Re: Active Directory to ADAM Sync Password question



You can't read passwords out of AD or sync them with ADAMSync.

However, I'm confused by your statement as bind proxy objects are designed
specifically so that you can have an object in ADAM to do a simple bind on
and have the actual authentication be performed directly against AD, thus
eliminating the need to sync the password in the first place.

Can you explain in more detail what that problem here is.

Joe K.
--
Joe Kaplan-MS MVP Directory Services Programming
Co-author of "The .NET Developer's Guide to Directory Services Programming"
http://www.directoryprogramming.net
--
"chienine" <chienine.3ba4rd@xxxxxxxxxxxxx> wrote in message
news:chienine.3ba4rd@xxxxxxxxxxxxxxxx

I was following this topic and wanted to ask if any one here have
specific experience with ADAM and manageing users which are of the user
objectClass. I am a computer programmer and maintain a php application
(SSO) that communicates with ADAM thru LDAP. I have successfully set up
my ADAM (AD LDS) instance on Windows Server 2003 and do use ADAMSync to
sync user accounts from AD into ADAM with no real issues.

I have setup a bind-user which is a userProxy object which
successfully supports a simple bind (redirection to AD) providing
Readers role access to ADAM via LDAP port 389. What I am doing is
designing a LDAP SSO solution to support an AD/ADAM backend. This will
afford me a simpe method to authenticate my users via a PHP application
against Active Directory. I do have scheduled tasks configured and
scripts written which help populate my ADAM instance with AD user
accounts.

My issue here is getting user passwords to Sync from AD -> ADAM for
each distinguishedName (simple user account). When I used ADSIEdit to
set the users password in ADAM my PHP application will authenticate via
LDAP and pull the sAMAccountName and password for simple authentication.
The main issue I am having is getting those passwords (userPassword)
which is defined in AD to successfully Sync with ADAM for each user
object class that is enabled in AD.

Any help would be simply appreciated as I am fairly new to how AD
stores user account password info. I have made note that the
userPassword attribute is available but not set in ADAM. Is it possible
to modify the ADAMSync.xml to sync passwords for each AD user instance
in ADAM? If not how can I get those user passwords from AD into ADAM.

Thanks in advance!!


--
chienine
------------------------------------------------------------------------
chienine's Profile: http://forums.techarena.in/member.php?u=51777
View this thread: http://forums.techarena.in/showthread.php?t=989062

http://forums.techarena.in



.



Relevant Pages

  • Re: Architectural question for product security deployment
    ... ADAM uses the local and domain policies where it's installed. ... Also, to change passwords via LDAP, you must connect via a secure method by ... bit (may not work in workgroup setting; you may need an alternate method, ... > 1) I Installed ADAM by first logging in a system admin and creating the ...
    (microsoft.public.windows.server.active_directory)
  • Re: ADAM - AD_Schema load fails with error
    ... It sounds like you are saying that the passwords are not bought down by ... If ADAMSync is bringing accounts into ADAM as native accounts... ... >> somewhere as Windows Principals. ...
    (microsoft.public.windows.server.active_directory)
  • Re: ADAM user authentication
    ... auxiliary class to the auxiliaryClass of the ADAM classSchema user object?? ... If you go down this route then you will need to maintain ADAM user passwords ... as well as AD user passwords by sync or otherwise, ... Bind type: Simple bind ...
    (microsoft.public.windows.server.active_directory)
  • Re: Configuring ADAM replication resets passwords
    ... applied on the other systems which causes the passwords to be effectively ... even though the actual ADAM data is replicated. ... after you configure replication which ADAM instance is your ...
    (microsoft.public.windows.server.active_directory)
  • Re: ADAM installed
    ... The only way to sync AD passwords into ADAM is to use MIIS/IIFP ... Extended the ADAM Schema to match the Windows 2003 schema ...
    (microsoft.public.windows.server.active_directory)