RE: [ActiveDir] os version

2003-08-14 Thread Joe
Check out gettype from the reskit. It will return a string and an errorlevel based on the OS. joe -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Graham Turner Sent: Thursday, August 14, 2003 7:09 AM To: [EMAIL PROTECTED] Subject: [ActiveDir] os vers

RE: [ActiveDir] Settign password Expiration date

2003-08-14 Thread W2K List
Password policies can only be set at the domain level. Dennis Depp _ From: Erick Christian [mailto:[EMAIL PROTECTED] Sent: Wednesday, August 13, 2003 1:17 PM To: [EMAIL PROTECTED] We are rolling our W2k network out, and have successfully migrated from NT4.0. Previously we had sat ou

RE: [ActiveDir] OT: Has anyone had a problem with the RPC call to the OS

2003-08-14 Thread Bryan Schlegel
Title: Message We got smoked yesterday around 1:00.  It was difficult to troubleshoot what was going on because I couldn't figure out how it was replicating through the network.  Some machines had symptoms and others didn't (some machines had patches applied). Our symptoms included problems

Re: [ActiveDir] Who's online

2003-08-14 Thread Glenn Corbett
Agung,   this was covered recently, mainly centered around the LastLogin attributes in AD.   Tio find out who actually has a connection to the server, you can use the built in admin tools to see who has a connection to a share (useful for looking at home drive servers prior to restarts), or u

RE: [ActiveDir] LDAP & LastLogin for Computers

2003-08-14 Thread Coleman, Hunter
Title: LDAP & LastLogin for Computers I'm getting the computer "lastlogin" attribute, which as I understand it is the most recent time that the workstation authenticated to a domain controller. I believe the oldest this timestamp would be is the last time the machine started up. Also, lastlog

[ActiveDir] Scripting ACEs

2003-08-14 Thread Coleman, Hunter
I'm seeing a discrepancy between setting ACEs through the GUI (Security tab on an object) and setting them through a script. If I go into the Security Tab on an OU and set a Deny ACE for some global group on "Change Password" and "Reset Password" for User objects, I end up with a single Deny ACE fo

RE: [ActiveDir] Choosing between Domain Controllers

2003-08-14 Thread Chianese, David P.
Title: Message Answer to question #1.) type "set" at the command prompt, look for LOGONSERVER=server name.   Answer to question #2.) \\HKEY_CURRENT_USER\Volatile Environment\LOGONSERVER   I'm not sure about changing the reg key or if it defaults back as the environment variable is loaded.  Perh

[ActiveDir] Max Connections?

2003-08-14 Thread Richard Sumilang
I'm using a Windows 2000 Server computer as a File Server but sometimes people have trouble connecting to it and they are on the local network. This network is very very small (about 10 users) and yet sometimes some people cannot connect to the file server so I'm wondering if there is a Maximum

[ActiveDir] Choosing between Domain Controllers

2003-08-14 Thread Kevin Felker
Title: Message Hi all,   We’re running two domain controllers on the same domain.   My questions are    i.  what command can you run to see which one your client pc is

RE: [ActiveDir] Broken RPC between DC's

2003-08-14 Thread Myrick, Todd (NIH/CIT)
You can use PORTQRY to tickle the RPC port 135 and see what is listening. I would also try 137 and 138 UDP respectively. Then check the router configuration to see what it's settings are. Toddler -Original Message- From: Ian Moran [mailto:[EMAIL PROTECTED] Sent: Thursday, August 14, 20

RE: [ActiveDir] Max Connections?

2003-08-14 Thread Myrick, Todd (NIH/CIT)
I would go into the Network Connections and select the network adapter on the server. On the Microsoft File and Print item, select properties. And make sure the settings are optimizes for file and print sharing. Next you could pull up perfmon and see what the network usage is for the box, and nu

RE: [ActiveDir] Max Connections?

2003-08-14 Thread Chianese, David P.
Check the Maximum users at the share level perhaps. That is the only place I can think of to limit it. The other option is to look in perfmon and see if it is an actual I/O issue. Also, make sure the NIC(s) are set to 100/Full duplex. Hope this helps, Dave -Original Message- From: Ric

RE: [ActiveDir] Max Connections?

2003-08-14 Thread Bryan Schlegel
Maybe a DNS in resolving the ip address to the computer name? Can you ping the server from their desks? How are their drives mapped? -Original Message- From: Chianese, David P. [mailto:[EMAIL PROTECTED] Sent: Thursday, August 14, 2003 1:16 PM To: '[EMAIL PROTECTED]' Subject: RE: [Active

RE: [ActiveDir] os version

2003-08-14 Thread Free, Bob
Knew that :-] ...but...I was giving a simple solution to the _specific_ situation asked for >>techniques of differentiating between Windows 2000 / NT4 Unless I misread the question... -Original Message- From: Cathy Hooper [mailto:[EMAIL PROTECTED] Sent: Thursday, August 14, 2003 8:41 A

RE: [ActiveDir] Group Policy and IE Zone Security

2003-08-14 Thread Charles Campbell
Title: Message Okay… This is what I have found in the userenv.log so far:   ProcessGPOs: Processing extension Internet Explorer Branding ProcessGPOs: Extension Internet Explorer Branding skipped with flags 0x7 (Which should be fine since I don’t use the GP to brand IE) ProcessGPOs: Pr

[ActiveDir] how to identify what got changed in a user's account?

2003-08-14 Thread Thommes, Michael M.
Hi, I am trying to identify exactly what got changed in a user's account (W2K domain). I know that a change will create a Security log record, EventID 642, category "Account Management", type "Success". It will identify the account that got changed ("Target Account ID") and who made the ch

RE: [ActiveDir] WOT Unreadable code (was Connection String)

2003-08-14 Thread Roger Seielstad
In a secure environment like Todd lives in, it would make the cross-firewall replication a fairly simple matter - one well known port and proper DNS is all that it would take to pass the required replication traffic around. -- Roger D. Se

RE: [ActiveDir] OT: Patch Management

2003-08-14 Thread Rod Trent
SMS with the SUS Feature Pack. -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Mitch Reid Sent: Friday, August 08, 2003 3:26 PM To: [EMAIL PROTECTED] Subject: [ActiveDir] OT: Patch Management Hi, we finally 'found' some money to purchase software that wi

[ActiveDir] [OT] RPC DCOM WORM (MSBLASTER)

2003-08-14 Thread Joe
In case you been sleeping on the RPC DCOM hole (MS03-26), the time to patch was a couple of weeks ago, but if you still didn't... Duck... No actually patch! Now is not the time for your company to discover that a firewall doesn't protect all entrances to your network. http://isc.sans.org/diary.

RE: [ActiveDir] WOT Unreadable code (was Connection String)

2003-08-14 Thread Rick Kingslan
Well, let's think for just a minute about this. If we're talking about a WAN-based network, couldn't the end-point devices (routers, firewall, bastion, etc.) be the terminus for the IPSec tunnel? And, if so, who cares what the clients speak? Seems to me that this would resolve many of the issues

Re: [ActiveDir] Active Directory Replication Failure

2003-08-14 Thread Glenn Corbett
Keith, 5 months is a long time to be off the air, and yes, AD does go 'stale' after a period of time (60 days ?). Had to plan for this on a worldwide rollout where server may be in transit for several months after being built in head office. One of the solutions was to send the server to the rem

RE: [ActiveDir] OT: Server Monitoring

2003-08-14 Thread Rod Trent
Try MOM. http://www.microsoft.com/mom When the email server is down, you can use scripts to send email via SMTP. -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Salandra, Justin A. Sent: Tuesday, August 05, 2003 4:35 PM To: ActiveDir (E-mail) Subject: [

RE: [ActiveDir] LDAP & LastLogin for Computers

2003-08-14 Thread England, Christopher M
Title: Message Well, "pwdLastChanged" or "LastLogin" or other variations are all for User objects. Oh well, thanks for all your advice, all!   Chris -Original Message-From: England, Christopher M Sent: Wednesday, August 06, 2003 9:22 AMTo: [EMAIL PROTECTED]Subject: [ActiveD

RE: [ActiveDir] Anonymous Logon

2003-08-14 Thread Rick Kingslan
:o) My security logs are 180MB. Rick Kingslan MCSE, MCSA, MCT Microsoft MVP - Active Directory Associate Expert Expert Zone - www.microsoft.com/windowsxp/expertzone -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Rittenhouse, Cindy Sent: Wednesday, A

RE: [ActiveDir] find out with VBS: domain trusts

2003-08-14 Thread Myrick, Todd (NIH/CIT)
You can use NETDOM.EXE to do the trust and NLTEST to do the Windows 2000 trust and site views, we like to use batch files when possible to gather information quickly. Then we use a command line utility to send email to our inboxes. I am not sure if it fits into the inprocess method you were look

