Go Back   TechArena Community > Technical Support > Computer Help > Windows Server > Active Directory
Become a Member!
Forgot your username/password?
Register Tags Active Topics RSS Search Mark Forums Read SiteMap

Tags: ,

Sponsored Links



Connecting using DN fails, have to use email address

Active Directory


Reply
 
Thread Tools Search this Thread
  #1  
Old 07-04-2008
anywherenotes@gmail.com
 
Posts: n/a
Connecting using DN fails, have to use email address

Hi, I'm experiencing a problem at a client with the following command:
../ldapsearch -T -h corpntpd01 -p 389 -w <password> -D
"CN=rndtest,OU=Generic User IDS,DC=soft,DC=com" -b
"cn=users,dc=soft,dc=com" "(sAMAccountName=bob)"

However this command works
../ldapsearch -T -h corpntpd01 -p 389 -w <password> -D
"rndtest@soft.com" -b "cn=users,dc=soft,dc=com" "(sAMAccountName=bob)"
(the only change is in the argument to "-D")

Basically, even though the dn specified seems to be correct, it does
not work. This is the error we get:
ldap_simple_bind: Invalid credentials
ldap_simple_bind: additional info: 80090308: LdapErr: DSID-0C090334,
comment: AcceptSecurityContext error, data 525, vec

The client is able to use the email address, but it's my understanding
that DN has to work, and the application is built on that premise.

Please let me know what you think the issue is, such as is it possible
to disable DN access somehow? or is there something else preventing DN
from working.

I do not have access to client machine, the customer support has been
handling the issue, but I'd like to understand it in more detail, and
any pointers are greatly appreciated.

Thank you.
Alex
Reply With Quote
  #2  
Old 07-04-2008
Joe Kaplan
 
Posts: n/a
Re: Connecting using DN fails, have to use email address

Usually this means that the DN is not correct. Are you sure that is right?

I also suggest you not deploy an application that uses LDAP simple bind
unless you are doing to deploy SSL on the domain controller as well and
connect via SSL.

Joe K.

--
Joe Kaplan-MS MVP Directory Services Programming
Co-author of "The .NET Developer's Guide to Directory Services Programming"
http://www.directoryprogramming.net
--
<anywherenotes@gmail.com> wrote in message
news:158e9bf6-6100-4aaf-bc02-b0a39e82b494@d45g2000hsc.googlegroups.com...
> Hi, I'm experiencing a problem at a client with the following command:
> ./ldapsearch -T -h corpntpd01 -p 389 -w <password> -D
> "CN=rndtest,OU=Generic User IDS,DC=soft,DC=com" -b
> "cn=users,dc=soft,dc=com" "(sAMAccountName=bob)"
>
> However this command works
> ./ldapsearch -T -h corpntpd01 -p 389 -w <password> -D
> "rndtest@soft.com" -b "cn=users,dc=soft,dc=com" "(sAMAccountName=bob)"
> (the only change is in the argument to "-D")
>
> Basically, even though the dn specified seems to be correct, it does
> not work. This is the error we get:
> ldap_simple_bind: Invalid credentials
> ldap_simple_bind: additional info: 80090308: LdapErr: DSID-0C090334,
> comment: AcceptSecurityContext error, data 525, vec
>
> The client is able to use the email address, but it's my understanding
> that DN has to work, and the application is built on that premise.
>
> Please let me know what you think the issue is, such as is it possible
> to disable DN access somehow? or is there something else preventing DN
> from working.
>
> I do not have access to client machine, the customer support has been
> handling the issue, but I'd like to understand it in more detail, and
> any pointers are greatly appreciated.
>
> Thank you.
> Alex



Reply With Quote
  #3  
Old 08-04-2008
Paul Bergson [MVP-DS]
 
Posts: n/a
Re: Connecting using DN fails, have to use email address

Go into ADSIEdit and drill down to the user that you believe you have the
correct dn for. Go to properties and copy the DN from the user object and I
will bet you have a typo.

--
Paul Bergson
MVP - Directory Services
MCT, MCSE, MCSA, Security+, BS CSci
2008, 2003, 2000 (Early Achiever), NT4

http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup
This posting is provided "AS IS" with no warranties, and confers no rights.

<anywherenotes@gmail.com> wrote in message
news:158e9bf6-6100-4aaf-bc02-b0a39e82b494@d45g2000hsc.googlegroups.com...
> Hi, I'm experiencing a problem at a client with the following command:
> ./ldapsearch -T -h corpntpd01 -p 389 -w <password> -D
> "CN=rndtest,OU=Generic User IDS,DC=soft,DC=com" -b
> "cn=users,dc=soft,dc=com" "(sAMAccountName=bob)"
>
> However this command works
> ./ldapsearch -T -h corpntpd01 -p 389 -w <password> -D
> "rndtest@soft.com" -b "cn=users,dc=soft,dc=com" "(sAMAccountName=bob)"
> (the only change is in the argument to "-D")
>
> Basically, even though the dn specified seems to be correct, it does
> not work. This is the error we get:
> ldap_simple_bind: Invalid credentials
> ldap_simple_bind: additional info: 80090308: LdapErr: DSID-0C090334,
> comment: AcceptSecurityContext error, data 525, vec
>
> The client is able to use the email address, but it's my understanding
> that DN has to work, and the application is built on that premise.
>
> Please let me know what you think the issue is, such as is it possible
> to disable DN access somehow? or is there something else preventing DN
> from working.
>
> I do not have access to client machine, the customer support has been
> handling the issue, but I'd like to understand it in more detail, and
> any pointers are greatly appreciated.
>
> Thank you.
> Alex



Reply With Quote
Reply

  TechArena Community > Technical Support > Computer Help > Windows Server > Active Directory


Thread Tools Search this Thread
Search this Thread:

Advanced Search


Similar Threads for: "Connecting using DN fails, have to use email address"
Thread Thread Starter Forum Replies Last Post
Configure static IP address for connecting Netgear WNCE2001 Dvimida Networking & Security 3 19-10-2011 10:57 PM
Can't Update/Change EMail address on EMail Tab RDK Active Directory 14 14-01-2010 07:32 PM
Cant Verify email address because I deleted email Michael Windows XP Support 6 18-11-2008 07:52 PM
Adding new email address to exchange address book Jason Small Business Server 11 24-09-2008 06:48 PM
CEICW fails at Fails at email configuration aabrantes Small Business Server 7 09-04-2007 09:02 PM


All times are GMT +5.5. The time now is 05:37 PM.