RE: [ActiveDir] [Dreadfully OT]: Interesting little tidbit....

2005-02-13 Thread deji
Actually, my malady is contagious :) It's 4.7MB. I did not want to believe it would be that small when I first look at it, that was why I was confused. But, from what I am reading, I can see it's so small. By the way, this does not appear to me to be any different from running LINUX under a typ

RE: [ActiveDir] [Dreadfully OT]: Interesting little tidbit....

2005-02-13 Thread deji
I looked at it, and my eyes (almost) popped out. Is that really a 4.7Gig distro, or am I hallucinating - again? :) Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCP+I Microsoft MVP - Directory Services www.readymaids.com - we know IT www.akomolafe.com Do you now realize that Today is the Tomorrow y

RE: [ActiveDir] VERY VERY OT: DEC and Vancouver/Canada

2005-02-13 Thread deji
Dissecting >>> Its Vancouver in March... Yeah, so? Can't be much worse than MI in March. >>> I am pretty tied up with Lame, so lame I'm tempted to not comment :) I am sure most presenters are in the same boat. I am personally in that boat. I am not even sure HOW I will get to DEC yet, be

RE: [ActiveDir] migrate home dirs

2005-02-10 Thread deji
Hyena is not free, but it is not THAT expensive. Permcopy is a free reskit, IIRC. You could use either xcacls or robocopy for the ACL. I have seen both of them hiccup before, so I can't say one is better than the other. But, since you are using robocopy to copy the files anyway, why not use the b

RE: [ActiveDir] migrate home dirs

2005-02-10 Thread deji
Yes. The syntax is a bit different, but it will work. Just read the readme doc Actually, my original response should have been Robocopy Robocopy + Hyena (for share permission} Robocopy itself will do the NTFS re-ACLing and you would then use Hyena to copy the shares and share permissions

RE: [ActiveDir] migrate home dirs

2005-02-10 Thread deji
Robocopy + xcacls Robocopy + Hyena Robocopy + prayers (lots of it :)) Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCP+I Microsoft MVP - Directory Services www.readymaids.com - we know IT www.akomolafe.com Do you now realize that Today is the Tomorrow you were worried about Yesterday? -anon

RE: [ActiveDir] DNS(again)

2005-02-09 Thread deji
Are you on IM? Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCP+I Microsoft MVP - Directory Services www.readymaids.com - we know IT www.akomolafe.com Do you now realize that Today is the Tomorrow you were worried about Yesterday? -anon From: [EMAIL PROTECTED] o

RE: [ActiveDir] DNS(again)

2005-02-09 Thread deji
> sales.charmer.com Server: ns1.akomolafe.com Address: 66.92.14.146 sales.charmer.com MX preference = 10, mail exchanger = mta1.sales.charmer.com mta1.sales.charmer.com internet address = 208.234.241.112 > I can get an A record now as well, and I can get them from webserver1 I think yo

RE: [ActiveDir] DNS(again)

2005-02-09 Thread deji
Top-posting, bottom-posting, I think it's all a matter of preference. I, for one, don't find bottom-posting useful, and I am not one to flame anyone for doing either. I just mentioned it to you because it makes it easier for me to follow the thread properly. Now, the output you gave me for sales.

RE: [ActiveDir] Remote Assistance

2005-02-09 Thread deji
Red Wine (and Steak), maybe. Definitely NOT RedHat :0 Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCP+I Microsoft MVP - Directory Services www.readymaids.com - we know IT www.akomolafe.com Do you now realize that Today is the Tomorrow you were worried about Yesterday? -anon

RE: [ActiveDir] Remote Assistance

2005-02-09 Thread deji
Joe is just being well Joe. I don't think it's so much because he can't "think" of what to present as it is deciding on which of the numerous things he CAN present he should present. Something tells me, though, that if you can get Dean over to DEC (and make sure he brings his laptop), J

RE: [ActiveDir] DNS(again)

2005-02-09 Thread deji
Let's reboot. Describe what you are trying to do Describe your setup (who is the NS? Which client are you testing from, what is the output of ipconfig /all from that client?) What do you get, and how is that different from your expectation? What is the response when you do the following: nslookup

RE: [ActiveDir] Migrating access rights from Novell/NDS to W2K3/A D with NDS migra tor

