Re: Multiple ADAM Problem

Tech-Archive recommends: Fix windows errors by optimizing your registry



Will there be a forest trust between the current forest and the new forest?
Since the ADAM server can only belong to one domain/forest, it would need a
trust in order to authenticate bind proxies from a different forest.

Another option you could look into would be to use ADFS and use federation
to tie all of these things together. You get a lot more flexibility that
way, at the cost of (potentially) more complexity.

Joe K.

--
Joe Kaplan-MS MVP Directory Services Programming
Co-author of "The .NET Developer's Guide to Directory Services Programming"
http://www.directoryprogramming.net
--
"sfloyd" <sfloyd@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:54D01B0B-099A-47C2-A6AD-BC9EEEA31538@xxxxxxxxxxxxxxxx
I have custom web applications that are currently authenticating against
ADAM. ADAM is populated with proxy Objects from AD and also ADAM user
accounts. ADAM was used because we did not want to extend the AD schema
for
these applications.

Problem: I have a requirement for a new forest to authenticate against
this
application. We would like a single source for authentication. The new
forest is going to require a deployment of a new ADAM instance.

Questions: Is there a way for a single ADAM instance to proxy
authentication to multiple backend ADAM servers?

Can I do this without deploying MIIS? I would like to stay away from a
meta-directory and sync scripts if I can)

Thanks for any help. (BTW - I am looking at a product called RadiantOne
VDS
to help with this problem, but would like to stick with a Microsoft
solution).


.



Relevant Pages

  • Re: Can ADAM do this?
    ... if the machine ADAM is on has a trust relationship with the Windows ... of that forest, then it should be able to authenticate any of them. ...
    (microsoft.public.windows.server.active_directory)
  • Re: ADAM Proxy Authentication and Movetree
    ... the separate domain trusts with one single forest trust, ... The reason our ADAM cluster is in a separate forest is mainly because we ... will also be provisioning users to ADAM from an external client domain which ...
    (microsoft.public.windows.server.active_directory)
  • Re: is the AD LDAP interface domain trust aware?
    ... This might also be the kind of thing that you could use ADAM and MIIS to ... Essentially, you build the forest you need for your Windows stuff, ... >> can I use LDAP query's on this 2 domain situation on one domain ...
    (microsoft.public.windows.server.active_directory)
  • Re: ADAM Proxy Authentication and Movetree
    ... trust in place from the outset for this to work and that possible ... Move ADAM into the forest where users live. ... >> yet to be upgraded to Windows Server 2003. ...
    (microsoft.public.windows.server.active_directory)
  • Re: External Active Directory and IIS 6.0
    ... servers and then install ADAM on a member server who is part of this forest? ... This is a direct link to the Microsoft Public ...
    (microsoft.public.windows.server.active_directory)