Re: AD/Simple bind - Why "user DN" fails, but "UPN-format" works?



Hi,

I'm starting to wonder if it might be something OUTSIDE of the
configuration of AD itself might be causing this behavior?

Specifically, I'm wondering whether maybe something like the AD-to-DNS
server relationship is different between the two different AD instance
configurations?

For example, if one configuration were using an integrated DNS server
vs. the other using a separate DNS server, or maybe the DNS
configuration (Network->Advanced->DNS tab) settings is different between
the two AD machines?

For reference, the test AD instance that I have here at home, which
doesn't exhibit this "UPN format only" problem, was built with an
integrated DNS server configuration (i.e., I installed MS DNS server
when I did the DCPROMO to turn the machine into an AD) with the default
network/DNS settings from the Win2K3 installation.

I've asked the guys at work to check on this next week, but I was
wondering if anyone here might have an idea if something like this might
be causing the difference? Would something in the DNS configuration
cause AD not to be able to accept userDN for simple binds, whereas UPNs
would work?

I know that this is a 'long shot', but I'm kind of running out of ideas
:(!!

Thanks,
Jim



"Joe Kaplan (MVP - ADSI)" wrote:

In the local security policy, go to the auditing section and enable both
success and failure audits of logon events. This will populate the security
event log with lots of gory details about what's going on with your
authentications. This is also something I would consider a best practice
for most Windows server deployments.

Joe K.

"ohaya" <ohaya@xxxxxxx> wrote in message news:4452D235.6B683254@xxxxxxxxxx
Joe,

I know it's weird :(...

I can't duplicate the problem on a different test AD/2003 I have at home
either. I've even tried some odd stuff like changing the
userPrincipalName in the AD so that the first part is be different than
the CN, I could still do a simple bind using either the full user DN or
the UPN.

When you say "try auditing logon events on the DC", is there something I
need to enable this? If so, can you describe?

As I mentioned, I did a ldifde to export, and I couldn't see anything
strange in there.

I definitely will post back if I find anything.

Thanks for your help.

Jim

.



Relevant Pages

  • Re: Group policy Error; Event ID 1030 & 1058
    ... Starting test: CrossRefValidation ... Running partition tests on: Configuration ... "Meinolf Weber" wrote: ... On my DC NIC 213.42.20.20 is the alternate DNS server. ...
    (microsoft.public.windows.group_policy)
  • Re: Which DC for authentication?
    ... > I have check the configuration of the DNS server: ... When you are implementing sites you usually first configure the site, ... when rebooting or when restarting the netlogon service. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Computers Registering Two IPs
    ... bearing whatsoever to the configuration of our network. ... this IP in the registry of the affected machines, ... The dynamic updates to our domain controller's DNS server appear to be ... Microsoft MVP - Directory Services ...
    (microsoft.public.windows.server.dns)
  • Re: Two ISPs, One NATed Internal Subnet, Firewall Policys
    ... > We wish to use one connection primarly, ... the netfilter configuration can be static; ... ADSL/cable router and the ISP, and between the ISP and the wider Internet ... DNS server monitoring is often used. ...
    (Fedora)
  • make my DNS to maintain my zone.
    ... 2.- I have configured NIC.COM to forward queries to NS0.XXX.COM and ... by my ISP so it was easier to update the A records in the DNS server. ... Here I used the wizard to add the zone XYZ.COM ... What is the problem with my configuration? ...
    (microsoft.public.windows.server.dns)