2005-02-09 Thread deji
You get all the docs if you download SP1. If you are not into that, then you can get it here: http://www.microsoft.com/downloads/details.aspx?familyid=C3C26254-8CE3-46E2-B 1B6-3659B92B2CDE&displaylang=en Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCP+I Microsoft MVP - Directory Services www.r

RE: [ActiveDir] DNS(again)

2005-02-09 Thread deji
According to webserver1.charmer.com, webserver1.charmer.com is THE NS for both Charmer.com and sales.charmer.com According to the output you've just posted webserver1.charmernydom.csg-it.net According to the world, webserver1.charmernydom.csg-it.net does not exist According to webserver1.char

RE: [ActiveDir] Migrating access rights from Novell/NDS to W2K3/AD with NDS migra tor

2005-02-09 Thread deji
Jimmy always sees his shadow around this time - Summit must be around the corner :-p Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCP+I Microsoft MVP - Directory Services www.readymaids.com - we know IT www.akomolafe.com Do you now realize that Today is the Tomorrow you were worried about Yesterda

RE: [ActiveDir] Remote Assistance

2005-02-08 Thread deji
Without pointing fingers, or mentioning "short" names, here's my stance on sniffing traffic for diagnosis. It is a GREAT concept IF you know what you are looking for. Merely firing up Netmon/Ethereal and such will not be productive without the necessary capabilities to discern and interpret the tra

RE: [ActiveDir] users with power user rights

2005-02-08 Thread deji
You are forgetting that you can't use the %username% variable in the startup script successfully since the script is processed before the logon is initiated and, as such, before that variable holds anything. I ran into this a while back and smack into the 4-by-clue :) Sincerely, Dèjì Akómöláfé

RE: [ActiveDir] Win DNS and BIND

2005-02-08 Thread deji
You create a new delegation and specify the IP Address of the BIND server. Wizard will do it. Scripts will do it. You don't NEED to hack any boot file. Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCP+I Microsoft MVP - Directory Services www.readymaids.com - we know IT www.akomolafe.com Do you now

RE: [ActiveDir] OT: Exchange Mail Forwarding

2005-02-01 Thread deji
Don't you have a tool to write or something? :p Yeah, I know. It's cold in MI and you are stuck in the house. Can't do anything "with shorts on" for the next couple of months ;) You are right, though - as always. I just didn't feel the need to go into that much details. Experience has taught me

RE: [ActiveDir] OT: Exchange Mail Forwarding

2005-02-01 Thread deji
>> I am not too happy with this solution as I believe there may be a way to set this up on the Exchange server itself. You and a lot of others. But, this is what you are stuck with for the time being. >> I would like to disable the user's domain account for security reasons Don't disable the acco

RE: [ActiveDir] Where does AD store the Dial In settings?

2005-01-27 Thread deji
No way, Hunter! C:\Documents and Settings\deji>adfind -default -f "&(objectcategory=person)(msNPAllowDialin=TRUE)" samaccountname 'adfind' is not recognized as an internal or external command, operable program or batch file. ROFL Sincerely, Dèjì Akómöláfé, MC

RE: [ActiveDir] Where does AD store the Dial In settings?

2005-01-27 Thread deji
http://www.readymaids.com/Portals/1/Find%20Users%20allowed%20to%20use%20VPN.t xt Enjoy - and remember to thank Hunter :) Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCP+I Microsoft MVP - Directory Services www.readymaids.com - we know IT www.akomolafe.com Do you now realize that Today is the To

RE: [ActiveDir] Sid to Group Name

2005-01-27 Thread deji
Since the account is gone, there is nothing to translate it to. Unless it is one of the well-known (built-in) groups, I think you are SOL :) Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCP+I Microsoft MVP - Directory Services www.readymaids.com - we know IT www.akomolafe.com Do you now realize th

RE: [ActiveDir] OT:exchange restore

2005-01-27 Thread deji
When you build an offline recovery server, you'd want to do it "offline". Away from the existing exchange infrastructure. That is the way I've done it and seen it done, so I've tended to assume that it is "best practice". You do not want to restore into the same environment. The good news is that y

RE: [ActiveDir] Trust Problems

2005-01-25 Thread deji
If you have to resort to lmhosts and hosts files in a 2K3/2K environment, something wrong with DNS. Ahem... now that I have demonstrated that I am a genius at stating the obvious. :-p Let's comment out the entries you put in those files and configure the DCs to not use lmhosts (in TCP/IP prop

RE: [ActiveDir] Sites VS domains in a distributed global environm ent.

