Re: The specified Directory Service has denied access



Thank you for your answer, Christoffer.

The thing is I do not wish to enable anonymous ldap binding (unless I have
misunderstood the word and that "anonymous" means that the user is not
authentified in any domain).

What I am trying to achieve is the ldap directory to be available to users
(who belong to the AD forest and) who have provided their username and
password in the address book account . They would be able to access the ldap
directory although they are not logged onto a domain. Is this possible?


Another thing is that the dsHeuristics setting for the instance is not set.
Is that normal? And, as I cannot modifiy the value of the seventh character,
should I set the value to 0000002001001?


As you might have gathered, I am quite new in the field so any help would be
greatly appreciated.

Frances

"chriss3 [MVP]" wrote:

Hello, to allow anonymous connection to the ADAM instance application
directory partition you will need to modify dsHeuristics setting for
the instance. See:

ADAM Help File
How To section
Manage an ADAM instance
Allow anonymous LDAP binding to an ADAM instance


You then need to modify the ACEs on the partition entries using
DSACLs or by adding a security principal to one of the ADAM builtin
roles for the partition e.g. Readers role.



--
Regards
Christoffer Andersson
Microsoft MVP - Directory Services


No email replies please - reply in the newsgroup
------------------------------------------------
http://www.chrisse.se - Active Directory Resources

"Lady Frances" <LadyFrances@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:576BDEE8-B646-4BDF-9897-FC3A4D2320DD@xxxxxxxxxxxxxxxx
I have installed ADAM on a front-end server which is in the DMZ.
There is no problem accessing the ldap directory from our network i.e.
when
one is logged onto the domain.

But when trying to access the directory from the internet (using wab), I
get
the following error: "The specified Directory Service has denied access.
Check the Properties for this Directory Service and verify that your
Authentication Type settings and parameters are correct.".

I noticed that the system hosting ADAM uses the client's Windows logon
information and not the Directory Service Account information. The event
viewer shows this:

Event Type: Failure Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 529
Date: 17.05.2006
Time: 10:05:38
User: NT AUTHORITY\SYSTEM
Computer: [Server hosting the ADAM instance]
Description:
Logon Failure:
Reason: Unknown user name or bad password
User Name: [Windows XP logon username]
Domain: [Client workstation name]
Logon Type: 3
Logon Process: NtLmSsp
Authentication Package: NTLM

Is there any specific configuration I need to enable the ldap directory to
be accessed using the credentials provided as the Directory's Service
Account, regardless of what information is used to log onto the Windows
session?

Thanks in advance,
Frances



.



Relevant Pages

  • Re: ADAM full sync needed every 30 days??????
    ... BTW, you may catch the failing operation if you enable LDAP auditing for \Administrator, through an inheritable SACL on the NC head. ... You should enable failure audits for all operations, for this account. ... performing the sync is unable to move an object. ... The current authoritative ADAM instance is ...
    (microsoft.public.windows.server.active_directory)
  • Re: ADAM full sync needed every 30 days??????
    ... Event Source: ADAM LDAP ... so the /sync works OK after you have performed a full sync? ... same ADAM instance. ... lock since it is the 'bind' account used for the sync's. ...
    (microsoft.public.windows.server.active_directory)
  • RE: [PHP] RE: Address book - LDAP or MySQL?
    ... I didn't say LDAP was a database. ... to set up a network address book of some kind. ... A directory service is a software application - or a set of applications ... book using MySQL and access it with PHP's library of MySQL functions. ...
    (php.general)
  • Re: [PHP] RE: Address book - LDAP or MySQL?
    ... since Timothy is already using MySQL that sounds like a great place for the ... So let me see if i can draw LDAP into the equation. ... graphical interface via PHP, but he wants to allow people to query the ... A directory service is a software application - or a set of applications ...
    (php.general)
  • Re: company-wide address book?
    ... >If you mean some sort of directory service that will fill in the name of ... >Netscape Mail client and Netscape's Directory Service (an implementation ... >of LDAP) will work. ... If you have divergent email clients, ...
    (comp.os.linux.misc)