Re: Domain Trusts and LDAP

From: GMartin (gmartin_at_gmartin.org)
Date: 01/14/05


Date: Thu, 13 Jan 2005 22:39:15 -0500
To: "Chriss3 [MVP]" <noSpamHere@chrisse.se>

Chriss3 [MVP] wrote:
> Another solution may could be to use ADAM (Active Directory in Application
> Mode) for the web application, and create ProxyUser Accounts that relays to
> an Account in the Active Directory but thats not really secure.
>
> For security reasons I recommend you to use IIFP Identify Integration
> Feature Pack for synchronize accounts between the external and internal
> domain. Trusting Domains/Forests are not secure. IIFP is free as long you
> have a copy of Windows Server 2003
>
I'm not really interested in copying our internal credentials out to the
  DMZ. Seems risky. I was considering doing all of the trust
communications over IPSEC with direct holes through the firewall or
maybe using ISA to proxy the conncetion.

\\Greg



Relevant Pages

  • Re: Domain Trusts and LDAP
    ... >> Mode) for the web application, and create ProxyUser Accounts that relays ... >> an Account in the Active Directory but thats not really secure. ... Trusting Domains/Forests are not secure. ... > I'm not really interested in copying our internal credentials out to the ...
    (microsoft.public.windows.server.active_directory)
  • Re: KDC error suggestions?
    ... I have followed the steps in the Microsoft Article that you referred to. ... we need to locate the machine accounts that have the ... > 250455 How to Change Display Names of Active Directory Users ... I have the Windows Support Tools installed that some have ...
    (microsoft.public.windows.server.sbs)
  • Re: Active Directory Value Proposition
    ... > backup purposes - which leads to centralized backups (including open file ... > 1) Central administration of accounts, permissions, and policy. ... > What are the risks? ... >> Would you recommend using Active Directory in a small-business setting? ...
    (microsoft.public.win2000.active_directory)
  • Re: 2000 server and 2000 pro network
    ... I set up accounts from the server using ... these are in a workgroup called CMT. ... but a regular user cannot login using network ... Microsoft Windows MVP - Active Directory ...
    (microsoft.public.win2000.dns)
  • Re: Searching for expired by date accounts in AD
    ... expired passwords but expired by date expired) in Active Directory. ... Dim objShell, lngBiasKey, lngBias, k ... Set objConnection = CreateObject ... ' Filter on expired user accounts. ...
    (microsoft.public.scripting.vbscript)