2005-01-25 Thread deji
With apologies to the original poster, I would like to hijack this thread and respond to Frank's idea on this: DNS - If you use AD integrated DNS for your AD domains (I did), make sure that each of your child DCs has a standard secondary of the TLD _msdcs zone and then have the clients use their

RE: [ActiveDir] Creating user accounts, home folders and assigning permissions to user and groups

2005-01-21 Thread deji
Will this do? http://www.readymaids.com/Portals/1/userprof-xcacls.txt Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCP+I Microsoft MVP - Directory Services www.readymaids.com - we know IT www.akomolafe.com Do you now realize that Today is the Tomorrow you were worried about Yesterday? -anon

RE: [ActiveDir] backup script

2005-01-20 Thread deji
Are you sure that the service is not auto-restarting itself? Look at the service's properties. The NTBACKUP line should finish ALL the backup before going to the next line. Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCP+I Microsoft MVP - Directory Services www.readymaids.com - we know IT www.ako

RE: [ActiveDir] LimitLogon

2005-01-20 Thread deji
Join the Beta and find out. Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCP+I Microsoft MVP - Directory Services www.readymaids.com - we know IT www.akomolafe.com Do you now realize that Today is the Tomorrow you were worried about Yesterday? -anon From: [EMAIL

RE: [ActiveDir] backup script

2005-01-20 Thread deji
If you are doing the backup through a batch script, then after the backup is completed, it should return to the next line in the batch script. Is that what you are asking? Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCP+I Microsoft MVP - Directory Services www.readymaids.com - we know IT www.akom

RE: [ActiveDir] Clients Not Authenticating with Site DC

2005-01-20 Thread deji
I think your problem is that you probably upgraded the DC at that site last and, before the upgrade, your XP and 2K clients had discovered the new 2K3 DCs at the remote site. Once XP and 2K clients discover and authenticate against a 2K or 2K3 DC, they usually don't go back. This may be what you ar

RE: [ActiveDir] Cconnect.exe: Con-Current Connection Limiter

2005-01-19 Thread deji
cconnect was not fully developed, IMO. I think it was abandoned in the middle of development. I have never met or heard of anyone who has successfully implemented it. Senthil, you said you want to "limit one person to one workstation". You don't need cconnect or any fancy tool to do that. You sho

RE: [ActiveDir] Urgent!!: exchange 2000

2005-01-17 Thread deji
Bawo ni, Omo iya :) First, this does not appear to be an E2K issue. Second, there is no MX for vmobile-nigeria.com or econet-nigeria.com. Third, a sum total of the first 2 is thatyou are relaying through MessageWall and it is hte one throwing the error. Being unfamiliar with MessageWall, I can'

RE: [ActiveDir] Change password at next logon greyed out

2005-01-14 Thread deji
You must also delegate the "Write Account Restrictions" rights before the users can toggle this box. Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCP+I Microsoft MVP - Directory Services www.readymaids.com - we know IT www.akomolafe.com Do you now realize that Today is the Tomorrow you were worrie

RE: [ActiveDir] DNS question

2005-01-14 Thread deji
Not to crash the party or anything like that. Here's a rule I use for figuring out my 2K3 DNS configuration. In an Intra-Forest Parent-Child relationship: Create parent.whatever zone on Parent DNS server Create child.parent.whatever on Child DNS Server Delegate child.parent.whatever to Child DNS

RE: [ActiveDir] Crazy question

2005-01-13 Thread deji
>>>B) if he does not.start from the scratch...create all the users with same user names as they had before >>>either way there would not be any down time as the users should be able to login to the cached profiles. Pardon the interruption, but .. I don't believe this is feasible for

RE: [ActiveDir] Inbound mail NDR

2005-01-13 Thread deji
MAIL PROTECTED] on behalf of Manjeet Sent: Wed 1/12/2005 7:49 PM To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] Inbound mail NDR Deji, The newly cretaed user hasno problem in sending mail to internal accounts, and also can send mail to internet (yahoo). but if I reply the same message

RE: [ActiveDir] Migrating to Win2k3

2005-01-13 Thread deji
Domain Rename has actually evolved and matured since those initial days. It's easier and better thought-through now. Having said that, it is NOT easy and I agree that it should be on the tail end of your alternatives. As to your question regarding ADMT, ADMT will migrate your computer accounts ve

