Re: Is is possible to have Active Directory use a different LDAP server for logging in users?



Thanks Joe, I think that will help out a lot and will look into it.

Kind of funny that you replied considering I am reading your book right
now.

-Ian


Joe Richards [MVP] wrote:
It is if you can kerberize the Tivoli stuff and make it into its own
realm (i.e. like a domain). Then you tell AD to trust that realm and it
will be similar to using another trusted domain.

Otherwise no, LDAP isn't a good auth mechanism and isn't an auth
protocol at all despite the fact that people use it for that. Windows
uses kerberos for Auth because it is a true auth protocol designed
specifically for that purpose.


--
Joe Richards Microsoft MVP Windows Server Directory Services
Author of O'Reilly Active Directory Third Edition
www.joeware.net


---O'Reilly Active Directory Third Edition now available---

http://www.joeware.net/win/ad3e.htm


Ian Becker wrote:
In our current environment, we have a Tivoli Directory server that is
our main LDAP server, would it be possible to have Active Directory
pass through logons to that to authenticate users without actually
replicating the databases?

Thanks,
Ian


.



Relevant Pages

  • Re: URL Authorzation Problem
    ... Serves me right... ... > Hello Joe, ... >> What I'm not totally sure about is whether the forms auth module will ... >> I'm not really that much of a forms authentication expert as it is. ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: Does IsInRole() check against Active Directory groups?
    ... people do forms auth against AD if there is a technical or policy ... problem with making the web server a domain member or someone really wants ... > Thanks Joe, this worked. ... >> can authenticate users in your target domain and you have ASP.NET ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: Unlock acct permissions
    ... > "Active Directory Design and Deployment" ... > and which Joe referenced. ... >> These are some of the best books out there right now for AD Admin level ... How do I get DSACLS to run on a specific account? ...
    (microsoft.public.win2000.active_directory)
  • Re: Default tombstone lifetime
    ... besides what joe mentioned some more details in the following article... ... Joe Richards Microsoft MVP Windows Server Directory Services ... is used when building a new forest and it isn't like that is buggy. ...
    (microsoft.public.windows.server.active_directory)
  • Re: PasswordFilter and ASP.NET
    ... looking at the set policy. ... Joe Richards Microsoft MVP Windows Server Directory Services ... >>Joe Richards Microsoft MVP Windows Server Directory Services ...
    (microsoft.public.platformsdk.security)