Hi All,
I can't seem to find any newsgroup on here for ADAM, so hopefully nobody
will mind if I post my question under the AD newsgroup instead.
I've recently been trying out an application which requires some changes to
be made to the AD schema (an additional object class). So I decided to try
out ADAM instead on a test machine. I created an ADAM instance, imported the
user LDIF file, modified the schedule to add the additional objectClass and
also created a test "user" object.
I've not had any problems creating objects in ADAM, but now I've got a few
questions which I'm hoping somebody can help me with?
1. I can open ADAM ADSI Edit just fine using my domain account which I used
to install ADAM and create the instance. However, I cannot use it to bind to
the ADAM instance using an LDAP browser - it says invalid credentials. Why
is this? How do I bind using an AD account? Or am I supposed to use an ADAM
account? I've tried googling this but keep coming up with ADAM BIND
redirection which seems to be something to do with userProxy objects from
what I can gather?
2. I didn't set a password on my test "user" object as the ADAM user will
never have to authenticate using ADAM, ADAM will only be used to authorize
the AD user. What is best practices for an situation like this? Should I
set a password, not set a password or ... ? Or should I be using a userProxy
object instead?
3. I've tried setting up a userProxy object, but it seems that it wants the
SID from AD, but it seems to want it in HEX format. How can I get this?
I've tried using converters etc but to no avail ........
4. If I create a userProxy object in ADAM (as I understand it, a userProxy
object is almost like an extension of an AD user - it contains attributes
that could be contained in AD, but avoids the hassle and risk of modifying
the AD schema) is it possible to add additional information to the ADAM
userProxy object and then have AD look at that ADAM instance if it is queried
for information it doesn't contain.
For example, could I add Home Address to a userProxy object in an ADAM
instance, then configure AD to redirect any queries for Home Address to that
particular ADAM instance? If not, then what is the difference between an
ADAM user and an ADAM userProxy object and what is the application of an ADAM
userProxy object?
Sorry for the lengthy post, but I have googled these things but not come up
with much. So I'd really apprecaite any help anybody can give me.
Thanks in advance
Bookmarks