Re: LDAP in SBS 2003?

Tech-Archive recommends: Fix windows errors by optimizing your registry



Cliff Galiher wrote:
Ahh... Yes, there is a better way.

I'm with you on this one Cliff, there's at least one better way and probably
many better ways than exposing your AD to external authenticated ldap
queries. (and because this is an authenticated connection to your sbs server
it would use a (at least one) device CAL for your external mail server).

So, here's another way too. Maybe more work than Cliffs scripting, but for
larger scale solutions perhaps a preferable method (and it could avoid the
CAL requirement too)

http://technet.microsoft.com/en-us/library/cc783121.aspx




I have written a small perlscript generates a txt file with the
addresses. With that perl script, I can add any formatting the
program requires (like Postfix prefers an OK after each address) or
whatever. I then can customize the perl script do *do* something
with that file.
I have this script in place to rsync a copy out to a postfix server.
Another version will use the perl HTTP libraries to update the valid
list out on a dyndns backup MX account.

The point is the script generates the list and the connection to
update the necessary server is OUTGOING, not INCOMING. And my LDAP
server is never exposed.

I personally would *STRONGLY* recommend this approach.

-Cliff


"Charles Lavin" <x@xxx> wrote in message
news:B596E1F0-C653-4499-8BAF-072150958E48@xxxxxxxxxxxxxxxx
There is no better way. I have an outside mail server that needs to
verify email addresses. I either maintain a separate list of email
addresses on the outside server, or (as they recommended) I set up
the outside server to perform LDAP queries on the SBS box. I would
much rather set this up to only allow LDAP queries from the outside
mail server and not from the Internet at large -- authenticated user
or not. Tnx

"Cliff Galiher" <cgaliher@xxxxxxxxx> wrote in message
news:fc2dndlbJYZn4kXVnZ2dnUVZ_qXinZ2d@xxxxxxxxxxxxxx
Well, active directory uses LDAP...so exposing the default LDAP
ports through your firewall is exposing active directory. This is
a *VERY BAD IDEA!!!!!*

So perhaps, if you can explain in more detail, what you are trying
to accomplish and what app needs this access, we can find a better
way. -Cliff


"Charles Lavin" <x@xxx> wrote in message
news:ur2lnNSHJHA.1308@xxxxxxxxxxxxxxxxxxxxxxx
Hi --

I have an SBS 2003 SP2 box running Windows Firewall (not ISA) and
also behind a Netopia router with firewall features.

I need to allow an outside server to perform LDAP queries on the
SBS box. I want to set it up so that LDAP queries are only allowed
from the IP address of this outside server.

Where do I find the proper docs to allow me to set this up? I
can't seem to find any suitable info on setting up LDAP on Windows
servers. I can set up pinholes on the Netopia router to allow the
LDAP ports through to the SBS box, but I have no IP address
control from there. Thanks,
CL

--
/kj


.



Relevant Pages

  • RE: server/connectcomputer from remote offices
    ... We have the sbs server installed at location A. ... The problem lies in the fact that the first line in the script points at ... the client machines have to ...
    (microsoft.public.windows.server.sbs)
  • RE: server/connectcomputer from remote offices
    ... I understand that you want to copy some files from SBS Server to DCs locate ... second DC or member server in the SBS 2003 domain, we can use the DFS to ... >The problem lies in the fact that the first line in the script points at ...
    (microsoft.public.windows.server.sbs)
  • Re: Default POP email in Outlook keeps changing back to exchange s
    ... You may experience high memory usage on an ISA Server 2004-based computer ... about SBS in the process. ... script from doing its' job. ... without requiring a registry change. ...
    (microsoft.public.windows.server.sbs)
  • Re: RPCHTTP_setup.vbs
    ... If you are needing to setup the server side (based on that script).. ... Internet Connection Wizard (Connect to Internet link on the To Do List in ... SBS v4.x: microsoft.public.backoffice.smallbiz ...
    (microsoft.public.windows.server.sbs)
  • Re: unexpected "default gateway changes" SBS network.
    ... > dhcp clients on the other subnet were left alone by the script. ... my SB server is a one ... >> server runs the default sbs logon script, ...
    (microsoft.public.windows.server.networking)