Re: ADAM ADSI
From: Lee Flight (lef_at_le.ac.uk-nospam)
Date: 11/24/04
- Next message: Migration User: "Re: How do I workgroup users to Active Directory"
- Previous message: Thorsten Schmitt: "Re: DS Get in Windows 2003 Domain"
- In reply to: Owen Oriaku: "ADAM ADSI"
- Messages sorted by: [ date ] [ thread ]
Date: Wed, 24 Nov 2004 13:57:29 -0000
Hi
ADAM permissions are somewhat restrictive by default. To enable
users or groups to read from an application partition you will need
to add them to the builtin Readers role/group for that partition. See
the
ADAM help file
Administering ADAM
Administering access control
If you fire up ADSIedit and bind to the application partition then you
should find that you can edit the member attribute on
cn=Readers,cn=Roles
under the partition head to add ADAM or Windows principals.
The ADAM technical reference
has some useful in this area, p.63 onwards.
Lee Flight
"Owen Oriaku" <akuchigo@yahoo.com> wrote in message
news:b70ef34.0411240528.5057633c@posting.google.com...
> Hi there,
>
> I am having a weired problem with Active Directory Application Mode. I
> recently installed AD/AM on my Laptop running MS Windows 2003 Server,
> using a windows account that has got admin rights. this was the
> account that I used in logging into the computer.
>
> During the installation, I created the DN as O=OPRA,C=UK. Also I was
> able to create an Authorization store with the following
> "CN=azPolicy,OU=ADAM users,O=OPRA,C=UK". When I try to access this
> store from Authorization Manager using the original account that was
> used in setting up AD/AM, I could access the store. But when I log in
> as a different user and try to access the store from Authorization
> Manager, I get the error "System could not find the specified file".
>
> Further investigating the problem, I found out that I couldn't access
> the Application Partition "O=OPRA,C=UK", using the new user windows
> account. This goes to tell me that there is a permission thing going
> on that I can't figure out.
>
> What do I need to do to AD/AM to be able to access the application
> partition created by different windows account users?
>
> Regards
> Owen Oriaku
- Next message: Migration User: "Re: How do I workgroup users to Active Directory"
- Previous message: Thorsten Schmitt: "Re: DS Get in Windows 2003 Domain"
- In reply to: Owen Oriaku: "ADAM ADSI"
- Messages sorted by: [ date ] [ thread ]
Relevant Pages
|