Re: Anonymous LDAP browsing in Outlook 2003

From: Jose (Jose_at_discussions.microsoft.com)
Date: 12/16/04


Date: Thu, 16 Dec 2004 10:49:11 -0800

OK, I have set up two LDAP directory entries into my Outlook 2003 SP1. In
the first LDAP, I'll call it LDAP_Auth, entry I have set the domain\userID
and password and I am able to browse all entries in the directory when I open
the address book and select the LDAP_Auth directory. When I open the address
book and select the second entry which I call LDAP_Anon, no domain\userID and
password is set, the browse window in the address book is blank. Is this a
function of Outlook 2003 SP1 or a function of the LDAP server not allowing
the anonymous client access to browse the LDAP directory?

"Dmitri Gavrilov [MSFT]" wrote:

> There are no special permissions to set up for VLV. If anonymous can see the
> objects using normal LDAP searches, then they will also be visible via VLV.
>
> --
> Dmitri Gavrilov
> SDE, Active Directory Core
>
> This posting is provided "AS IS" with no warranties, and confers no rights.
> Use of included script samples are subject to the terms specified at
> http://www.microsoft.com/info/cpyright.htm
>
> "Jose" <Jose@discussions.microsoft.com> wrote in message
> news:747C3A34-E2C3-481F-90F9-39CD6DF2CD5F@microsoft.com...
> > I have a Windows 2003 Active Directory forest with 2 DCs. I found in the
> > following Microsoft articles, "How Active Directory Searches Work" and
> > 326690, how to enable anonymous LDAP searches and these features are
> working.
> >
> > In Outlook 2003 SP1, I have defined the LDAP directory and I am able to
> > resolve email addresses anonymously. As an authenticated user to this
> domain
> > I am able to browse the LDAP directory via the Outlook 2003 SP1 address
> book.
> > As an anonymous user I am not able to browse the LDAP directory via the
> > Outlook 2003 SP1 address book. In the following Microsoft article 820864
> it
> > states
> >
> > "If your LDAP server does not provide either of these functionalities, you
> > do not have the browsing feature set in Outlook 2003. Particularly for the
> > VLV extension, permission is not typically granted on the LDAP server for
> > anonymous users to access the extension. Therefore, without a change in
> the
> > permission assignments, the browsing feature set in Outlook 2003 is not
> > available."
> >
> > Since I am able to browse the LDAP directory as an authenticated user, how
> > can I grant the proper permissions to allow anonymous users to access the
> VLV
> > extensions on the LDAP server?
> >
> > Any help is greatly appreciated.
> >
>
>
>



Relevant Pages

  • Re: Anonymous LDAP browsing in Outlook 2003
    ... If you are running WS 2003, then you need to first enable Anonymous ldap ... I have set up two LDAP directory entries into my Outlook 2003 SP1. ... permission is not typically granted on the LDAP server ... >>> can I grant the proper permissions to allow anonymous users to access ...
    (microsoft.public.windows.server.active_directory)
  • RE: LDAP directory
    ... Subject: LDAP directory ... the problem with LDAP is the fact that no standard is in place for ACL. ... A good example is a LDAP server that is used in a single signon solutions ... ldap security will be secure, if you set proper access permissions. ...
    (Pen-Test)
  • Re: Anonymous LDAP browsing in Outlook 2003
    ... There are no special permissions to set up for VLV. ... objects using normal LDAP searches, then they will also be visible via VLV. ... I have defined the LDAP directory and I am able to ...
    (microsoft.public.windows.server.active_directory)
  • RE: LDAP directory
    ... Subject: LDAP directory ... ldap security will be secure, if you set proper access permissions. ... For more information on SecurityFocus' SIA service which ...
    (Pen-Test)
  • Re: Anonymous LDAP browsing in Outlook 2003
    ... > There are no special permissions to set up for VLV. ... > objects using normal LDAP searches, then they will also be visible via ... >> can I grant the proper permissions to allow anonymous users to access the ...
    (microsoft.public.windows.server.active_directory)