siuko Posted June 25, 2009 Posted June 25, 2009 I have started implementing LDAP access for some of our websites so that the staff can use their network usernames and password (rather than having to remember another one). The problem I am facing is that we have 2 domains (curriculum and admin - yeah I know I could setup as one with better permissions ) and the LDAP authenticates against the main curriculum domain where most of the staff have accounts. Both domains are windows 2000. Is there any way to somehow replicate the staff accounts from the admin domain to the curriculum domain so they can use their usernames and passwords but that dont have any other rights to actually log onto the curriculum domain?
jamesb Posted June 25, 2009 Posted June 25, 2009 Trusts. Understanding domain trusts These seem to be coming up a lot lately. It'll allow the users to be authenticated in the trusted domain (assuming you set up a one-way trust) and you can just remove their right to log on interactively to any computers in that domain via GPO, or simply not provide them any permissions other than to authenticate.
siuko Posted June 25, 2009 Author Posted June 25, 2009 I have a vague feeling that trusts are already setup between the 2 domains. We have it so users can be given permissions on shares between the 2 domains easily. I'm feeling a little noobish but could you possibly point me in the direction of how I have their accounts trusted for auth only?
jamesb Posted June 25, 2009 Posted June 25, 2009 I should point out that I don't use Windows 2k, so can't be completely sure that this would be the right route. Basically though you should be able to create a group with membership assigned to all of the users from the admin domain, then allow it Network Authentication permission, but deny Interactive Logon to all machines. This'll allow them to authenticate, but not actually log on to any computers. The permission you need is under Computer Configuration | Windows Settings | Security Settings | Local Policies | User Rights Assignment | Deny log on locally. Add the group you've created to hold the users and apply it at the appropriate point for any machines in the network where you want them unable to log on. You can lock down various other permissions as well. Active Directory Users, Computers, and Groups - goes into a bit more detail on interactive logon and network authentication.
siuko Posted June 25, 2009 Author Posted June 25, 2009 I have just checked the domains and there is a 2 way trust between them. I am at a complete loss now as to how I can allow the ldap process on Request Tracker and MRBS to ask for authentication through the curriculum server that they point to - to the other trusted domain.
jamesb Posted June 25, 2009 Posted June 25, 2009 If the users from the admin domain are visible in the curriculum domain, and can authenticate there, then it should be automatic from that point on. The sites will go to the curriculum DC to authenticate credentials, the curriculum DC will recognise that its not credentials for accounts in its own domain and fire the requests off to the trusted admin DC, that'll come back saying that the users do exist and are valid, and that should be it. I think so anyway.
siuko Posted June 25, 2009 Author Posted June 25, 2009 The users from the admin domain arent visible in the curriculum domain. Thats the step I think I am lost at.
jamesb Posted June 25, 2009 Posted June 25, 2009 Right, we're getting somewhere then. Create a domain local group and go to add members to it, you should find that you're able to add members from the foreign domain. Failing that, on the foreign domain create a universal security group and you should be able to surface that in the curriculum domain.
Michael Posted June 25, 2009 Posted June 25, 2009 I'm not so sure that a domain trust would have any impact. Users still authenticate against their own server, but for example, can access shares held on another domain, hence the need for a trust. I presume both servers are Global Catalog servers, as this holds information on objects in its own domain and any other domain associated with it. In saying that, I can imagine this is going to get very difficult to achieve. Longterm properly merging the domains would give you the true single sign on you want to achieve.
jamesb Posted June 25, 2009 Posted June 25, 2009 I'm not so sure that a domain trust would have any impact. Users still authenticate against their own server, but for example, can access shares held on another domain, hence the need for a trust. I presume both servers are Global Catalog servers, as this holds information on objects in its own domain and any other domain associated with it. In saying that, I can imagine this is going to get very difficult to achieve. Longterm properly merging the domains would give you the true single sign on you want to achieve. True, but the computers will be sending a request to their own DC for authentication - if that DC doesn't have permissions for those users to authenticate in its domain then it won't forward the authentication request.
Michael Posted June 25, 2009 Posted June 25, 2009 True, but the computers will be sending a request to their own DC for authentication - if that DC doesn't have permissions for those users to authenticate in its domain then it won't forward the authentication request. Yes I agree with you there. Unless LDAP can be modified to look at two domains (possible in theory), maybe the only other way would be to create a secondary logon page for these users which authenticate against the second server. Longterm, a single manageable domain would make things easier longterm. Having two domains would require two instances of AV and WSUS for example.
siuko Posted June 25, 2009 Author Posted June 25, 2009 Still playing about with the Local groups on the curriculum domain. With the AV and WSUS it works fine via both domains
jamesb Posted June 25, 2009 Posted June 25, 2009 Thinking about it, there's no need to modify LDAP to look at two domains. Why are the users not simply using their full domain\username, or username@domain to log on? With DNS set up, and the permissions configured, that should sort it.
siuko Posted June 25, 2009 Author Posted June 25, 2009 I tried with the usernames in the format you mentioned and it doesnt seem to work. Do I need to have transitory trust between the 2 domains? From what I read about it I dont think I should - but thought I would ask. I also tried creating the local domain group on the curriculum domain and adding the admin users to it. This does not seem to have worked either. Does it require a server restart or anything? PS. I have a feeling that becuase the ldap requires a specific base domain to read from it wont just switch between the curriculum and admin domains with the [email protected] or [email protected] usernames.
binky Posted June 25, 2009 Posted June 25, 2009 Have you tried using Identity Integration Server to sync the users?
siuko Posted June 25, 2009 Author Posted June 25, 2009 Never heard of it! I shall google it now! Thanks to everyone for all the suggestions - hopefully i will get it working soon
jamesb Posted June 25, 2009 Posted June 25, 2009 Is there any option in the LDAP setup to query the GC? I'm basing this on Sharepoint access, but its only just occurred to me that Sharepoint may do something clever in terms of checking domains. The only thing I can think of which I did have to do was to give the service account running Sharepoint permission to read the second domain. I take it you've got a service account running the websites?
siuko Posted June 25, 2009 Author Posted June 25, 2009 The websites run on linux so the accounts dont quite match up. I have the server joined to the curriculum domain with samba but I think its mainly the issue with the fact that I have to specify only one ldap server. So I either have to: Allow the users to be seen through the ldap server I specify (which is what I am trying to do now) or Some how configure the websites for multiple domains (I dont beleive I can do this with one website) but if I create a second website configured for the admin domain that would work. The problem there is then I have the issue of letting staff know about the 2 website and also I would want both websites even though configured for seperate ldaps to be able to write their data to one mysql database! Which could be fun
siuko Posted June 25, 2009 Author Posted June 25, 2009 Hehe yeah it seems to look that way at the moment
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now