RE: [ActiveDir] GLOBAL CATALOG- WITH 2 DOMAINS

2005-05-23 Thread Mohammed_Tantawi
Dear man, The main thing which i wat to do is:- 1. i want to establish OWA for my External user. == I have the following :- 1. i have only 2 domains ( mailserver ) & ( webloc), in the same Network. 2. both domains ha

RE: [ActiveDir] Windows 2000 terminal services again

2005-05-23 Thread al_maurer
"What's the point in getting licenses if all your clients are 2k/xp then?" No point. The TS License server figures out what the OS is. This is (IMHO) needlessly complex, but here's the MS whitepaper: http://www.microsoft.com/windowsserver2003/techinfo/overview/termservlic.mspx Good luck! AL

RE: [ActiveDir] Solaris authentication

2005-05-23 Thread al_maurer
Title: RE: [ActiveDir] Ocra I have not done Solaris->AD authentication specifically, but other *nixes can be configured to authenticate to AD via Kerberos v5.  Like everyting in the Unix world, it's a-la-carte, so it's a separate module you would install in addition to the Sun LDAP package.

[ActiveDir] OT: WSUS and Windows Update GPO Settings

2005-05-23 Thread Devan Pala
Hi all, I've attached an administrative template you may find beneficial for allowing non administrators the privilege to approve or disapprove updates. I noticed that in our environment, the remote IS Administrators were not able to delay the restart of a computer (in this case a domain contr

RE: [ActiveDir] DNS oddity

2005-05-23 Thread deji
Russ, The trailing dot issue is a classic nslookup behavior (some call it bug :)). Nslookup does domain devolution on all lookups and, unless the query is terminated with a ".", any rlookup for a record will always be submitted by nslookup in the following fashion: recordname.current.dns.context.

RE: [ActiveDir] AD DR - replication lag site----Why?

2005-05-23 Thread deji
Guido, You had to go have a "great weekend" AND then have to post after the thread has been declared "complete". 2 infractions!. Your Dining Services MVP status is now officially suspended - by the special power invested in Todd :) Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCP+I Microsoft MVP

RE: [ActiveDir] NOVELL and WINDOWS 2003 AD

2005-05-23 Thread Medeiros, Jose
Hi Chadra, I am forwarding you the response from our Netware Consultant, " I'm assuming that by 'Novell' we mean 'NetWare' as Novell has different O/S platforms with different DNS servers. The newer NetWare DNS in NetWare 6.5 will support AD: http://support.novell.com/cgi-bin/search/searchti

Re: [ActiveDir] NOVELL and WINDOWS 2003 AD

2005-05-23 Thread chuckgaff
You have to use either Novell DNS if you have DNS servers running NetWare or Windows DNS as your authoritative system.  You can't have the same domain name in the way you are suggesting.  Mu advice is to use Windows 2000/2003 for your DNS which can be done by repointing the settings in NetWare in

RE: [ActiveDir] AD DR - replication lag site----Why?

2005-05-23 Thread Grillenmeier, Guido
oh, gee, I'm too late - but I had a great weekend ;-)) I'd have to say (and all the posts show themselves) that there is no single right or wrong answers to lag sites. It's one building block to mastering AD DR and may very well apply more for larger companies than for smaller ones (it's tough

RE: [ActiveDir] GLOBAL CATALOG- WITH 2 DOMAINS

2005-05-23 Thread Ruston, Neil
Are these domains part of the same forest? If so, then a trust *will* exist and a level of interop will be available. Are you able to provide further detail? neil -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Mohammed_Tantawi Sent: 23 May 2005 04:21

RE: [ActiveDir] GLOBAL CATALOG- WITH 2 DOMAINS

2005-05-23 Thread Jorge de Almeida Pinto
Do the credentials (username and password) you are using exist in both domains? What do you want to acchieve with interoperability between the environments? If users are in the first domain and need to access resources on the second domain you need a trust where the second domain trusts the first

RE: [ActiveDir] NOVELL and WINDOWS 2003 AD

2005-05-23 Thread Jorge de Almeida Pinto
Let me rephrase... You have a Novell environment that already uses the DNS domain name BLABLA.COM and you want to install W2K3 AD with the same DNS domain name and you also need interoperability between Novell and AD? This would not be possible if you were talking about 2 W2K3 domains with the sa

[ActiveDir] GLOBAL CATALOG- WITH 2 DOMAINS

2005-05-23 Thread Mohammed_Tantawi
Dear All, i have one question here:- if i have 2 Domains , one is ( mailserver.com ) & the second is ( webloc.com) installed on 2 different Server. the Both server are in the same Network ID. i mean the Domain controller which is under ( Mailserver ) is haveing this IP-Address ( 192.168.1.1

