Solved

Application needs to lookup Active Directory info

Posted on 2010-11-13
3
396 Views
Last Modified: 2012-08-13
Hi

We are running AD 2003. We have multiple domains within the same forest - emea.kam.com and apac.kam.com, forest root kam.com

We have an application that will need to query AD to lookup attributes of users, their group membership and other info.

What port does the app need to query the DC on - 386 (LDAP) or 3268 (GC)?
0
Comment
Question by:kam_uk
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 57

Accepted Solution

by:
Mike Kline earned 250 total points
ID: 34128412
It depends on what type of groups and what the other info is.  Look at the last section here   http://technet.microsoft.com/en-us/library/cc978012.aspx

The GC only holds a partial set of attributes so while a GC in emea knows about every object it doesn't contain every attribute for every object.

Thanks

Mike
0
 
LVL 24

Assisted Solution

by:Awinish
Awinish earned 250 total points
ID: 34130724
Could you reveal the name of application,you are going to use in AD for performing ldap query.

The general attribute can be queried by most of the application using GC but if you want specific attribute, you require some set of programming/scripting to achieve that.

http://msdn.microsoft.com/en-us/library/ms675085%28VS.85%29.aspx

You will surely require 389 for ldap server & for secure 636(LDAP SSL)

Same for GC 3268 & 3269 for SSL.

It might require 53 for DNS server lookup.
 

0
 
LVL 24

Expert Comment

by:Awinish
ID: 34130730
Check the below article its for windows 2000 but you will get an idea.

http://support.microsoft.com/kb/256938
0

Featured Post

On Demand Webinar: Networking for the Cloud Era

Ready to improve network connectivity? Watch this webinar to learn how SD-WANs and a one-click instant connect tool can boost provisions, deployment, and management of your cloud connection.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Had a business requirement to store the mobile number in an environmental variable. This is just a quick article on how this was done.
Let's recap what we learned from yesterday's Skyport Systems webinar.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …

623 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question