RE: [ActiveDir] Inbound mail NDR

2005-01-12 Thread deji
From: [EMAIL PROTECTED] on behalf of Manjeet Sent: Wed 1/12/2005 7:49 PM To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] Inbound mail NDR Deji, The newly cretaed user hasno problem in sending mail to internal accounts, and also can send mail to internet (yahoo). but if

RE: [ActiveDir] Inbound mail NDR

2005-01-12 Thread deji
o you now realize that Today is the Tomorrow you were worried about Yesterday? -anon From: [EMAIL PROTECTED] on behalf of Manjeet Sent: Wed 1/12/2005 7:19 PM To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] Inbound mail NDR Hi Deji, Thanks for your p

RE: [ActiveDir] Inbound mail NDR

2005-01-12 Thread deji
It looks like you are going through Postini. I think it's time to call their support. Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCP+I Microsoft MVP - Directory Services www.readymaids.com - we know IT www.akomolafe.com Do you now realize that Today is the Tomorrow you were worried about Yesterday

RE: [ActiveDir] Forest trusts vs trusts within forests

2005-01-07 Thread Deji Akomolafe
No, Dean. You are all alone in your own little "stubby" world :o)   Actually, I use Stubs, especially in the scenario Guido described. I wouldn't introduce CF or secondaries in that situation.     Sincerely,Dèjì Akómöláfé, MCSE+M MCSA+M MCP+I Microsoft MVP - Directory Services www.readymaids.c

RE: [ActiveDir] Forest trusts vs trusts within forests

2005-01-07 Thread Deji Akomolafe
Without disagreeing with any of the points you made, don't you think multi-forest deployment is an "overkill" for what he's trying to achieve?   Let's look at the SOW again:   The motivations for considering another forest are the following: 1) we have some remote sites with workstations that a

RE: [ActiveDir] Password Filter DLL and Trust Password

2005-01-06 Thread Deji Akomolafe
Unless something has changed in the Password Filter implementation lately, I believe that Computer password changes do not hit the PasswordFilter. At least, that routine did not get called when using the passfilt I got from MS a long time ago. I haven't used this lately and the behavior may have

RE: [ActiveDir] Forest trusts vs trusts within forests

2005-01-06 Thread Deji Akomolafe
>>>  by using selective authentication (SA). Which, in order words, means that SEPARATE FOREST does not in itself protect you from an internal "clever domain admin" in any of the domains/forest. Unless you go through the troubles SID filtering, SA, and other ACLing. And, even with all that in p

RE: [ActiveDir] Script working for some users, and not for others ?

2005-01-05 Thread Deji Akomolafe
Could you try something like this:   Set wshShell = WScript.CreateObject("WScript.Shell") usrName = wshShell.ExpandEnvironmentStrings("%USERNAME%")Set usr = GetObject("WinNT://NetBIOSDomainName/" & usrName & ",user") For Each grp In usr.Groups If grp.Name = "HR" Then    Do Something Exit For

RE: [ActiveDir] Script working for some users, and not for others ?

2005-01-05 Thread Deji Akomolafe
I had issues like this a long time ago in my previous life, and I think I had to change the code to use the WinNT provider instead of LDAP to get it working. I can't remember the specifics now, but you may want to try that. I will post more if I can find the code in question, or if I see yours f

RE: [ActiveDir] Setting up AD trusts

2005-01-05 Thread Deji Akomolafe
"Users, objects, etc" does not really say much :) There are more things in an AD than just those, and you will need to take them into accounts in making your decisions. For example, Exchange (hence mailboxes, DLs, PFs, Recippient Policies and namespace, routing, calendars, and oh yeah e

RE: [ActiveDir] Storage Limit Change in AD

2004-12-20 Thread deji
afe.com Do you now realize that Today is the Tomorrow you were worried about Yesterday? -anon From: [EMAIL PROTECTED] on behalf of Manjeet Sent: Mon 12/20/2004 5:58 PM To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] Storage Limit Change in AD Hi Deji, Tha

RE: [ActiveDir] Storage Limit Change in AD

2004-12-20 Thread deji
It depends (TM) Ordinarily, you will be controlling this setting at the Store level. If this is what you are doing, then all you will need to do is create another mailbox store, set the Limit the way you want and move all the 600 mailboxes to that new store. They will then inherit the new setting

RE: [ActiveDir] Event 673 on SBS 2003

2004-12-16 Thread deji
Have you tried www.eventid.net ? Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCP+I Microsoft MVP - Directory Services www.readymaids.com - we know IT www.akomolafe.com Do you now realize that Today is the Tomorrow you were worried about Yesterday? -anon From: [

RE: [ActiveDir] Sequence LDAP query

2004-12-15 Thread deji
#x27;'''''''''''''''''''''''''''''''''''''''''''''''''

RE: [ActiveDir] Create Home Directory for New Users?