RE: [ActiveDir] Group Policy Monitoring Tool

2003-08-14 Thread Free, Bob
Title: Group Policy Monitoring Tool > I came across a tool called "Active Administrator" from Sunbelt Software.   I liked it when I looked at it in beta. Nice company to deal with if you get it from the source (smallwonders) they are very attentive and you can talk directly to the develop

RE: [ActiveDir] WOT Unreadable code (was Connection String)

2003-08-14 Thread Roger Seielstad
I'd look at it as two separate problems - infrastructure services and client services. On the infrastructure side, I'd consider using IPSec (tunnelling only, not encryption) for RPC based services because of their natural disdain for firewalls. Things like DNS and SMTP mail flow are easily dealt w

RE: [ActiveDir] ISA & FE combination - Load Balancing Help

2003-08-14 Thread Shawn.Hayes
Title: Message www.isaserver.org     Shawn -Original Message-From: Morley, Scott [mailto:[EMAIL PROTECTED] Sent: Wednesday, August 13, 2003 3:51 PMTo: [EMAIL PROTECTED]Subject: [ActiveDir] ISA & FE combination - Load Balancing Help All,   I 've been scramblin

RE: [ActiveDir] Groups and OU's

2003-08-14 Thread Cary, Mark
From what I understand, OUs should be created for who will administer the resources (users, computers, groups) in them.  Beyond that it is strictly organizational ease-of-use.  I tend to think of OUs as mini-domains.    -Original Message-From: Ellis, Debbie [mailto:[EMAIL PROTE

RE: [ActiveDir] [OT] RPC DCOM WORM (MSBLASTER)

2003-08-14 Thread Hutchins, Mike
Lol... :-) -Original Message- From: Joe [mailto:[EMAIL PROTECTED] Sent: Monday, August 11, 2003 5:41 PM To: [EMAIL PROTECTED] Subject: [ActiveDir] [OT] RPC DCOM WORM (MSBLASTER) In case you been sleeping on the RPC DCOM hole (MS03-26), the time to patch was a couple of weeks ago, but if

Re: [ActiveDir] Connection String

2003-08-14 Thread Glenn Corbett
>From the online help about NameTranslate, VBScript Example (havent tried it, but looks like it should work) Dim nto const ADS_NAME_INITTYPE_SERVER = 2 const ADS_NAME_TYPE_1779 = 1 const ADS_NAME_TYPE_NT4 = 3 server = "aDsServer" user = "jeffsmith" dom= "Fabrikam" passwd = "

[ActiveDir] changing home drive problem

2003-08-14 Thread Gasper, Rick
HI all, I am moving home folders to a new server. Since I have thousands of users I need to script this. The script works fine, however the new home folders don't map until I go into aduc, make a change to the home folders (add a space to the end of the path then delete it) ) and hit apply. I am wo

RE: [ActiveDir] changing home drive problem

2003-08-14 Thread Roger Seielstad
Try reversing the order you set the drive letter and path, and put a .setinfo between them. -- Roger D. Seielstad - MTS MCSE MS-MVP Sr. Systems Administrator Inovis Inc. > -Original Message- > From: Gasper, Rick [mailto:[EMAIL P

RE: [ActiveDir] Connection String

2003-08-14 Thread Myrick, Todd (NIH/CIT)
Glenn is that what they make documentation and comments for? Toddler -Original Message- From: Glenn Corbett [mailto:[EMAIL PROTECTED] Sent: Tuesday, August 05, 2003 9:38 AM To: [EMAIL PROTECTED] Subject: Re: [ActiveDir] Connection String HAHAHAPerl I like to be able to read my cod

RE: [ActiveDir] LDAP & LastLogin for Computers

2003-08-14 Thread Coleman, Hunter
Title: Message Well, that wouldn't be the first time :-)   At some point I suspect I'll *need* to query for a non-replicated attribute, so it's not a totally wasted effort. Your suggestion is a better fit in this case, though. Back to visual notepad   Cheers, Hunter From: Roger Seielst

[ActiveDir] Password expiation Script

2003-08-14 Thread Clarence Heier
I need a script that will find users accounts where the password will expire in 5 days and email them. Does anyone know of a source for a script similar to this. Clarence Heier mailto:[EMAIL PROTECTED] List info : http://www.activedir.org/mail_list.htm List FAQ: http://www.activ

RE: [ActiveDir] OT: Packaging Software for Deployment

2003-08-14 Thread Rick Kingslan
Justin, Being a part of your HIPAA requirement solution, it would be somewhat imperative to get it righ the first time and know that you're in compliance, right? Given that, and the specifics of compliance under HIPAA (generally impossible, so why try) I'd suggest a mechanism that is going to

