Re: [ActiveDir] Replmon vs. dssite.msc

2006-07-22 Thread Matheesha Weerasinghe
If I understand correctly, replmon shows connection object info that was retrieved from the dc itself. dssite.msc shows the connection object info from the dc the snap-in is focused on. please correct me if i've misunderstood M@ On 7/19/06, Noah Eiger <[EMAIL PROTECTED]> wrote: Hi – I a

RE: [ActiveDir] root admin account able to be locked out?

2006-07-22 Thread Thommes, Michael M.
Title: root admin account able to be locked out? Jorge (and joe),     Thanks for your reply on this issue!   Mike Thommes   From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Almeida Pinto, Jorge de Sent: Tuesday, July 18, 2006 3:43 PM To: ActiveDir@mail.activedir.o

RE: [ActiveDir] Vendor Domain

2006-07-22 Thread Grillenmeier, Guido
> Will the application run off of an ADAM instance instead of a full blown forest?   That was going through my mind as well - why would the vendor want to use a NOS AD for his application? Again, there must be some reason for this.   joe makes great points rgd. the support issues of an appl

RE: [ActiveDir] Domain Trusts.

2006-07-22 Thread Grillenmeier, Guido
you might want to describe to us what your actual goal is for creating a non-fully trusted domain in your AD forst.  Maybe you can reach a similar goal by using the fairly powerful capabilities in AD to delegate administration of objects within a domain. You can also use these features to hi

RE: [ActiveDir] DNS Issue

2006-07-22 Thread Wyatt, David
Hi Steve Binary version is 5.2.3790.1830 (srv03_sp1_rtm.050324-1447) Clearing the cache does not fix the issue. Thanks David -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Steve Linehan Sent: 22 Jul 2006 0:56 To: ActiveDir@mail.activedir.org; Activ

RE: [ActiveDir] Always point a DC with DNS installed to itself as the preferred DNS server...always?

2006-07-22 Thread joe
:)      The main thing I don't like is AD Integrated. There is something fundamentally wrong with having your directory replication completely dependent on the name resolution system that is completely dependent on the directory replication system that is completely dependent on the name re

RE: [ActiveDir] Raid 1 tangent -- Vendor Domain

2006-07-22 Thread albertduro
"- stop using mirrors damnit) ."[1] can you please explain that? What's wrong with mirrors? [1] joe, speaking particularly in the context of Exchange List info : http://www.activedir.org/List.aspx List FAQ: http://www.activedir.org/ListFAQ.aspx List archive: http://www.activedir.org/ml/th

RE: [ActiveDir] RootDSE requires admin privileges

2006-07-22 Thread Sakari Kouti
Hi Joe, I installed NetMon on that workstation and it seems that nothing gets out on the wire with the failure case. And quite normal LDAP searches in the success case. I also did a little more testing and found out that the user doesn't need to be a domain admin for the script lines to work.

RE: [ActiveDir] Raid 1 tangent -- Vendor Domain

2006-07-22 Thread joe
Mirrors don't scale. Microsoft's deployment doc mostly just talks about using mirrors (small nod to RAID 10/0+1) so everyone thinks that they should build their Corporate DCs on mirrors, usually 3 - OS, Logs, and DIT. Very few people if anyone would build a corporate Exchange Server on mirrors...

[ActiveDir] Managing Third-Party Users

2006-07-22 Thread Marcus.Oh
My trusted directory resource,   I don’t remember if this came up on a previous post… but don’t recall seeing the topic.  As things become more and more integrated w/ some form of ldap authentication against a common directory, the necessity for managing outside vendors, contractors, etc

RE: [ActiveDir] Always point a DC with DNS installed to itself as the preferred DNS server...always?

2006-07-22 Thread joe
Any poor implementation is going to hurt you but I would argue that you are better off with a poor BIND/QIP DNS implementation than a poor Windows DNS implementation just because of the whole dependency loop thing.   If you can adequately state your needs to a UNIX DNS group they can usual

RE: [ActiveDir] RootDSE requires admin privileges

2006-07-22 Thread Dean Wells
Windows or 3rd party firewall related?? -- Dean Wells MSEtechnology t Email: [EMAIL PROTECTED] http://msetechnology.com > -Original Message- > From: [EMAIL PROTECTED] [mailto:ActiveDir- > [EMAIL PROTECTED] On Behalf Of Sakari Kouti > Sent: Saturday, July 22, 2006 11:39 AM > To: ActiveDir@

Re: [ActiveDir] Managing Third-Party Users

2006-07-22 Thread Joe Kaplan
Federation is the way of the future in these scenarios. I'm spending about 50% of my time at work these days helping to build out our federation infrastructure and imagine that we'll be using it extensively. We are already doing some type of federation thing with over 30 vendor-hosted apps in

RE: [ActiveDir] RootDSE requires admin privileges

2006-07-22 Thread Sakari Kouti
Nope. Not ICF or any other firewall on on these Virtual PC machines. Yours, Sakari -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Dean Wells Sent: 22. heinäkuuta 2006 21:02 To: Send - AD mailing list Subject: RE: [ActiveDir] RootDSE requires admin priv

Re: [ActiveDir] Raid 1 tangent -- Vendor Domain

2006-07-22 Thread Albert Duro
no debate from me. I was just asking. Thank you for the lesson. - Original Message - From: "joe" <[EMAIL PROTECTED]> To: Sent: Saturday, July 22, 2006 9:48 AM Subject: RE: [ActiveDir] Raid 1 tangent -- Vendor Domain Mirrors don't scale. Microsoft's deployment doc mostly just talk

Re: [ActiveDir] Raid 1 tangent -- Vendor Domain

2006-07-22 Thread Kevin Gent
joe, you must type really, really fast - Original Message - From: "Albert Duro" <[EMAIL PROTECTED]> To: Sent: Saturday, July 22, 2006 7:06 PM Subject: Re: [ActiveDir] Raid 1 tangent -- Vendor Domain no debate from me. I was just asking. Thank you for the lesson.

RE: [ActiveDir] Raid 1 tangent -- Vendor Domain

2006-07-22 Thread joe
That's a command line guy for you... :o) The thing is that I type in a very odd way two, my whole right hand just one or two fingers from my left hand. People tend to get a bit confused when they see me type. joe -- O'Reilly Active Directory Third Edition - http://www.joeware.net/win/ad3e.h