Solved

Application needs to lookup Active Directory info

Posted on 2010-11-13
3
365 Views
Last Modified: 2012-08-13
Hi

We are running AD 2003. We have multiple domains within the same forest - emea.kam.com and apac.kam.com, forest root kam.com

We have an application that will need to query AD to lookup attributes of users, their group membership and other info.

What port does the app need to query the DC on - 386 (LDAP) or 3268 (GC)?
0
Comment
Question by:kam_uk
  • 2
3 Comments
 
LVL 57

Accepted Solution

by:
Mike Kline earned 250 total points
ID: 34128412
It depends on what type of groups and what the other info is.  Look at the last section here   http://technet.microsoft.com/en-us/library/cc978012.aspx

The GC only holds a partial set of attributes so while a GC in emea knows about every object it doesn't contain every attribute for every object.

Thanks

Mike
0
 
LVL 24

Assisted Solution

by:Awinish
Awinish earned 250 total points
ID: 34130724
Could you reveal the name of application,you are going to use in AD for performing ldap query.

The general attribute can be queried by most of the application using GC but if you want specific attribute, you require some set of programming/scripting to achieve that.

http://msdn.microsoft.com/en-us/library/ms675085%28VS.85%29.aspx

You will surely require 389 for ldap server & for secure 636(LDAP SSL)

Same for GC 3268 & 3269 for SSL.

It might require 53 for DNS server lookup.
 

0
 
LVL 24

Expert Comment

by:Awinish
ID: 34130730
Check the below article its for windows 2000 but you will get an idea.

http://support.microsoft.com/kb/256938
0

Featured Post

Comprehensive Backup Solutions for Microsoft

Acronis protects the complete Microsoft technology stack: Windows Server, Windows PC, laptop and Surface data; Microsoft business applications; Microsoft Hyper-V; Azure VMs; Microsoft Windows Server 2016; Microsoft Exchange 2016 and SQL Server 2016.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Setting up a Microsoft WSUS update system is free relatively speaking if you have hard disk space and processor capacity.   However, WSUS can be a blessing and a curse. For example, there is nothing worse than approving updates and they just have…
A quick step-by-step overview of installing and configuring Carbonite Server Backup.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

920 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

17 Experts available now in Live!

Get 1:1 Help Now