2004-12-15 Thread deji
I know that you said "no scripting knowledge, but if you can take hints, this should help: http://www.readymaids.com/LinkClick.aspx?link=userprof-xcacls.txt&mid=431 You are welcome Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCP+I Microsoft MVP - Directory Services www.readymaids.com - we kno

RE: [ActiveDir] Sequence LDAP query

2004-12-15 Thread deji
'''''''''''''''''''''''''''''''''''''''''''''''' ''''&

RE: [ActiveDir] Default Domain Policy

2004-12-15 Thread deji
Either way would work for you. I am not aware of a mandated "best practice" that would invalidate one option or the other. Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCP+I Microsoft MVP - Directory Services www.readymaids.com - we know IT www.akomolafe.com Do you now realize that Today is the To

RE: [ActiveDir] Sequence LDAP query

2004-12-15 Thread deji
This is just a pseudo-code... objCommand.CommandText = "Select mail from 'LDAP://DC=Domain,DC=com'" Set objRecordSet = objCommand.Execute objRecordSet.MoveFirst Do Until objRecordSet.EOF objemailAddy = objRecordSet.Fields("mail").Value If instr(lcase(objemailAddy), "[EMAIL PROTECTED]") > 0

RE: [ActiveDir] Domain Name and DNS Problems

2004-12-14 Thread deji
>>I would like for our internal AD DNS to only host records for our internal systems and forward any other unresolved requests When a DNS server is told that it is authoritative for a zone, it takes that responsibility seriously. This means that it considers ANYTHING that is not in that zone non-

RE: [ActiveDir] Slow External DNS after 2003 Domain Upgrade

2004-12-09 Thread deji
"Lost another Soul to EDNS0" :) dnscmd /config /enableednsprobes 0 net stop dns & net start dns Either that, or fix your Router. Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCP+I Microsoft MVP - Directory Services www.readymaids.com - we know IT www.akomolafe.com Do you now realize that Today

RE: [ActiveDir] The server is not operational

2004-12-09 Thread deji
You can get me offline on MSN IM. deji at iyaburo dot com Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCP+I Microsoft MVP - Directory Services www.readymaids.com - we know IT www.akomolafe.com Do you now realize that Today is the Tomorrow you were worried about Yesterday? -anon

RE: [ActiveDir] The server is not operational

2004-12-08 Thread deji
aids.com - we know IT www.akomolafe.com Do you now realize that Today is the Tomorrow you were worried about Yesterday? -anon From: [EMAIL PROTECTED] on behalf of Noah Eiger Sent: Wed 12/8/2004 12:47 PM To: [EMAIL PROTECTED] Subject: RE: [ActiveDir] The server is not operat

RE: [ActiveDir] DNS root

2004-12-08 Thread deji
Thanks for putting that into perspective for me. It helps to understand design requests before saying "yes/no". Having said that, secondarying the TLD from the Child DCs would be a requirement (must-have) IF there are no TLD DNS servers at the local site. I know that this is a common scenario, and

RE: [ActiveDir] The server is not operational

2004-12-08 Thread deji
Noah elger wrote RRAS is running (only for me to make a PPTP connection over which I run RD). Due to RRAS, the server registers another A record and SRV record in DNS (for the VPN interface). DNS also shows that it is servicing requests on that address. ... And I replied .. I com

RE: [ActiveDir] DNS root

2004-12-08 Thread deji
I have been away for a while and have not been following this conversation closely, so excuse me if I missed some of the relevant conversation. Looking at what you've written, I do not understand what the purpose of this exercise would be. If you have a parent-child topology, and you configure

RE: [ActiveDir] Slightly OT: File Copy of Death - off-list reply

2004-12-02 Thread deji
Did you look here? http://www.windowsitpro.com/Article/ArticleID/19826/19826.html Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCP+I Microsoft MVP - Directory Services www.readymaids.com - we know IT www.akomolafe.com Do you now realize that Today is the Tomorrow you were worried about Yesterday? -

RE: [ActiveDir] OT: Virtual Server 2005

2004-11-19 Thread deji
I don't use sysprep. I just use newsid from sysinternals. Then I edit the .vmc to reflect the new VS name/location. I'm that lazy. Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCP+I Microsoft MVP - Directory Services www.readymaids.com - we know IT www.akomolafe.com Do you now realize that Today i

RE: [ActiveDir] OT: Why no AD integrated DNS secondary zones?