RE: [ActiveDir] VBscript Help

2003-08-14 Thread lfriedland
I keep a list of these sites - hope this helps (watch for URL wrap): (may be dups from others in list) http://msdn.microsoft.com/scripting -- Microsoft's scripting site http://www.microsoft.com/technet/treeview/default.asp?url=/technet/scriptcen ter/default.asp -- Another Microsoft scripting sit

RE: [ActiveDir] Password Lookup

2003-08-14 Thread Puckett, Richard
Title: Message   Ryan,   If you're asking this because you're doing a security/password strength analysis sweep, you can use a couple of different tools to do this (all of which will rely on administrative privileges to AD).  Tools like PWDUMP2 have been updated to pull password hashes from t

Re: [ActiveDir] OT: Server Monitoring

2003-08-14 Thread jim . katoe
Title: Message If you are worried about security or just lazy, look at blat. It is a commandline smtp tool.--Sent from my BlackBerry Wireless Handheld  - Original Message -  From: ActiveDir-owner  Sent: 08/07/2003 08:59 AM  To: <[EMAIL PROTECTED]>  Subject: RE: [A

RE: [ActiveDir] Groups and OU's

2003-08-14 Thread Roger Seielstad
Title: Message I'd suggest doing whatever makes sense to you, really. We have 4 basic OU's - Employees, Workstations, Servers and Groups.   Part of my rationale for having a separate OU for Groups is that I also maintain a separate recipients container in Exchange 5.5 for Distribution Lists

RE: [ActiveDir] System Shutting Down

2003-08-14 Thread Robert Moir
Or failing that, safe mode with command line to update the problem file. (back it up to another file name first) > -Original Message- > From: Joe [mailto:[EMAIL PROTECTED] > Sent: 11 August 2003 03:18 > To: [EMAIL PROTECTED] > Subject: RE: [ActiveDir] System Shutting Down > > Try coming

RE: [ActiveDir] Connection String

2003-08-14 Thread Robbie Allen
Ha! It is not the language that makes code unreadable, it is the PROGRAMMER :-) Robbie Allen http://www.rallenhome.com/ > -Original Message- > From: Glenn Corbett [mailto:[EMAIL PROTECTED] > Sent: Tuesday, August 05, 2003 9:38 AM > To: [EMAIL PROTECTED] > Subject: Re: [ActiveDir] Connec

RE: [ActiveDir] Password expiation Script

2003-08-14 Thread Rick Kingslan
Here's a starter - it's far from done as the e-mail pieces will need to be added and the logic added to determine a given expiration date, then act on it. http://www.microsoft.com/technet/treeview/default.asp?url=/technet/scriptcen ter/user/ScrUG17.asp Hope this helps you get started. Rick Kings

RE: [ActiveDir] How to force RID master change

2003-08-14 Thread Chianese, David P.
NTDSUTIL.EXE, follow the prompts to seize the roll. NOTE: Once you seize this roll make sure the dead RID is offline and fdisk'd as you never want that server to come back and start servicing DC's with its old RID pool. The new RID master will artificially inflate the RID pool to a higher number a

Re: [ActiveDir] Max Connections?

2003-08-14 Thread Richard Sumilang
I went there and the radio button is set to "Maximize data throughput for file sharing". This problem starter happening before the blaster worm went out. Where would I check is the settings are set to auto negotiate and the set port thing? Thanks - Richard S. On Thursday, August 14, 2003, at 1

RE: [ActiveDir] LDAP & LastLogin for Computers

2003-08-14 Thread Bjelke John A Contr AFRL/VSIO
Title: Message One way to go about it would be to turn up the auditing and query the event log on the machine for login success/failure events.   John A. Bjelke   Unisys 505.853.6774   [EMAIL PROTECTED] "Many of life's failures are people who did not realize

RE: [ActiveDir] Anonymous Logon

2003-08-14 Thread Rick Kingslan
Nope - MonitorWare. Tested it and it worked well in the homogenous environment. Fairly configurable and it will allow me to use eventcomb first to determine what logs I want to send. This was I can get rid of the Service and SYSTEM related events and the extraneous 'crap' (technical term, you kn

RE: [ActiveDir] Group Policy and Kiosk Mode

2003-08-14 Thread Rick Kingslan
How much have you looked into the abilities of loopback processing and forcing the IE format, form and function via that method of applying and enforcing both user and computer settings with no user actually logging on? Rick Kingslan MCSE, MCSA, MCT Microsoft MVP - Active Directory Associate Expe

