Solved

LDAP Query for account properties over a trust

Posted on 2011-03-03
1
701 Views
Last Modified: 2012-06-21
I have two domains domain1.corp.com and domain2.corp.com that share a trust relationship. I have a third party network access control system that periodically sniffs kerberos traffic to obtain user credentials and spot check/implement access rules on the connection. This tool does no authentication in and of itself, it merely passively sniffs traffic. It is only capable of defining a single LDAP source for its lookups.

I would like to query for account properties on domain2 via an LDAP query against domain1. Specifically, we interrogate the memberOf properties to look for specific network access groups. Is this possible without some sort of LDAP front end?
0
Comment
Question by:WMorgen
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
1 Comment
 
LVL 10

Accepted Solution

by:
abbright earned 500 total points
ID: 35031240
You may want to try to query the global catalog which holds information from several trusting domains. Maybe the following helps: http://technet.microsoft.com/en-us/library/cc978012.aspx
0

Featured Post

Windows running painfully slow? Try these tips..

Stay away from Speed Up Computer Programs that do more harm than good.
Try these tips instead.
Step by step instructions in trouble shooting Windows Performance issues.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

If you are looking at this article, you have most likely been hit by some version of ransomware and are trying to find out if there is anything you can do, or what way you should react - READ ON!
Many old projects have bad code, but the budget doesn't exist to rewrite the codebase. You can update this code to be safer by introducing contemporary input validation, sanitation, and safer database queries.
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…

739 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question