Re: accessing Active Directory

From: reda (reda_at_discussions.microsoft.com)
Date: 08/25/05


Date: Thu, 25 Aug 2005 01:21:07 -0700

Dear Joe,

Thank You for your help.

I find the document and tried to apply the delegation in the active directory
first I made the users accounts to be trusted for delegation, not sensetive,
and can be delegated
then I made the web server computer to be trusted for delegation

but I still have the same error !!
is there any other settings should take place in the active directory or in
the web server itself ?

Thank You,

"Joe Kaplan (MVP - ADSI)" wrote:

> This is a double hop issue. Essentially, the security token can go "one
> hop" from either the browser to the web server or directly from the web
> server to the AD if the browser was run from the local server, but it can't
> go two hops from the browser to the web server to the AD.
>
> If you really must access AD with the security context of the current user
> and you want to use IWA authentication in the web site, you need to also
> implement Kerberos delegation to overcome the double hop limitation.
>
> http://msdn.microsoft.com/vstudio/using/building/web/default.aspx?pull=/library/en-us/dnnetsec/html/SecNetHT05.asp?FRAME=true#ImplementKerberos
>
> http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/security/tkerberr.mspx
>
> If you don't need to use the authenticated user's security context to access
> AD, then you can use a service account instead. If you specify credentials
> or change the worker process to use a domain account and disable
> impersonation, you can do this instead. This arcticle has some suggestions.
>
> http://support.microsoft.com/default.aspx?scid=kb;en-us;329986
>
> Joe K.
>
> "reda" <reda@discussions.microsoft.com> wrote in message
> news:70D7BC57-F466-408E-A6A6-C1A18A8FABAE@microsoft.com...
> > Hi all,
> >
> > I am developing asp.net application using windows authentication from
> > active
> > directory on a local area network. the domain controller is not on the
> > same
> > machine of the IIS. when trying to get the display name of the logged in
> > user
> > I am getting an error if I try remotly even if user is logged in but it
> > works
> > fine localy on the web server.
> >
> > I am new in using directoryservice namespace and donnt find any document
> > to
> > disccus how to emplement an application like that using active directory
> > hosted on another server.
> >
> > this is my code
> >
> > DirectorySearcher ds = new DirectorySearcher();
> > ds.SearchRoot = new DirectoryEntry("LDAP://CN=users,DC=TAC,DC=local");
> > string filter = "";
> > filter += FormFilter("user", userName);
> > filter = "(|" + filter + ")";
> > ds.Filter = filter;
> > ds.PropertiesToLoad.Add("*");
> > System.DirectoryServices.SearchResult res = ds.FindOne();
> >
> > in the last line I get "An Operations error occurred"
> >
> > both of web server and domain controller are windows 2003 and the domain
> > name is TAC.LOCAL
> >
> > any body can help me ?
> >
> > Regards,
> >
>
>
>



Relevant Pages

  • Re: CA web component problems
    ... Could you please confirm that the Enterprise Admin account you are using is ... > for delegation via the ADUC check box. ... is there a way to install the Web enrollment pages ... >>> enabled the web server for delegation via ADUC and rebooted the ...
    (microsoft.public.win2000.security)
  • Re: Avoiding password history setting
    ... I am spending most of my time right now putting the final touches on O'Reilly's Active Directory 3rd Edition. ... They should have a setting to specify history in the product itself, you shouldn't need to use the domain policy for that to be enforced. ... Further, I know their product works with a delegated account, I wouldn't let them use anything else and they had to correct the product to work. ... As for delegation, there is nothing that walks through every single possible thing you can click on as it is extensiable. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Windows integrated authentication with site content on UNC share...
    ... I have configured the AD such that the web server and the ... checkbox for "Trust computer for delegation". ... right clicking on the user account, went to "Account" tab and enabled ... Client Realm: ...
    (microsoft.public.inetserver.iis.security)
  • Re: SqlXml Bulk Load Error: COMException (0x80004005)
    ... describe that were resolved by setting the "Trusted for Delegation" group ... policy setting. ... Neither the IIS Computer itself nor the account it is using are setup for ... If I use same account on a box with both a web server and a sql server on it ...
    (microsoft.public.sqlserver.xml)
  • Re: domain local group
    ... But I'm curious, as far as adding a user to a domain local group, which is one of the best practice methods to administer group nesting, what is your intentions? ... Here is some additional information on delegation, but Meinolf and Florian already provided you on the default ability of a user account to add computers. ... Best Practices for Delegating Active Directory ...Nov 25, ...
    (microsoft.public.windows.server.active_directory)