[ActiveDir] Group Policy and IE Zone Security

2003-08-14 Thread Charles Campbell
For the life of me… I’m being plagued with problems now. On the server, I set up the GPO to reflect certain sites under the Intranet and Trusted sites. I also set the GPO to disable the users ability to add/remove sites, and change their home page.   As of right now, users can not add/re

RE: [ActiveDir] Group Policy

2003-08-14 Thread Darren Mar-Elia
Debbie- Go here to get an Excel spreadsheet that lists all of the .adm settings that come out of the box: http://www.microsoft.com/downloads/details.aspx?displaylang=en&familyid= 7821c32f-da15-438d-8e48-45915cd2bc14 Darren -Original Message- From: Ellis, Debbie [mailto:[EMAIL PROTECTED]

RE: [ActiveDir] WOT Unreadable code (was Connection String)

2003-08-14 Thread Roger Seielstad
Hmmm... What would make sense to me is if the option for site replication via SMTP actually worked intra-domain rather than cross domain only. That solves probably 90-some percent of the issues involved in site replication. Roger -- Roger

RE: [ActiveDir] Anonymous Logon

2003-08-14 Thread Free, Bob
>Since I'll need a syslog server, I'd like one that will also work with the logs on >our Cisco >devices? Sorry on monitorware, but KIWI is a very popular free Win32 implementation with folks in mixed MS/Cisco environments who just want to syslog, say Windows, Cisco routers and PIX's. http://ww

RE: [ActiveDir] VBscript Help

2003-08-14 Thread Carlos Magalhaes
Hi Jacqui,   (PLEASE WATCH FOR URL WRAPPING!) I do have a few I could mention, one tool you absolute need when scripting using VBScript for Ad is the ADSI scriptomatic you can obtain it here: http://www.microsoft.com/downloads/details.aspx?FamilyId=39044E17-2490-487D-9A92-CE5DCD311228&d

RE: [ActiveDir] Password Lookup

2003-08-14 Thread rmcdonald
Where can I find the scripts and where can you set the password complexity? Thanks Ryan McDonald Systems Administrator The Bankers Bank "Thommes, Michael M." <[EMAIL PROTECTED]> Sent by: [EMAIL PROTECTED] 08/05/2003 10:39 AM Please respond to ActiveDir                 To:        <[EMAIL

Re: [ActiveDir] LDAP & LastLogin for Computers

2003-08-14 Thread Jan Wilson
Title: LDAP & LastLogin for Computers What - if any  - login script tool do you use? We keep every login (time -date - IP - computer name - user name) in one huge text - each month werename and collect the next month's data. We use KIX - Original Message - From: Glenn Corbe

RE: [ActiveDir] LDAP & LastLogin for Computers

2003-08-14 Thread Coleman, Hunter
Title: LDAP & LastLogin for Computers I've sent you off-list a copy of a script we use to get this information. Hope it helps   Hunter From: England, Christopher M [mailto:[EMAIL PROTECTED] Sent: Wednesday, August 06, 2003 8:22 AMTo: [EMAIL PROTECTED]Subject: [ActiveDir] LDAP & LastLogin f

RE: [ActiveDir] Groups and OU's

2003-08-14 Thread Myrick, Todd (NIH/CIT)
Title: Message Nice way to separate out Data Administration from Directory Level Administration.    Toddler -Original Message-From: Ellis, Debbie [mailto:[EMAIL PROTECTED] Sent: Monday, August 11, 2003 8:19 AMTo: [EMAIL PROTECTED]Subject: RE: [ActiveDir] Groups and OU's

RE: [ActiveDir] Non-dictionary passwords

2003-08-14 Thread Joe
Title: Message You can't do this natively but you can write a password filter DLL to hook into the LSASS to do it. It isn't a trivial experiment as bad code will do bad things since it is running as LSASS and when LSASS gets cranky, blue tends to be your predominant screen theme color.   Th

[ActiveDir] OT: Patch Management

2003-08-14 Thread Mitch Reid
Hi, we finally 'found' some money to purchase software that will help with patch management. I was wondering if anybody has suggestions what I should look at (and what not to look at). We have about 300 local servers and a handful more across the WAN. They're NT, 2000 and 2003 in an NT/AD multi-

RE: [ActiveDir] How to force RID master change

2003-08-14 Thread daniel . gilbert
One thing to do is use NTDSUTIL to sieze the RID master role. Remove all references to the failed DC in AD (ADSI edit, Sites and Services, DNS,) Let replication update all DC's. You should then be able to bring the server back using it's original name. HTH -Original Message- From:

