Re: Export Passwords from AD
- From: "Jorge de Almeida Pinto [MVP - DS]" <SubstituteThisWithMyFullNameSeparatedByDots@xxxxxxxxx>
- Date: Wed, 14 Jan 2009 12:42:58 +0100
I not saying it is the correct solution. It isn't! I'm just saying it is not impossible and it is considered hacking. If you want to sync passwords between multiple sources, then use something like MS ILM 2007 FP1 and PCNS ("Password Change Notification Service")
--
Cheers,
(HOPEFULLY THIS INFORMATION HELPS YOU!)
# Jorge de Almeida Pinto # MVP Identity & Access - Directory Services #
BLOG (WEB-BASED)--> http://blogs.dirteam.com/blogs/jorge/default.aspx
BLOG (RSS-FEEDS)--> http://blogs.dirteam.com/blogs/jorge/rss.aspx
------------------------------------------------------------------------------------------
* This posting is provided "AS IS" with no warranties and confers no rights!
* Always test ANY suggestion in a test environment before implementing!
------------------------------------------------------------------------------------------
#################################################
#################################################
------------------------------------------------------------------------------------------
"Michael Ströder" <michael@xxxxxxxxxxxx> wrote in message news:l5q046-j01.ln1@xxxxxxxxxxxxxxxxxxx
Irwin Fletcher wrote:And I'm still wondering if MIIS and / or ILM can export password hashes
or clear text passwords from an AD?
As I already wrote: Something like this is done via password change
interception. I don't know of any AD sync implementation which does it
differently. Extracting NT hashes and conduct dictionary attacks does
not scale well.
So if you implement something like this you have to set all passwords to
expired for enforcing a password change for all users. Or you could do
this one-by-one for users who want to use the Google account.
But I'd strongly recommend not to sync the local AD passwords to Google
anyway.
Ciao, Michael.
.
- References:
- Export Passwords from AD
- From: Irwin Fletcher
- Re: Export Passwords from AD
- From: Meinolf Weber [MVP-DS]
- Re: Export Passwords from AD
- From: Irwin Fletcher
- Re: Export Passwords from AD
- From: Paul Bergson
- Re: Export Passwords from AD
- From: Jorge de Almeida Pinto [MVP - DS]
- Re: Export Passwords from AD
- From: Michael Ströder
- Re: Export Passwords from AD
- From: Paul Bergson
- Re: Export Passwords from AD
- From: Joe Kaplan
- Re: Export Passwords from AD
- From: Irwin Fletcher
- Re: Export Passwords from AD
- From: Michael Ströder
- Export Passwords from AD
- Prev by Date: Re: [WARNING] Failed to query SPN registration on DC
- Next by Date: Re: [WARNING] Failed to query SPN registration on DC
- Previous by thread: Re: Export Passwords from AD
- Next by thread: Re: Export Passwords from AD
- Index(es):
Relevant Pages
|