[ActiveDir] NOVELL and WINDOWS 2003 AD

2005-05-23 Thread Chandra Burra
All, Quick one please.client wants to have same domain name for the existing Novell directory and new Windows2003 AD as the same...ex; xxx.com Can this be done ...if yes, then what are the implications...and also they wanted to stay on the Novell DNS... Thanks you for inputs. Chandra List

Re: [ActiveDir] First time to subscribe

2005-05-23 Thread Peter Jessop
Mohammed You can read the replies in your e-mail or on http://www.mail-archive.com/activedir@mail.activedir.org/ Regards Peter Jessop

[ActiveDir] DNS oddity

2005-05-23 Thread Rimmerman, Russ
We have an empty root domain, and 1 child domain. When we do an nslookup on an external hostname (eg nslookup www.yahoo.com) from the child domain, we get the proper responses we'd expect. When we terminal serve to our root domain DNS and do an nslookup on the same external hostname, if we don't

[ActiveDir] First time to subscribe

2005-05-23 Thread Mohammed_Tantawi
Dear All, My name is Mohammed , I am from egypt, this is the first time i am subscribe to your list, Please reply on me if you see this E_mail.\ if i want to see the Reply, should i see it in the E-mail, or should i see it on the Web Site. Thanks & Best Regards, Mohammed List info : http

RE: [ActiveDir] "Sticky" group membership - Solved

2005-05-23 Thread Dean Wells
Hey Tony (you're alive :-), Correct, the cache is used exclusively for authentication purposes, nothing more. PS - How's life 'Down Under' and to the right a bit (well, quite a lot actually :)? -- Dean Wells MSEtechnology * Email: [EMAIL PROTECTED] http://msetechnology.com -Original Messag

RE: [ActiveDir] AD DR - replication lag site----Why?

2005-05-23 Thread Myrick, Todd (NIH/CC/DNA)
Using the powers of the MVP, I now officially pronounce this thread as complete :) Todd -Original Message- From: Jorge de Almeida Pinto [mailto:[EMAIL PROTECTED] Sent: Sunday, May 22, 2005 4:12 PM To: 'joe '; '[EMAIL PROTECTED] '; 'ActiveDir@mail.activedir.org ' Subject: RE: [ActiveDir]

Re: [ActiveDir] RPC problem on DC

2005-05-23 Thread Peter Jessop
Thanks Jorge I've just found the cause of the problem. The DC giving problems in on another LAN. I work in a ministry of an autonomous goverment. Over the weekend the people responsible for the routers cut access on various ports on all routers due to an infection of EFEWE.B Y SDBOT.67363. They we

RE: [ActiveDir] RPC problem on DC

2005-05-23 Thread Jorge de Almeida Pinto
What are event ids on the DC?   To demote the DC in a forced way: DCPROMO /FORCEREMOVAL (you need at least W2KSP4 or hotfix or W2K3)   Using this the DC will be demoted to a STAND-ALONE server (not a member server) and afterwards you need to do a metadata cleanup   Cheers, #JORGE# From: [

Re: [ActiveDir] "Access denied" connecting to remote Event Logs

2005-05-23 Thread Mark Parris
Neil Have you seen 323076 ? Mark -Original Message- From: "Ruston, Neil" <[EMAIL PROTECTED]> Date: Mon, 23 May 2005 09:13:01 To:"'ActiveDir@mail.activedir.org'" Subject: RE: [ActiveDir] "Access denied" connecting to remote Event Logs John, To re-iterate, I am using an account wi

RE: [ActiveDir] "Access denied" connecting to remote Event Logs

2005-05-23 Thread Ruston, Neil
Title: Message Bob,   I can indeed access the logs on the w2k3 DC from its own console. The account used is *not* a member of Guests.   Where is the explicit deny set and how is this visible/changed?   Guests and Domain Guests have default members [this is a test lab].   neil   -O

[ActiveDir] RPC problem on DC

2005-05-23 Thread Peter Jessop
I have a problem We have a forest with 1 domain and 3DCs. One of the DCs is having replication problems 1. Users having authentification problems. 2. Netdiag errors on DC3      "[FATAL] Secure channel to domain s broken. [ERROR_NO_LOGON_SERVER]" message from Netdiag on DC     LDAP test. . . . .

RE: [ActiveDir] "Access denied" connecting to remote Event Logs

2005-05-23 Thread Ruston, Neil
Title: Message John,   To re-iterate, I am using an account with membership of domain admins. The domain admins group has the right 'manage auditing and security logs' granted.   neil -Original Message-From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of John Po