ldap authentication in multforest domain?

From: Jims (biz_at_neocasa.net)
Date: 02/25/04


Date: Wed, 25 Feb 2004 13:45:57 -0500

In a forest with multiple domains, what is the recommended strategy for ldap
consuming applications to bind to the forest for user information? For
instance, a non windows application authenticates a user by using their
application login credentials to perform a simple bind to a domain
controller and if successful grant the user access to the application. The
problem is that users are spread out on several domains within the forest
and an ldap search to a dc in one domain may or may not be sufficient
because the user might be in another domain in the forest. What is the best
practice here? Can ldap be used to bind to a global catalog server in order
to assure all users in the forest are represented?

Jim



Relevant Pages

  • Re: LDAP bind to Global Catalog dilemma?
    ... > In a forest with multiple domains, what is the recommended strategy for ldap ... > consuming applications to bind to the forest for user information? ...
    (microsoft.public.windows.server.active_directory)
  • LDAP bind to Global Catalog dilemma?
    ... In a forest with multiple domains, what is the recommended strategy for ldap ... consuming applications to bind to the forest for user information? ...
    (microsoft.public.windows.server.active_directory)
  • How do I locate an object using its sid in a multi-forests environ
    ... Hi, I'm using vs2005, .net2 for a windows applicaiton. ... I need to bind to an ... and I only have its sid. ... If this object is not in current forest, then, how can I verify if the ...
    (microsoft.public.dotnet.security)
  • Re: Query AD from DMZ via LDAP?
    ... You don't really need ADAM for this unless you need LDAP simple bind, ... authentication to apps on the public internet, ...
    (microsoft.public.windows.server.active_directory)
  • Re: Troubleshooting DC with dcdiag
    ... attempting to bring this DC back into replication is a bad idea ... >>> RPC B ... >>> LDAP ... >>> Bind ...
    (microsoft.public.windows.server.active_directory)