AD LDS resources

Main entry point: AD DS vs AD LDS – Active Directory solutions compared step1 – backup AD LDS: step2 – restore AD LDS: On MS Technet:   AD LDS Replication Step-by-Step Guide Step 1: Practice Managing Replica AD LDS Instances Step 2: Practice Managing Site Objects Step 3: Practice Managing Site Link Objects

Unix interoperability (SSSD) with a Microsoft Domain

SSSD principle: SSSD for SuSE (sles): RHEL: Troubleshooting SSSD: Resolution:   id  <userid> ; getent passwd <userid> Authentication: ssh <userid>@localhost   In addition to redhat guide, there are tones of interesting links:

Free Tools for System and Network or DB Administrators

Free tools for Windows sysadmin   – Find string if files on Windows: using findstr /s /i findstr /s /i /C:"provider=sqloledb" d:\dir\*.* Find and replace string in file (Find and Replace == fnr) : other tool requiring also JAVE: FAR – Test SSL and TLS: _Well-known online tools for network engineers:

Portqry failed with UDP/389

Understanding UDP 389 portqry error and how to solve this issue: Solution: check windows firewall check AV software (McAfee, Symantec…) check if IPV6 is disabled else renable it:

What is OAuth? OAuth versus Kerberos ! ADFS and OAuth !

Introduction: When Kerberos was chosen to be AD's authentication protocol in the mid- to late-1990s, the World Wide Web was a shadow of what the Internet offers today. Although the Kerberos ticket contained an encrypted password hash that could be attacked, there wasn't any substantial requirement to provide support outside the highly protected corporate firewall.

Active Directory: How to limit ldap queries ?

Hi, here is a new article to explain how to limit ldap queries (in order to minimize attacks or to minimize impact on the performance of ldap/AD server): Technet article: AD does not allow anonymous connection: By default, anonymous Lightweight Directory Access Protocol (LDAP) operations to Active Directory, other than rootDSE searches and

AD CS (PKI) Installing and Troubleshooting SSL certificate

The simplest way is using the MMC certificates. However is it only available for the GUI-based Windows servers. If you are using Core-based Servers, you cannot use the MMC. Or if you prefer, it is also possible using the command line: Note: To request a SSL certificate on w2k8-w2k8r2, it is recommended to use the default CA template:

Searching AD objects with ldapsearch

Ldapsearch is available by default on most of Linux/Unix with Openldap packages installed. else ldapsearch is also available on Windows servers: syntax: ldapsearch -x -LLL -E pr=200/noprompt -h [AD Host] -D [AD User] -w [AD Pass] -b [Base DN] -s sub "([LDAP Filter])" [attr list] example: ldapsearch -b dc=mydomain,dc=net -h -D 'cn=app-nceldap,ou=services&applis,dc=mydomain,dc=net' -w

LDAP resources

LDAP LDAP (Lightweight Directory Access Protocol) est un protocole d'accès à un annuaire,  dérivé d' X500, au dessus de TCP/IP. C'est une implémentation allégée du protocole ISO DAP. Il est devenu le standard des annuaires électroniques qui prennent de plus en plus d'importance dans les systèmes d'information des entreprises… Pointeurs pour démarrer Le tutorial LDAP