?
Solved

IIS change password multiple domains

Posted on 2010-09-14
6
Medium Priority
?
922 Views
Last Modified: 2012-05-10
Im running win2003 IIS. I have setup the change password feature for OWA, intranet etc. I recently added an additional domain to my forest. The change password feature is not working for the users in the new domain. Any ideas?
0
Comment
Question by:KratosDefense
  • 3
  • 3
6 Comments
 
LVL 24

Expert Comment

by:Radhakrishnan R
ID: 33674278
ok..You created addtional domain controller for this domain or one more domain for existing forest?
I guess its additional domain - So u have to create a trust between these 2 domain, also you have to enable the GC role for this server, then wait for rplication happenes or do gpupdate \force for force update.
0
 

Author Comment

by:KratosDefense
ID: 33674333
Already done all of that (trust, GC etc.) Domain has been in place for a month already.
0
 
LVL 24

Expert Comment

by:Radhakrishnan R
ID: 33674531
0
Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 

Author Comment

by:KratosDefense
ID: 33675883
Nope didn't fix. I have the IISADMPWD setup and working properly. I believe the problem is in the achg.asp page. here is a snippet from it:

<%end if%>
<%
      On Error resume next
      dim domain, posbs, posat, username, pUser, root
      dim upn_name

      upn_name = ""

      domain = Trim(Request.Form("domain"))
      ' if no domain is present we try to get the domain from the username,
      ' e.g. domainusername or praesi@ultraschallpiloten.com
      
      if domain = "" then
            posbs = Instr(1,Request.Form("acct"),"\" )
            posat = Instr(1,Request.Form("acct"),"@" )
            if posbs > 0 then
                  domain = Left(Request.Form("acct"),posbs-1)
                  username = Right(Request.Form("acct"),len(Request.Form("acct")) - posbs)
            elseif posat > 0 then
                  upn_name = Request.Form("acct")
                  domain = Right(upn_name, len(upn_name) - posat)
                  username = Left(upn_name, posat-1)
            else      
                  username = Request.Form("acct")
                  set nw = Server.CreateObject("WScript.Network")
                  domain = "WFINET"
                  ' domain = nw.Computername
            end if

Note the domain WFINET, thats the domain it works for, I need it to look at an additional domain if the user account doesnt exist in the wfinet domain. Any idea what the asp coding would be that I need to add?
0
 
LVL 24

Accepted Solution

by:
Radhakrishnan R earned 2000 total points
ID: 33679629
You can try this script, I am not sure whether it will resolve you issue but you can try once
The existing script has some logic to deal with a UPN if the domain is not present, the problem is that the users upn is not the same as the domain so it fails.  To get around the problem you can replace the code that looks like this:

set pUser = Server.CreateObject("IIS.PwdChg")

if Not IsObject(pUser) then

       set pUser = GetObject("WinNT://" & domain & "/" & username & ",user")

       if Not IsObject(pUser) then

              set root = GetObject("WinNT:")

              set pUser = root.OpenDSObject("WinNT://" & domain & "/" & username & ",user", username, Request.Form("old"),1)

              Response.Write "<!--OpenDSObject call-->"

       end if

else

       pUser.Domain = domain

       pUser.User = username

       pUser.UPN = upn_name

end if

 

With

 

Set PUser = Createobject("ADSystemInfo")

Set  Root = GetObject("LDAP:")

Set Puser = Root.OpenDSObject("LDAP://" & pUser.Username, Request.Form("Acct"), Request.Form("old"),1)

 

To ensure that it works correctly the domain field has to be empty and the account should be entered as the e-mail address.  I would recommend that you change the page to reset the domain field to “” and to ensure the username has an @ in it.  Otherwise this will work.

Also have a look at this MS article about password change problem
http://support.microsoft.com/?id=894825

Good Luck}
0
 

Author Closing Comment

by:KratosDefense
ID: 33803485
thxs
0

Featured Post

Get expert help—faster!

Need expert help—fast? Use the Help Bell for personalized assistance getting answers to your important questions.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Introduction This article explores the design of a cache system that can improve the performance of a web site or web application.  The assumption is that the web site has many more “read” operations than “write” operations (this is commonly the ca…
What You Need to Know when Searching for a Webhost Provider
Integration Management Part 2
How can you see what you are working on when you want to see it while you to save a copy? Add a "Save As" icon to the Quick Access Toolbar, or QAT. That way, when you save a copy of a query, form, report, or other object you are modifying, you…
Suggested Courses

621 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question