[ActiveDir] Broken RPC between DC's

2003-08-14 Thread Ian Moran
Strange one this. Two DC's, same site, different subnets separated by a router. Clients on subnet A can net view \\serverB, clients on subnet B can net view \\serverA - but serverA & serverB cannot net view each other - iyswim. Almost like a broken netbios channel between just these two servers Se

RE: [ActiveDir] OT: VPN agreement

2003-08-14 Thread Raymond McClinnis
We do allow them to use their home PC's, but require Windows 2000/XP as a minimum, A common AV Client (Norton, McAfee, etc) with up to date definitions, a Personal Firewall of some sort (I'm using Norton, someone else said the FW built into XP is decent, although not great). Our worries are about

Re: [ActiveDir] VBscript Help

2003-08-14 Thread Glenn Corbett
if you want "hackable" scripts etc, then a good source is http://cwashington.netreach.net/, has lots of scripts and tools around network administration. Most are nicely documented, so can work out how to do things from there. They have some resources there on undertsanding things like LDAP query f

Re: [ActiveDir] VBscript Help

2003-08-14 Thread Tony Murray
Jacqui There are some links to ADSI and scripting resources on the ActiveDir web site: http://www.activedir.org/links.htm Carlos probably has more. One link I have yet to put up on the ActiveDir web site is to Robbie Allen's code from his Cookbook. This is an excellent resource and pretty muc

RE: [ActiveDir] Anonymous Logon

2003-08-14 Thread Roger Seielstad
How are you sending the Windows event logs to a syslog server? Is that Kiwi as well? -- Roger D. Seielstad - MTS MCSE MS-MVP Sr. Systems Administrator Inovis Inc. > -Original Message- > From: Rick Kingslan [mailto:[EMAIL PROTECT

RE: [ActiveDir] Password change issue

2003-08-14 Thread Rick Kingslan
And, to further add to the sage advice of Mr. Richards - remember that you CAN call Microsoft and get these fixes at NO CHARGE. You will have to give a credit card number to get past the PSS Call Router (the warm body that takes your name, gets the initial information and then passes you on to the

Re: [ActiveDir] System Shutting Down

2003-08-14 Thread Richard Sumilang
Cool but how am I supposed to install a new service pack if the computer reboots every 60 seconds when the message comes up? On Saturday, August 9, 2003, at 05:26 AM, Thommes, Michael M. wrote: Check out http://support.microsoft.com/default.aspx?scid=kb;EN-US;q284003 Mike Thommes -

Re: [ActiveDir] WOT Unreadable code (was Connection String)

2003-08-14 Thread Glenn Corbett
Agreed Rick. Since the internal network is trusted (I assume), you only need to do the encryption between the trusted networks over an untrusted connection. Terminating the connection on the bastion hosts / firewalls etc means that the Windows boxes don't know / don't care if there is encryption b

Re: [ActiveDir] LDAP & LastLogin for Computers

2003-08-14 Thread Glenn Corbett
LDAP & LastLogin for ComputersThanks hunter. here is some code to determine all DC's in the AD domain (so you dont need to hardcode the DC server list). It doesnt take into account the relative site topology. This routine basically returns a collection of DC's, with the server name, and FQDN of t

RE: [ActiveDir] The Truth Is Out There:

2003-08-14 Thread Bjelke John A Contr AFRL/VSIO
James, I had similar issues on my home network from my desktop firewall blocking on netbios resolution. The other possibility is that who ever is the browse master has gone stupid and needs a reboot :^) John A. Bjelke Unisys 505.853.6774 [EMAIL PROTECTE

RE: [ActiveDir] Groups and OU's

2003-08-14 Thread James_Day
Return Receipt Your RE: [ActiveDir] Groups and OU's document :

RE: [ActiveDir] OT: Packaging Software for Deployment

2003-08-14 Thread Salandra, Justin A.
The setup command part, would that be the UNC path to the install? Also, will the install run as administrator or as the user? Will the user be prompted to do anything during installation? -Original Message- From: Rod Trent [mailto:[EMAIL PROTECTED] Sent: Wednesday, August 06, 2003

RE: [ActiveDir] Synchronize AD

2003-08-14 Thread Dipowarga Wirawan
Thanks all for the help..:) I'll try it. Dipo -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] Sent: Wednesday, August 06, 2003 7:29 PM To: [EMAIL PROTECTED] Subject: RE: [ActiveDir] Synchronize AD or replmon |+--> |

