Re: Unable to bind with new ADAM accounts

From: Everest25 (Everest25_at_discussions.microsoft.com)
Date: 11/24/04


Date: Wed, 24 Nov 2004 07:39:03 -0800

We've checked the msDS-UserAccount Disabled attribute and it is FALSE.
These machines are not in a domain so they are using the local password
policy, which we've checked and they are good. We've been using command line
utility ldapsearch.exe to check authentication, which we get the error
invalid credentials.

Everest25

"Lee Flight" wrote:

> If the account is a native ADAM user then a likely cause is that the
> msDS-UserAccountDisabled attribute on the user is set to TRUE, it needs
> to be set to FALSE for the account to be able to authenticate. If you are
> running under W2K3, you will need to make sure that any passwords you
> set satisfy the local machine or domain password complexity for the W2K3
> server for the account to be created as enabled.
>
> You do not say how you are attempting to bind, recall that for the simple
> bind of a native ADAM user the username must be the distinguishedName
> of the user object (or the UPN if you have set one). You can check binding
> with ldp.exe:
>
> Connection menu -> Connect (specify your ADAM server and port)
> Connection menu -> Bind (user: <distinguishedName of user>,Password (as
> set), clear the Domain check box)
>
> Hope this helps
> Lee Flight
>
> "Everest25" <Everest25@discussions.microsoft.com> wrote in message
> news:7E55DB2A-6C0B-4D5B-BE0E-2C5F0DB06C25@microsoft.com...
> > Recently we've noticed that whenever we create a new ADAM account and then
> > try to bind to a ADAM instance that we get an error saying invalid
> > credentials. We've checked all of the normal things (password,
> > groups...etc.). Does anyone have any ideas what could be causing this?
>
>
>



Relevant Pages

  • Re: Nameserver
    ... >I'd like to set up BIND locally to resolve names between machines on my ... >primary nameserver. ... configure your local machines to point to this box as their DNS server. ... Or you can read the DNS HOWTO at The Linux Documentation Project ...
    (RedHat)
  • Re: /var partition overflow (due to spyware?) in FreeBSD default install
    ... > FreeBSD machines with default installs of the operating system. ... > verified it yet) that the problem is due to the New.Net spyware, ... It may also pay to patch BIND to limit the overhead that is ... log files and rotate them when needed and turn off logging to syslog. ...
    (FreeBSD-Security)
  • ADAM AND ASP.NET
    ... I configured 3 machines on the same domain ... Windows 2000 Server ... ADAM ...
    (microsoft.public.windows.server.active_directory)
  • Re: [opensuse] Server cannot connect to itself
    ... One is running Bind 9.3.2 and the other is running ... Apache 2.1 and MySQL 5.0. ... Apache and Mysql from remote machines and ...
    (SuSE)
  • RE: BIND Crash
    ... Count me in - I've had this on one of my bind servers today as well. ... > of their other machines. ... implement and enforce WLAN security policies ... > to lockdown enterprise WLANs. ...
    (Incidents)