Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

IIS change password multiple domains

Posted on 2010-09-14
6
Medium Priority
?
915 Views
Last Modified: 2012-05-10
Im running win2003 IIS. I have setup the change password feature for OWA, intranet etc. I recently added an additional domain to my forest. The change password feature is not working for the users in the new domain. Any ideas?
0
Comment
Question by:KratosDefense
  • 3
  • 3
6 Comments
 
LVL 23

Expert Comment

by:Radhakrishnan R
ID: 33674278
ok..You created addtional domain controller for this domain or one more domain for existing forest?
I guess its additional domain - So u have to create a trust between these 2 domain, also you have to enable the GC role for this server, then wait for rplication happenes or do gpupdate \force for force update.
0
 

Author Comment

by:KratosDefense
ID: 33674333
Already done all of that (trust, GC etc.) Domain has been in place for a month already.
0
 
LVL 23

Expert Comment

by:Radhakrishnan R
ID: 33674531
0
Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 

Author Comment

by:KratosDefense
ID: 33675883
Nope didn't fix. I have the IISADMPWD setup and working properly. I believe the problem is in the achg.asp page. here is a snippet from it:

<%end if%>
<%
      On Error resume next
      dim domain, posbs, posat, username, pUser, root
      dim upn_name

      upn_name = ""

      domain = Trim(Request.Form("domain"))
      ' if no domain is present we try to get the domain from the username,
      ' e.g. domainusername or praesi@ultraschallpiloten.com
      
      if domain = "" then
            posbs = Instr(1,Request.Form("acct"),"\" )
            posat = Instr(1,Request.Form("acct"),"@" )
            if posbs > 0 then
                  domain = Left(Request.Form("acct"),posbs-1)
                  username = Right(Request.Form("acct"),len(Request.Form("acct")) - posbs)
            elseif posat > 0 then
                  upn_name = Request.Form("acct")
                  domain = Right(upn_name, len(upn_name) - posat)
                  username = Left(upn_name, posat-1)
            else      
                  username = Request.Form("acct")
                  set nw = Server.CreateObject("WScript.Network")
                  domain = "WFINET"
                  ' domain = nw.Computername
            end if

Note the domain WFINET, thats the domain it works for, I need it to look at an additional domain if the user account doesnt exist in the wfinet domain. Any idea what the asp coding would be that I need to add?
0
 
LVL 23

Accepted Solution

by:
Radhakrishnan R earned 2000 total points
ID: 33679629
You can try this script, I am not sure whether it will resolve you issue but you can try once
The existing script has some logic to deal with a UPN if the domain is not present, the problem is that the users upn is not the same as the domain so it fails.  To get around the problem you can replace the code that looks like this:

set pUser = Server.CreateObject("IIS.PwdChg")

if Not IsObject(pUser) then

       set pUser = GetObject("WinNT://" & domain & "/" & username & ",user")

       if Not IsObject(pUser) then

              set root = GetObject("WinNT:")

              set pUser = root.OpenDSObject("WinNT://" & domain & "/" & username & ",user", username, Request.Form("old"),1)

              Response.Write "<!--OpenDSObject call-->"

       end if

else

       pUser.Domain = domain

       pUser.User = username

       pUser.UPN = upn_name

end if

 

With

 

Set PUser = Createobject("ADSystemInfo")

Set  Root = GetObject("LDAP:")

Set Puser = Root.OpenDSObject("LDAP://" & pUser.Username, Request.Form("Acct"), Request.Form("old"),1)

 

To ensure that it works correctly the domain field has to be empty and the account should be entered as the e-mail address.  I would recommend that you change the page to reset the domain field to “” and to ensure the username has an @ in it.  Otherwise this will work.

Also have a look at this MS article about password change problem
http://support.microsoft.com/?id=894825

Good Luck}
0
 

Author Closing Comment

by:KratosDefense
ID: 33803485
thxs
0

Featured Post

Veeam Task Manager for Hyper-V

Task Manager for Hyper-V provides critical information that allows you to monitor Hyper-V performance by displaying real-time views of CPU and memory at the individual VM-level, so you can quickly identify which VMs are using host resources.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

If you are a web developer, you would be aware of the <iframe> tag in HTML. The <iframe> stands for inline frame and is used to embed another document within the current HTML document. The embedded document could be even another website.
A phishing scam that claims a recipient’s credit card details have been “suspended” is the latest trend in spoof emails.
Please read the paragraph below before following the instructions in the video — there are important caveats in the paragraph that I did not mention in the video. If your PaperPort 12 or PaperPort 14 is failing to start, or crashing, or hanging, …
In a question here at Experts Exchange (https://www.experts-exchange.com/questions/29062564/Adobe-acrobat-reader-DC.html), a member asked how to create a signature in Adobe Acrobat Reader DC (the free Reader product, not the paid, full Acrobat produ…
Suggested Courses

885 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question