Re: ADAM "add application partition" using LDIFDE

Tech-Archive recommends: Fix windows errors by optimizing your registry



OK I think understand this a little better now, one thing I am still
struggling with is:

> then things are simple. However, if it is not, then the instance attempts
> to create the crossRef remotely on the naming fsmo, while attempting to
> impersonate the caller. This actually requires special work to setup
> connection (enabling delegation). DSmgmt does this work, but LDIFDE it is
> not likely going to work.

I'm not sure how dsmgmt achieves this as I do not understand how the
delegation
is working; if this were AD and so the DSAs were DCs then as DC are trusted
for delegation I could see this working. For ADAM say the servers are just
domain
members and so not trusted for delegation by default I would see this as the
calling application running (dsmgmt) in the user context making a request
for ticket to access the member server that is the FSMO? I'm probably
misunderstanding the security
context; I'll try a packet sniff...

Lee Flight


.



Relevant Pages

  • Re: ADAM "add application partition" using LDIFDE
    ... > fsmo), and only then creates the partition on the target instance. ... > core to create the crossRef if necessary. ... >>> work to setup connection (enabling delegation). ... DSmgmt does this work, ...
    (microsoft.public.windows.server.active_directory)
  • Re: ADAM "add application partition" using LDIFDE
    ... Due to delegation settings. ... I checked ntdsutil/dsmgmt code -- indeed, when it is talking to an ADAM ... fsmo), and only then creates the partition on the target instance. ... DSmgmt does this work, but LDIFDE it is ...
    (microsoft.public.windows.server.active_directory)