Solved

Application needs to lookup Active Directory info

Posted on 2010-11-13
3
382 Views
Last Modified: 2012-08-13
Hi

We are running AD 2003. We have multiple domains within the same forest - emea.kam.com and apac.kam.com, forest root kam.com

We have an application that will need to query AD to lookup attributes of users, their group membership and other info.

What port does the app need to query the DC on - 386 (LDAP) or 3268 (GC)?
0
Comment
Question by:kam_uk
  • 2
3 Comments
 
LVL 57

Accepted Solution

by:
Mike Kline earned 250 total points
ID: 34128412
It depends on what type of groups and what the other info is.  Look at the last section here   http://technet.microsoft.com/en-us/library/cc978012.aspx

The GC only holds a partial set of attributes so while a GC in emea knows about every object it doesn't contain every attribute for every object.

Thanks

Mike
0
 
LVL 24

Assisted Solution

by:Awinish
Awinish earned 250 total points
ID: 34130724
Could you reveal the name of application,you are going to use in AD for performing ldap query.

The general attribute can be queried by most of the application using GC but if you want specific attribute, you require some set of programming/scripting to achieve that.

http://msdn.microsoft.com/en-us/library/ms675085%28VS.85%29.aspx

You will surely require 389 for ldap server & for secure 636(LDAP SSL)

Same for GC 3268 & 3269 for SSL.

It might require 53 for DNS server lookup.
 

0
 
LVL 24

Expert Comment

by:Awinish
ID: 34130730
Check the below article its for windows 2000 but you will get an idea.

http://support.microsoft.com/kb/256938
0

Featured Post

Efficient way to get backups off site to Azure

This user guide provides instructions on how to deploy and configure both a StoneFly Scale Out NAS Enterprise Cloud Drive virtual machine and Veeam Cloud Connect in the Microsoft Azure Cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Synchronize a new Active Directory domain with an existing Office 365 tenant
In this article, I am going to show you how to simulate a multi-site Lab environment on a single Hyper-V host. I use this method successfully in my own lab to simulate three fully routed global AD Sites on a Windows 10 Hyper-V host.
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.

792 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question