2004-11-19 Thread deji
>>Why is it not a good idea to store zone data in AD? For the simple fact that I can use it as a vector to introduce malicious contents into the secondarying AD. >>Why not exploit a modern replication engine? modern, legacy. Does it really matter which one we go through? >>The admin. overhead to

RE: [ActiveDir] OT: Why no AD integrated DNS secondary zones?

2004-11-19 Thread deji
because I didn't think you could. Are you sure you could AD-intg conditionally-forwarded zones? They are not "real" zones in the normal sense, mind you. Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCP+I Microsoft MVP - Directory Services www.readymaids.com - we know IT www.akomolafe.com Do you no

RE: [ActiveDir] OT: Why no AD integrated DNS secondary zones?

2004-11-19 Thread deji
t MVP - Directory Services www.readymaids.com - we know IT www.akomolafe.com Do you now realize that Today is the Tomorrow you were worried about Yesterday? -anon From: [EMAIL PROTECTED] on behalf of Dean Wells Sent: Fri 11/19/2004 8:24 AM To: Send - AD mailing

RE: [ActiveDir] OT: Why no AD integrated DNS secondary zones?

2004-11-19 Thread deji
How many new DCs are you adding per day/week/month? :) If I were doing this, Stub or Secondaries would take a back-seat. I would be investing in Conditional Forwarding. I would have all my other DNS servers forward unresolved queries to one or (ideally) 2 of MY DNS servers. On those 2 designated D

RE: [ActiveDir] OT: Why no AD integrated DNS secondary zones?

2004-11-19 Thread deji
AM To: Send - AD mailing list Subject: RE: [ActiveDir] OT: Why no AD integrated DNS secondary zones? Deji, There would a concept of "AD integrated secondaries" had MS decided to write it; it may be desirable (to some) to maintain read-only yet AD replicated zones. I guess the point i

RE: [ActiveDir] OT: Why no AD integrated DNS secondary zones?

2004-11-19 Thread deji
Because when it's integrated, there is no concept of "secondaries" as we understood it to be in pre-2Kx world. It's there in AD, and any DC can see and write to it. Now, if you are secondarying the zones on another server located in another forest/network, why would you want to store that info in y

RE: [ActiveDir] DNS Issues

2004-11-18 Thread deji
>>This is not a problem with 2K3 DNS. Depends on how you define "problem" ownership. 2K3 DNS implements EDNS0 (a fully RFC-compliant implementation, mind you). However, a number of the Network equipments were not ready for it. Many are still not compliant. So, your EDNS0-enabled DNS server is able

RE: [ActiveDir] Netlogon won't start

2004-11-16 Thread deji
I tink it's time to bring out Winternal's ERD Commander or similar tool. I don't know if Winternals has a trial version, but if you have it, you should be able to boot all the way into the OS and start the necessary service. Perhaps you could also try machinename\administrator at the logon prompt

RE: [ActiveDir] Netlogon won't start

2004-11-16 Thread deji
Yes. Local logon should still work. Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCP+I Microsoft MVP - Directory Services www.readymaids.com - we know IT www.akomolafe.com Do you now realize that Today is the Tomorrow you were worried about Yesterday? -anon From

RE: [ActiveDir] Rebuilding RUS - sanity check

2004-11-16 Thread deji
>>1. Loop through all USN's from zero for all objects. I.E. the current USN is 23000, it asks for a query to return all objects with a USN less than or equal to 23000. At the end of that processing, it can easily pick up and gather changes that occurred since the start of the rebuild (i.e. any obje

RE: [ActiveDir] Rebuilding RUS - sanity check

2004-11-16 Thread deji
Thanks, all. I got in touch with the source of this mandate and all I could get was the concern that rebuilding will require people to re-download offline address books. At this point, I regret to inform you that the concern appears to be more political (turf protection) than technical. I know I