RE: [ActiveDir] Group Policy

2003-08-14 Thread Bjelke John A Contr AFRL/VSIO
http://www.microsoft.com/WindowsXP/pro/techinfo/productdoc/gpss.asp John A. Bjelke Unisys 505.853.6774 [EMAIL PROTECTED] Computers are like Old Testament gods; lots of rules and no mercy. - Joseph Campbell -Original Message- From: Ellis, Debbie [mai

Re: [ActiveDir] System Shutting Down

2003-08-14 Thread John Witasick
What version SP or SRP are you running?  What happens when you boot into Safe Mode?   http://support.microsoft.com/default.aspx?scid=kb;EN-US;Q300038   http://support.microsoft.com/default.aspx?scid=kb;EN-US;306497   http://support.microsoft.com/default.aspx?scid=kb;en-us;q318650   John W --

RE: [ActiveDir] Group Policy and IE Zone Security

2003-08-14 Thread Darren Mar-Elia
Title: Message Charles- Just out of curiosity, are you using preference mode settings here? Things to check:   -- Make sure you don't have any local GPO IE settings defined. Highly unlikely but worth checking. -- Enable verbose userenv.log logging to see if you can get a clue as to why this

RE: [ActiveDir] Home Labs Interconnected

2003-08-14 Thread Joe
I agree with Gil. You would really need to back down the number of people with full control and only give delegated rights out to the majority and big changes (topology, Schema, etc) would have to be put through committee and then agreed by the majority and then sent to whomever holds the keys. T

[ActiveDir] Disaster recovery scenario comments requested.

2003-08-14 Thread Chianese, David P.
All, I want to run this DR situation by the group and see if anyone else can identify any "gotcha's" in the process. We are currently testing out a DR scenario that involves off-site Domain controllers at a recovery center. During normal operations the DR DC's are linked to our network via VPN

RE: [ActiveDir] Seeking some feedback ... use of 2003 Admin. tools against a non-forest prep'd 2000 only directory ...

2003-08-14 Thread Dean Wells
Hi David,   Many consumers of Active Directory are more than hesitant to extend their schema (this is by no means the first time I've encountered this kind of resistance). Much of the cause is generally related to the somewhat extreme warnings both within the product and in numerous publica

RE: [ActiveDir] Anonymous Logon

2003-08-14 Thread Rick Kingslan
Bob, Thanks for bringing these up. I've read through these (which drove much of our efforts for our syslog server) and am quite pleased with where we are and how we're eventually going to get there. Now, all I need is a crap-load of space and a Security Analyst with time to comb the 'intersting'

RE: [ActiveDir] Who's online

2003-08-14 Thread Joe
NET SESSION can only be used locally but you can use RCMD or psexec or something like that to get a remote console shell on the remote box. Alternatively I wrote a quick little basic tool to do it remotely as well, look for netsess on www.joeware.net on the free win32 tools page. F:\Dev\cpp\NetSe

Re: [ActiveDir] Turn off account lockout feature on a account.

2003-08-14 Thread rick reynolds
Title: Message system account - Original Message - From: Myrick, Todd (NIH/CIT) To: '[EMAIL PROTECTED]' Sent: Thursday, August 07, 2003 9:54 PM Subject: RE: [ActiveDir] Turn off account lockout feature on a account. Thanks Joe,   Just wanted to

RE: [ActiveDir] os version

2003-08-14 Thread Free, Bob
190899 - How to Determine the OS Type in a Logon Script: http://support.microsoft.com/default.aspx?scid=kb;[LN];190899 You can obtain Gettype.exe version 4.0 from by installing the Windows 2000 Resource Kit Tools. Gettype.exe works by querying the registry for the installation type and setting

RE: [ActiveDir] Synchronize AD

2003-08-14 Thread Dipowarga Wirawan
Title: Message I don't have problem in the past.  Just recently it won't synchronize.  I heard before that we could force synchronize.   Dipo -Original Message-From: Gil Kirkpatrick [mailto:[EMAIL PROTECTED]Sent: Wednesday, August 06, 2003 1:41 PMTo: '[EMAIL PROTECTED]'Subject

RE: [ActiveDir] Password Lookup

2003-08-14 Thread Robbie Allen
Title: Message I don't believe MS does, but there are a few scripts/tools on the net that can be used to do it.  Have you enabled password complexity, which prevents the use of dictionary passwords?  Do you have account lockout enabled?  It is much harder (i.e. time consuming) to perform di

[ActiveDir] OT: VPN agreement

2003-08-14 Thread Raymond McClinnis
Sorry to post off topic, but with all the experience on this list I know someone will have a quick answer so we can kill it quickly. Does anyone have a good "policy manual" type VPN agreement? Up until recently VPN was reserved for VP's and above and the IT Department, but now the VP's want other

[ActiveDir] Groups and OU's

2003-08-14 Thread Ellis, Debbie
Is it advisible to have an OU for Groups? What are the pros and cons?  I want a very simple and basic OU structure.

RE: [ActiveDir] Home Labs Interconnected

2003-08-14 Thread James_Day
Return Receipt Your RE: [ActiveDir] Home Labs Interconnected document :

RE: [ActiveDir] [OT] RPC DCOM WORM (MSBLASTER)

2003-08-14 Thread james . blair
Charles, Our remote satellite sites were hit and infected 3/7 (broadband satellite), Internally no problems. Info @: Trend describes best way to do a manual removal. Easy Way: If you were infected and PC keeps restarting goto Services-Remote Procedure Call (RPC). Right Mouse Click goto Properti

[ActiveDir] Turn off account lockout feature on a account.

2003-08-14 Thread Myrick, Todd (NIH/CIT)
Title: Message Does anyone know how to disable account lockout restrictions on a account Like a service account, but leave the rest of the accounts with the ability to be locked out?   Thanks,   Toddler

RE: [ActiveDir] Disaster recovery scenario comments requested.

2003-08-14 Thread Joe
Actually VMWare or more likely Virtual Server are what we are *starting* to look at for a DR system. Basically the idea is to have a couple of nice sized Physical Servers running multiple virtual servers that are domain controllers for all Domains in the Forest. Every night one of the P-Servers shu

RE: [ActiveDir] LDAP search filter for enabled accounts ?

2003-08-14 Thread Fugleberg, David A
Jerry - Thanks ! Works like a charm. Dave -Original Message- From: Jerry Welch [mailto:[EMAIL PROTECTED] Sent: Thursday, August 14, 2003 1:55 PM To: [EMAIL PROTECTED] Subject: RE: [ActiveDir] LDAP search filter for enabled accounts ? Dave, As I understand it, the following identifies a

Re: [ActiveDir] Choosing between Domain Controllers

2003-08-14 Thread James_Day
>From the command prompt on the client machine you can type set This will give you the local variables including the login domain controller. Hope this helps. James R. Day (202) 354-1464 [EMAIL PROTECTED] |-+--> | | "Kevin Felker"

RE: [ActiveDir] Who's online

2003-08-14 Thread Thommes, Michael M.
Hi Agung, I think the command is used on the local computer only. But I think you could download the freeware from Sysinternals (www.sysinternals.com) named "psexec" and then use the following syntax: psexec \\ComputerName net session Mike Thommes -Original Message-

RE: [ActiveDir] VBscript Help

2003-08-14 Thread Steven Peck DNET
On a last note, the Windows Scripting Guide is online at MS http://www.microsoft.com/technet/treeview/default.asp?url=/technet/scriptcen ter/scrguide/sas_roa_overview.asp In case you forget the book at home or are broke. :) -sp > -Original Message- > From: [EMAIL PROTECTED] > [mailto

[ActiveDir] LDAP & LastLogin for Computers

2003-08-14 Thread England, Christopher M
Title: LDAP & LastLogin for Computers Greetings all, I am trying to pull LDAP queries on computer accounts and I want to find out the last time someone logged into the machine. "WhenModified" is just the computer account object and "LastLogin" is just for user accounts. Am I out of luck? W

Re: [ActiveDir] Who's online

2003-08-14 Thread Tony Murray
Agung This was covered fairly comprehensively in a thread a few days ago. Look in the archives for the subject "Users Logged In" on 29.07.03. The lastLogoff attribute is not used. There is very little MS documentation on this. Tony -- Original Message

Re: [ActiveDir] OT: Server Monitoring

2003-08-14 Thread Glenn Corbett
Justin, servers alive does report status to a web page, so that may be the easiest way to see if your exchange servers are alive. I understand the problem, you want to receive Email to your mailbox if a server is down, BUT if its the exchange server you cant get any mail. The problem is that if

Re: [ActiveDir] Anonymous Logon

2003-08-14 Thread Glenn Corbett
Can vouch for the Kiwi server. Works great, and even better its free. G. - Original Message - From: "Free, Bob" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Thursday, August 07, 2003 6:49 AM Subject: RE: [ActiveDir] Anonymous Logon >Since I'll need a syslog server, I'd like one tha

  1   2   3   >