema and classSchema also don't require these two attributes as