[ActiveDir] Rebuilding RUS - sanity check

2004-11-16 Thread deji
I have always thought that rebuilding (or updating) the Recipient Update Services after a reconfiguration of Recipient Policies is a "normal", non-destructive procedure. I am just now learning that rebuilding RUS is a "no-no" and must be avoided at all cost. I have not spoken directly to the "sourc

RE: [ActiveDir] Joining a Domain thru Command Line

2004-11-14 Thread deji
You did not mention where you are doing the join from. At what point in your installation? Are the computers remote to you? In any case, look into netdom. NETDOM JOIN NEWPC /DOMAIN:THISDOMAIN.LOCAL /USERD:BigDude /PASSWORDD:h4ckME /OU:OU=THISBOTTOMOU,OU=THISTOPOU,DC=THISDOMAIN,DC=LOCAL NETDOM JOI

RE: [ActiveDir] OU and Policies

2004-11-12 Thread deji
yes. read up on loopback. Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCP+I Microsoft MVP - Directory Services www.readymaids.com - we know IT www.akomolafe.com Do you now realize that Today is the Tomorrow you were worried about Yesterday? -anon From: [EMAIL P

RE: [ActiveDir] Deny Domain GP to a single user

2004-11-12 Thread deji
Make the user's computer a Secure-NAT client by setting its default gateway to the ISA server's internal IP. Make sure you don't install the Proxy client on the user's computer. This should work. Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCP+I Microsoft MVP - Directory Services www.readymaids.c

RE: [ActiveDir] OU and Policies

2004-11-12 Thread deji
Don't blame me. It's the voices in my head ;-p Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCP+I Microsoft MVP - Directory Services www.readymaids.com - we know IT www.akomolafe.com Do you now realize that Today is the Tomorrow you were worried about Yesterday? -anon ___

RE: [ActiveDir] ADS (Storage Limits)

2004-11-12 Thread deji
http://support.microsoft.com/default.aspx?scid=kb;EN-US;q316792 Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCP+I Microsoft MVP - Directory Services www.readymaids.com - we know IT www.akomolafe.com Do you now realize that Today is the Tomorrow you were worried about Yesterday? -anon __

RE: [ActiveDir] OU and Policies

2004-11-12 Thread deji
I think Mario is looking for http://support.microsoft.com/kb/260370/EN-US/ Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCP+I Microsoft MVP - Directory Services www.readymaids.com - we know IT www.akomolafe.com Do you now realize that Today is the Tomorrow you were worried about Yesterday? -anon

RE: RE: [ActiveDir] Indexing an attribute

2004-11-10 Thread deji
I second that :-p Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCP+I Microsoft MVP - Directory Services www.readymaids.com - we know IT www.akomolafe.com Do you now realize that Today is the Tomorrow you were worried about Yesterday? -anon From: [EMAIL PROTECTED

RE: [ActiveDir] Logon Information

2004-11-10 Thread deji
In 2K AD, yes. In 2K3 AD, no. In 2K3, there is the lastlogontimestamp attribute and this is replicated to all DCs. It's not completely "real-time", though. Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCP+I Microsoft MVP - Directory Services www.readymaids.com - we know IT www.akomolafe.com Do you

RE: [ActiveDir] DNS Event ID 5504

2004-11-09 Thread deji
Noah, do these event correspond to the time when your VPN servers are connecting to your network? The last time I saw this, it was coming from VPN client connections, and the culprit clients usually have invalid "wacky" characters in their names. The last I heard about this, it is "normal". I don't

RE: [ActiveDir] enforce a remote access security policy

2004-11-09 Thread deji
I have no idea why you don't see it, other than to speculate that you prolly deleted it :o. However, there is a known feature in the W2K RRAS wizard. The "feature" is not just cosmetic. I can almost swear that there is a KB for it, but I don't have it in my repository right now, and I don't want t

RE: Spam: Spam: RE: [ActiveDir] DNS Scavenging

2004-11-08 Thread deji
>>Isn't that only true if you aren't using Windows 200X for DHCP services? Possibly. I have not personally seen a difference in the behavior, though. I also do not agree with the document. Test it out, in a lab. Scavenging and aging confuses me, and I try very hard to get a handle on it. I sugges

RE: [ActiveDir] DNS Scavenging

2004-11-08 Thread deji
Depending on how large your environment is, you may be best served by just doing regular scavenging as a part of your weekly/bi-weekly/monthly maintenance. The reason I say this is that the Scavenging option you see in the GUI is a little bit hard to get a handle on. dnscmd /startscavenging will

