Re: LDAP lookup based on a Security group?



"Transam388" <Transam388@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:FBDCB2C6-B59E-4ED2-9F08-E79654A144B4@xxxxxxxxxxxxxxxx
Not sure if this belongs here but this is the question. We have a devie
which we would like to do an LDAP lookup against our 2003 AD. Now this is
the twist...is it possible to base the account that this is done on a
security group versus a specific account? Essentially looking for a way
that
only the persons within that group can execute this LDAP but not have it
based only on one ID.

Thanks!!

Well, I am not quite sure I am guessing what you ask by saying

is it possible to base the account that this is done on a security group

Does that mean: can we limit the account(s) doing the LDAP query to
members of a security group ?

In general, any forest account can use LDAP to query just about anything.
You can limit what account(s) can execute some app/script your dev
comes up with, sure, and by groups too. But that does not mean that
only those accounts are able to run the query used in the app/script.
To control what accounts can get results for some specific LDAP query
you would have to control what accounts can read the AD objects/attributes
in AD via their permissions - something you should only do with awareness
of possible implications.

Roger


.



Relevant Pages

  • [NT] Security considerations to keep in mind when using Site Server 3.0
    ... Site Server version 3.0 Commerce Edition ... LDAP_Anonymous user account, which is used by the included LDAP service. ... A valid NT user account is required to upload ...
    (Securiteam)
  • Re: Less Informaion Availiable in LDAP on SBS than Server 2003
    ... Just tried and apparently if a user account is a member of "Domain Power ... Users" then I can query these LDAP attributes. ... While you might upgrade the schema on SBS to v31 note that a SBS R2 ...
    (microsoft.public.windows.server.sbs)
  • Re: Less Informaion Availiable in LDAP on SBS than Server 2003
    ... Compatible Access" we were able to query all attributes just fine on SBS. ... You can also modify your setup to allow anonymous LDAP access... ... Just tried and apparently if a user account is a member of "Domain Power ... causing us not to be able to query the UNIX attributes from ...
    (microsoft.public.windows.server.sbs)
  • Re: Less Informaion Availiable in LDAP on SBS than Server 2003
    ... Compatible Access" we were able to query all attributes just fine on SBS. ... You can also modify your setup to allow anonymous LDAP access... ... we wanted to use a very limited account, like you can use under 2003R2. ... I get the same results using ldapsearch from a UNIX command line ...
    (microsoft.public.windows.server.sbs)
  • Re: Less Informaion Availiable in LDAP on SBS than Server 2003
    ... Have you tried running the LDAP query under a power user account? ... causing us not to be able to query the UNIX attributes from ... While you might upgrade the schema on SBS to v31 note that a SBS R2 ...
    (microsoft.public.windows.server.sbs)