Solved

TomCat Service cannot authenticate from DMZ to AD to start TomCat Service 2008R2

Posted on 2014-02-06
4
285 Views
Last Modified: 2014-02-15
Hi Folks,

Have a Winodws 2008R2 box in the DMZ we run Tomcat on it and it starts its service with AD Account Credentials.

What ports do I need to make this happen:

DMZ >>> INTERNAL LAN

LAN >>> DMZ
0
Comment
Question by:999
  • 3
4 Comments
 
LVL 11

Expert Comment

by:Manjunath Sullad
ID: 39841345
Check the connectivity to Active Directory, Telnet to DC with port number 389.

telnet Servername 389, If its working fine, There is no problem with LDAP service.

Also cross verify with Server Admin who is maintaining AD,
0
 

Author Comment

by:999
ID: 39841349
Need more than LDAP, Kerberos RCP secure channel setup and password exchanges after timeouts.

I am getting closer so will post when I nail it.
0
 

Accepted Solution

by:
999 earned 0 total points
ID: 39849353
I sorted guys DNS, LDAP(U) KERBEROD and RCP(135) from DMZ to INT
0
 

Author Closing Comment

by:999
ID: 39861177
I spent an entire weekend on this trial and error reducing the number of ports required just to allow a service to authenticate with AD.
0

Featured Post

Do You Know the 4 Main Threat Actor Types?

Do you know the main threat actor types? Most attackers fall into one of four categories, each with their own favored tactics, techniques, and procedures.

Join & Write a Comment

Suggested Solutions

Title # Comments Views Activity
Problem with .htaccess file 4 57
wordpress email form 23 68
instanceof  operator in java 26 73
Has my website been infiltrated? 21 58
It is possible to boost certain documents at query time in Solr. Query time boosting can be a powerful resource for finding the most relevant and "best" content. Of course the more information you index, the more fields you will be able to use for y…
If you don't have the right permissions set for your WordPress location in IIS, you won't be able to perform automatic updates. Here's how to fix the problem.
In this video, we discuss why the need for additional vertical screen space has become more important in recent years, namely, due to the transition in the marketplace of 4x3 computer screens to 16x9 and 16x10 screens (so-called widescreen format). …
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…

746 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

9 Experts available now in Live!

Get 1:1 Help Now