RE: [ActiveDir] Scripting question - Net Send command

2004-11-03 Thread deji
It's an ugly hole. My option would be to have the tool run in the context of another account (like a service account). Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCP+I Microsoft MVP - Directory Services www.readymaids.com - we know IT www.akomolafe.com Do you now realize that Today is the Tomorr

RE: [ActiveDir] Notification containing new password

2004-11-03 Thread deji
I don't think there is such tool natively. I imagine that you could put a web interface on a vbscript where you direct your users to go to when they need to change their passwords. In the code, you will then put in a routine that grabs the value they type in and email it to you. Now, I will get a

RE: [ActiveDir] OT: helpdesk software

2004-11-02 Thread deji
I can also vouch for Liberum. I think the development has not moved much for a long time because the tool does all the things it's supposed to do beautifully. It meets all the criteria you mentioned in your request and it does so for free. Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCP+I Microso

RE: [ActiveDir] IP setting Script

2004-10-26 Thread deji
Have you been to: http://www.readymaids.com/Portals/1/Remotely%20change%20DNS%20IP%20on%20multi ple%20Computers.txt Enjoy Sincerely, Dèjì Akómöláfé, MCSE+M MCSA+M MCP+I Microsoft MVP - Directory Services www.readymaids.com - we know IT www.akomolafe.com Do you now realize that Today is the T

RE: [ActiveDir] Centralized vs. decentralized administration

2004-10-24 Thread deji
Just got my October edition of Windows IT Pro, and guess what I found. One of the nicest plugs for some of the best AD tools I've ever seen! Nice work, Robbie. Nicer work, Joe! The tools are now getting the recognition they deserve. I hope your web-host is robust enough to sustain the mad-rush fo

RE: [ActiveDir] Promoting 2nd Domain Controller in AD (The Credentials Supplied C onflict with an Existing set of credentials)

2004-10-21 Thread deji
simply do a net use * /delete /y and you are good to go Sincerely, Dèjì Akómöláfé, MCSE MCSA MCP+I Microsoft MVP - Directory Services www.readymaids.com - we know IT www.akomolafe.com Do you now realize that Today is the Tomorrow you were worried about Yesterday? -anon __

RE: [ActiveDir] uptime utility

2004-10-17 Thread Deji Akomolafe
Title: RE: [ActiveDir] Macs, LDAP Source it's called uptime. As in uptime.exe. It tells me the following:   file://myServer/ has been up for: 93 day(s), 14 hour(s), 19 minute(s), 42 second(s)   Sincerely,Dèjì Akómöláfé, MCSE MCSA MCP+I Microsoft MVP - Directory Services www.readymaids.com - we

RE: Re[2]: [ActiveDir] DNS naming confused

2004-10-16 Thread Deji Akomolafe
as exchange is concerned.     Sincerely,Dèjì Akómöláfé, MCSE MCSA MCP+I Microsoft MVP - Directory Services www.readymaids.com - we know ITwww.akomolafe.comDo you now realize that Today is the Tomorrow you were worried about Yesterday?  -anon From: SvetaSent: Sat 10/16/2004 5:58 PMTo: Deji Akomola

RE: [ActiveDir] DNS naming confused

2004-10-16 Thread Deji Akomolafe
You could name it anything you want. You could call it company.local. Or you could call it company.com. If you call it company.com, be prepared to host and maintain an internal company.com zone, which MUST be separate from your external company.com zone and must not be hosted on the same DNS ser

RE: [ActiveDir] Getting print info from event log

2004-10-15 Thread deji
download secops.exe (http://www.microsoft.com/downloads/details.aspx?displaylang=en&FamilyID=9989 D151-5C55-4BD3-A9D2-B95A15C73E92). It contains eventcombMT which should serve you well. Sincerely, Dèjì Akómöláfé, MCSE MCSA MCP+I Microsoft MVP - Directory Services www.readymaids.com - we know I

RE: [ActiveDir] 2K3 documentation update? (WAS: Windows Server 2003 Security Weirdness)

2004-10-15 Thread deji
ad me wide open and getting hammered by account enumeration attacks, whereas changing it to a "1" now has my IPC$ share behaving the way I thought it should've been. The kicker? I can't find any mention of the change in an MS Article (though Deji or someone will doubtless

<    2   3   4   5   6   7   8   9   10   >