RE: [ActiveDir] ADAM bind Redirection with a NULL password

2006-09-29 Thread Flight, L.
Hi This is not just an ADAM problem it's been a problem with LDAP directories for some time now and was discussed in the LDAPbis WG. As a result if you look at RFC4513(RFC2829 is obsolete) you will see this issue is now addressed by making a distinction between an anonymous authentication and

Re:[ActiveDir] Creating an OU in ADAM

2004-08-13 Thread Flight, L.
cnvals[0] = location; I think that needs to agree with your ou name i.e. cnvals[0] = test; Lee Flight List info : http://www.activedir.org/mail_list.htm List FAQ: http://www.activedir.org/list_faq.htm List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/

RE: [ActiveDir] Schema changes between 2000 and 2003

2004-02-20 Thread Flight, L.
For reference there is also a summary of of the Windows 2003 schema modifications at: http://msdn.microsoft.com/library/default.asp?url=/library/en-us/adschema/adschema/windows_server_2003_only_schema.asp Lee Flight Network Support, Computer Centre University of Leicester List info :

RE: [ActiveDir] schema updates (SMS 2003)

2004-02-02 Thread Flight, L.
In fact there is an LDIF file for SMS2003, it's buried in the SMS2003 Toolkit: http://www.microsoft.com/smserver/downloads/2003/tools/toolkit.asp Unfortunately the SMS2003 Active Directory Schema Modification and Publishing for Systems Management Server 2003 documentation at:

RE: [ActiveDir] Strange intermittent problem with IADsUser::SetPassword

2004-01-15 Thread Flight, L.
Hi, when the procedure starts to fail what do you see in the target DC audit trail: Account Logon | Account Management. Have you tried auditing Directory Services Access failures (KB232714)? Does the problem persist if you (are able) to switch to OpenDSObject(WinNT:// as a test? Does the

RE: [ActiveDir] DSQuery shows wrong DC as holding role

2003-09-25 Thread Flight, L.
When we were moving roles around recently for Windows 2003 upgrade we scripted: netdom query /server:dcname fmso to check consistency. As some roles are stored as attributes on the schema and configuration containers changes (KB 223787) may take longer to replicate than those stored as

RE: [ActiveDir] Microsoft Announces Identity Managment Solution

2003-07-02 Thread Flight, L.
Maybe there's a little more to it, in light of the the SSO scalability paper at: http://www.microsoft.com/windows2000/techinfo/howitworks/activedirectory/adscaltest.asp and the latest info. on TrustBridge: http://www.microsoft.com/usa/presentations/Hur_SecuritySummitWest03.ppt Further

RE: [ActiveDir] Question About Schema Extensions.... Chicken or Egg

2003-06-28 Thread Flight, L.
The Exchange 2000 schema extensions can lead to managled attributes when the W2003 schema updates take place wrt. the InetOrgPerson in W2003 see KB 314649 and KB 325379. Those two articles are not entirely consistent but the InetOrgPersonPrevent.ldf in KB 325379 (updated 06/20/2003) is the one

RE: [ActiveDir] [ActiveDir Digest] Back to Basics - Design Pros and Cons

2002-12-12 Thread Flight, L.
Hi, the windows-hied list (there is a link from http://windows.stanford.edu) discusses these issues for hied. There is an archive at: http://admin.ufl.edu/windows/discussions/windows-hied/ search in the subject for OU design. Empty root is certainly a design option but I do not believe that

RE: [ActiveDir] Manual Refresh of GPO on local computer

2002-12-09 Thread Flight, L.
If you are convinced that the policy change is active and replicating, you could try checking to see if the user policy has been tatoo'ed with the (old) redirection settings. KB article 242557 describes the keys. Beyond that debug the GPO application (KB article 250842) Lee Flight Network

RE: [ActiveDir] MMS

2002-11-21 Thread Flight, L.
Hi, If you want to do inter-AD forest testing: Microsoft Metadirectory Services 2003, Standard Edition, will ship approximately 90 days after the Windows .NET Server release (1Q03). Standard edition will be made available as a no-charge web download. From: