Re: LDAP bind allowing old password for 1 hour



Hi
The test code I supplied is not the code from the (third party) SSO
application but just something we wrote to reproduce the problem.
Unfortunately we do not have access to the code used in the SSO application.
The domain controller is in a stand-alone domain/forest used primarily as a
central password synchronisation domain and the client is external to this
domain/forest. Its looking like we will need to ask them to use a different
technique to authenticate other than using a simple LDAP bind to avoid this
"feature" in Windows 2003 Active Directory. (For other purposes we have
written web services that use .Net to authenticate a user and these do not
exhibit the problem - we may need to get the SSO application to use such a
web service.)
Regards,
Alan


.



Relevant Pages

  • Re: LDAP bind allowing old password for 1 hour
    ... This is followup to report that defining registry value ... Unfortunately we do not have access to the code used in the SSO application. ... technique to authenticate other than using a simple LDAP bind to avoid this ... written web services that use .Net to authenticate a user and these do not ...
    (microsoft.public.windows.server.active_directory)
  • Re: Cold Fusion SSO and File Access
    ... SSO is private to the CF application, ... > I am a security engineer who just completed an Cold ... The web server is obviously IIS. ... > authenticate to the windows server. ...
    (microsoft.public.inetserver.iis.security)
  • SSO Application Launching
    ... I want to create a web part that uses SSO to authenticate to several ... web-based applications. ... Tony ...
    (microsoft.public.sharepoint.portalserver.development)