RE: Active Directory password external use

From: Michael Scheidell (scheidell_at_secnap.net)
Date: 09/01/05

  • Next message: Sebastian Zdrojewski: "R: Active Directory password external use"
    Date: Wed, 31 Aug 2005 20:31:24 -0400
    To: "Rodrigo Blanco" <rodrigo.blanco.r@gmail.com>, <focus-ms@securityfocus.com>
    
    

    > -----Original Message-----
    > From: Rodrigo Blanco [mailto:rodrigo.blanco.r@gmail.com]
    > Sent: Wednesday, August 31, 2005 2:27 AM
    > To: focus-ms@securityfocus.com
    > Subject: Active Directory password external use
    >
    >
    > Hello list,
    >
    > I am currently doing a project that requires using the Active
    > Directory users' password for other purposes other than just
    > workstation logon or share access.
    >
    > What I would need to do is detect password change / reset
    > events on the domain, capture the new password and send it to
    > another application. This could be done with an agent or
    > daemon running on the DC machine.

    Better idea:

    When a user logs on this other resource, just use an smb (or pam_smb?)
    library, or maybe use LDAP to pass the username/password back to the AD
    server.

    That way there is no need to sync passwords, and no need to even store
    them on the other servers.

    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------


  • Next message: Sebastian Zdrojewski: "R: Active Directory password external use"

    Relevant Pages

    • Logon Scripts over VPN connections
      ... I have set up a Win 2K RAS Server as a VPN server that authenticates Active ... Directory users via a Radius server, that connect via a wireless link It ... However when I try to run a logon script to map ... drives and printers, the script runs under the username of the locally logged ...
      (microsoft.public.scripting.vbscript)
    • Re: I think my problem is with DNS
      ... Currently we have 2 windows 2003 sp1 DCs. ... A third machine is a member server housing exchange. ... When I try to start the Exchange System Manager administrative tool, ... Directory Users and Computers ADUC. ...
      (microsoft.public.windows.server.dns)
    • Re: Editing Multiple Users
      ... You are not stupid you can't edit multiple objects at once in Active ... adminpack.msi it includes a version of Active Directory Users and Computers ... The Windows Server 2003 Administration Tools Pack provides ...
      (microsoft.public.windows.server.active_directory)
    • Re: Load Balancing 2 Servers and profiles
      ... Launch Active Directory Users and Computers on the domain ... Services Profile stuff. ... >> name and YOUR_FILE_SERVER is a file server you may have. ... >> For Load Balancing if you are using Windows 2003 TS you can use NLB, ...
      (microsoft.public.windows.terminal_services)
    • RE: Accounts are getting locked
      ... "Harsha" wrote: ... > We are having a windows 2000 Server as a Domain Controller. ... > Unlocking was done manually going to property dialog of each user from Active ... > Directory Users and Computers. ...
      (microsoft.public.win2000.group_policy)