Solved

IIS change password multiple domains

Posted on 2010-09-14
6
889 Views
Last Modified: 2012-05-10
Im running win2003 IIS. I have setup the change password feature for OWA, intranet etc. I recently added an additional domain to my forest. The change password feature is not working for the users in the new domain. Any ideas?
0
Comment
Question by:KratosDefense
  • 3
  • 3
6 Comments
 
LVL 21

Expert Comment

by:RK
ID: 33674278
ok..You created addtional domain controller for this domain or one more domain for existing forest?
I guess its additional domain - So u have to create a trust between these 2 domain, also you have to enable the GC role for this server, then wait for rplication happenes or do gpupdate \force for force update.
0
 

Author Comment

by:KratosDefense
ID: 33674333
Already done all of that (trust, GC etc.) Domain has been in place for a month already.
0
 
LVL 21

Expert Comment

by:RK
ID: 33674531
0
What is SQL Server and how does it work?

The purpose of this paper is to provide you background on SQL Server. It’s your self-study guide for learning fundamentals. It includes both the history of SQL and its technical basics. Concepts and definitions will form the solid foundation of your future DBA expertise.

 

Author Comment

by:KratosDefense
ID: 33675883
Nope didn't fix. I have the IISADMPWD setup and working properly. I believe the problem is in the achg.asp page. here is a snippet from it:

<%end if%>
<%
      On Error resume next
      dim domain, posbs, posat, username, pUser, root
      dim upn_name

      upn_name = ""

      domain = Trim(Request.Form("domain"))
      ' if no domain is present we try to get the domain from the username,
      ' e.g. domainusername or praesi@ultraschallpiloten.com
      
      if domain = "" then
            posbs = Instr(1,Request.Form("acct"),"\" )
            posat = Instr(1,Request.Form("acct"),"@" )
            if posbs > 0 then
                  domain = Left(Request.Form("acct"),posbs-1)
                  username = Right(Request.Form("acct"),len(Request.Form("acct")) - posbs)
            elseif posat > 0 then
                  upn_name = Request.Form("acct")
                  domain = Right(upn_name, len(upn_name) - posat)
                  username = Left(upn_name, posat-1)
            else      
                  username = Request.Form("acct")
                  set nw = Server.CreateObject("WScript.Network")
                  domain = "WFINET"
                  ' domain = nw.Computername
            end if

Note the domain WFINET, thats the domain it works for, I need it to look at an additional domain if the user account doesnt exist in the wfinet domain. Any idea what the asp coding would be that I need to add?
0
 
LVL 21

Accepted Solution

by:
RK earned 500 total points
ID: 33679629
You can try this script, I am not sure whether it will resolve you issue but you can try once
The existing script has some logic to deal with a UPN if the domain is not present, the problem is that the users upn is not the same as the domain so it fails.  To get around the problem you can replace the code that looks like this:

set pUser = Server.CreateObject("IIS.PwdChg")

if Not IsObject(pUser) then

       set pUser = GetObject("WinNT://" & domain & "/" & username & ",user")

       if Not IsObject(pUser) then

              set root = GetObject("WinNT:")

              set pUser = root.OpenDSObject("WinNT://" & domain & "/" & username & ",user", username, Request.Form("old"),1)

              Response.Write "<!--OpenDSObject call-->"

       end if

else

       pUser.Domain = domain

       pUser.User = username

       pUser.UPN = upn_name

end if

 

With

 

Set PUser = Createobject("ADSystemInfo")

Set  Root = GetObject("LDAP:")

Set Puser = Root.OpenDSObject("LDAP://" & pUser.Username, Request.Form("Acct"), Request.Form("old"),1)

 

To ensure that it works correctly the domain field has to be empty and the account should be entered as the e-mail address.  I would recommend that you change the page to reset the domain field to “” and to ensure the username has an @ in it.  Otherwise this will work.

Also have a look at this MS article about password change problem
http://support.microsoft.com/?id=894825

Good Luck}
0
 

Author Closing Comment

by:KratosDefense
ID: 33803485
thxs
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Debug Tools to analyse IIS process: This article focus on taking memory dumps from IIS to determine which code is taking more time and to analyse which calls hangs/causes more CPU usage. To take dumps,download the following. Install1: To st…
Article by: kevp75
Hey folks, 'bout time for me to come around with a little tip. Thanks to IIS 7.5 Extensions and Microsoft (well... really Windows 8, and IIS 8 I guess...), we can now prime our Application Pools, when IIS starts. Now, though it would be nice t…
This video shows how to quickly and easily add an email signature for all users on Exchange 2016. The resulting signature is applied on a server level by Exchange Online. The email signature template has been downloaded from: www.mail-signatures…
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …

803 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question