RE: DC migrated from NT4 to 2003: cannot LDAP top level search dc=

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: Andreas Raschle (AndreasRaschle_at_discussions.microsoft.com)
Date: 11/23/04

  • Next message: Rebecca Chen [MSFT]: "Re: A difficult migration (2000 -> 2003)"
    Date: Tue, 23 Nov 2004 01:25:01 -0800
    
    

    Hello Carsyn
    Sorry that I could not answer earlier. I was away in a course (on the long
    way to MCSA:-)
    Thank you very much for your answer. I try to explain more:
    I use a self written tool by colleagues of me:
    http://www.c4b.de/ucp
    Then follow on the left:
    - Unified Messaging
    - Intravoice Unify 2.0
    Then in the center:
    - Software
    - Tools
    and therin get the LdapTest.zip.

    I have a domain called ucp.local (FQDN)
    Server 'Forest' ist the master
    Within the cn=users there is the standard administrator

    So my settings to look for users is:
    distinguished name for queries: 'cn=users,dc=ucp,dc=local'
    WHAT NOT WORKS: 'dc=ucp,dc=local'
    Server: 'forest', Port 389
    Authentication:
    Account: 'cn=Administrator,cn=users,dc=ucp,dc=local'
    Password: ******

    As far as I know within the tool LDAP V2 is used, but within the software we
    use V3. But it makes no difference, the Tool nor the Software can find any
    users if I want to search for users in all organisational units.

    Unfortunately there is no error than 'no user found'
    normally one get's messages like 'invaild credentials'

    Thank you for any answer or further question in this topic.
    Andreas

    "Carsyn Gu [MSFT]" wrote:

    > Hello Andreas,
    >
    > Thank you for your post.
    >
    > Firstly, before we go further on this issue, would you please let me know
    > more about the error you mentioned in an upgraded Windows Server 2003
    > environment? Did you receive any error message concerning on the error?
    > More specific information can help us to narrow down the root cause and to
    > get the issue resolved more efficient.
    >
    > Secondly, would you please let me know the query method of your
    > application? Generally speaking, if an application is okay to operation in
    > the flash installed Windows Server 2003 system, it should be no problem to
    > run in an upgraded system. We need to analyses the application firstly.
    >
    > Looking forward to your reply!
    >
    > Sincerely,
    > Carsyn Gu
    > Microsoft Online Partner Support
    >
    > Get Secure! - www.microsoft.com/security
    >
    > =====================================================
    > When responding to posts, please "Reply to Group" via
    > your newsreader so that others may learn and benefit
    > from your issue.
    > =====================================================
    >
    > This posting is provided "AS IS" with no warranties, and confers no rights.
    >
    > --------------------
    > | Thread-Topic: DC migrated from NT4 to 2003: cannot LDAP top level search
    > dc=comp
    > | thread-index: AcTFgsuodSb0fjTJT/ilfpOiuVWN8w==
    > | X-WBNR-Posting-Host: 83.77.221.158
    > | From: =?Utf-8?B?QW5kcmVhcyBSYXNjaGxl?=
    > <AndreasRaschle@discussions.microsoft.com>
    > | Subject: DC migrated from NT4 to 2003: cannot LDAP top level search
    > dc=comp
    > | Date: Mon, 8 Nov 2004 03:05:02 -0800
    > | Lines: 21
    > | Message-ID: <2C9B924D-A2A7-4FAD-8BE2-9202CDA85521@microsoft.com>
    > | MIME-Version: 1.0
    > | Content-Type: text/plain;
    > | charset="Utf-8"
    > | Content-Transfer-Encoding: 7bit
    > | X-Newsreader: Microsoft CDO for Windows 2000
    > | Content-Class: urn:content-classes:message
    > | Importance: normal
    > | Priority: normal
    > | X-MimeOLE: Produced By Microsoft MimeOLE V6.00.3790.0
    > | Newsgroups: microsoft.public.windows.server.migration
    > | NNTP-Posting-Host: TK2MSFTNGXA03.phx.gbl 10.40.1.29
    > | Path:
    > cpmsftngxa10.phx.gbl!TK2MSFTNGXA01.phx.gbl!TK2MSFTNGP08.phx.gbl!TK2MSFTNGXA0
    > 3.phx.gbl
    > | Xref: cpmsftngxa10.phx.gbl microsoft.public.windows.server.migration:15080
    > | X-Tomcat-NG: microsoft.public.windows.server.migration
    > |
    > | Dear readers
    > | I did install a fresh Windows 2003 domain and therein ADS I can build
    > | various Organisational Units (ou) with users inside.
    > |
    > | Our LDAP software must search for users all over the domain:
    > | disdinguished name for querries: dc=company,dc=com
    > |
    > | This works fin on a freshly installed Windows 2003
    > |
    > | But if I did an update from NT4 to Windows 2003 this LDAP search does not
    > | work. I get an LDAP connect error.
    > |
    > | Has anybody an idea where in Windows 2003 this behavior can be set up or
    > | configured so I can as well search for all users?
    > |
    > | Thanks for any comments in advance
    > | --
    > | Andreas Raschle
    > | Unified Communications
    > | Swisscom Systems AG
    > | Gossau, Switzerland


  • Next message: Rebecca Chen [MSFT]: "Re: A difficult migration (2000 -> 2003)"

    Relevant Pages

    • Re: format of service principal name (SPN)
      ... I can't speak to DsWriteAccountSpn. ... I justed used my own admod (simple LDAP mod tool) to set an SPN with spaces in both the service name and service class. ... Joe Richards Microsoft MVP Windows Server Directory Services ...
      (microsoft.public.windows.server.security)
    • Re: Create User who can only query LDAP
      ... There is no way of creating a such user account, How ever Anonymous LDAP ... operations to Active Directory are disabled on Windows Server 2003 domain ...
      (microsoft.public.windows.server.active_directory)
    • LDAP Error - 1216
      ... Windows 2008 server and the 2003 are domain controllers and the second ... article on "How to enable LDAP signing in Windows Server 2008" but I am ... these are the only LDAP errors being logged. ...
      (microsoft.public.windows.server.active_directory)
    • Re: mail validation for multiple active directory domains [ldap_routing]
      ... acting as a mail hub and a windows server 2003 running exchange. ... Using the available howtosI have already configured sendmail to ... server as the default ldap configuration is ...
      (comp.mail.sendmail)
    • Re: DNS
      ... Microsoft MVP: Windows Server ... MCSE/MCSA: Messaging ...
      (microsoft.public.windows.server.general)