Custom search policies: remote authentication, local user data?

I'm feeling optimistic this morning, but I fully expect the answer to this question to be no.
I've just read "Open Directory Administration", in particular the part about custom search policies. What I would like is an Open Directory server that uses another LDAP server for authentication but local information for administrative information such as UID, GID, name, home directory location. Is this possible?
I can think of some security problems that could be caused if it was possible, but I had to ask - it would make my life much easier.
I realise that the sensible answer is to put the administrative information on the LDAP server. For a variety of reasons too stupid to recount here, this would be a bit of a headache. It's also probably impossible to setup Kerberos on the LDAP server.
XServe Mac OS X (10.4.6) Horribly mixed environment: OS X, SuSE, old IRIX, Windows XP

its the service which is using the account info and authenticating against the DC to obtain service ticket and fails
Interesting log section is NULL SID which doesn't corresponds to any account name.
Security ID:        NULL SID
    Account Name:        -
    Account Domain:        -
    Logon ID:        0x0
and the below section explains , the request is made over network, which is most of the times by the service
Detailed Authentication Information:
    Logon Process:        NtLmSsp
    Authentication Package:    NTLM
    Transited Services:    -
    Package Name (NTLM only):    -
    Key Length:        0
The below is assumed to be performed on a client which does not run mission critical production applications which has zero impact when you perform the below actions,
can you disable
a) Server service
b) Workstation service
c) Disable RPC dependent service and services which depend on RPC and test
Question:
What is the level of DC hardening you have in your environment ?

Similar Messages

  • How to set a customized search results template for all users

    Hi.
    I know the customized search results views are stored in a file called pne_portal.hda that resides on every user's subfolder in data/users/profiles/...
    Is there a way to set a customized search results template for all users? If it's impossible, is there a way to modify the Headline view? I'm not able to find the resource or template where this view is.
    Thanks in advance.

    I wasn't able to understand what was meant by this post. Therefore, I modified the standard template HeadLine View.
    Columns for this template are defined in the include slim_search_result_table_header_setup (in std_page.htm).
    Here is the modification of the code:
    <$if customTemplateId and not (baseTemplateId like customTemplateId)$>
              <$columnsString = utGetValue("customlisttemplates/" & strLower(customTemplateId), "columns")$>          
              <!-- Modify START by Oracle-->
         <$else$>
    <!-- here add default fields -->
              <$columnsString="dDocName,dDocTitle,dInDate,dDocAuthor"$>
    <!-- here add your custom fields -->
              <$columnsString=columnsString&",xComment"$>
              <!-- Modify END by Oracle-->
         <$endif$>

  • Lumia 520 "Remote wipe of user data via Internet"

    I'm interested in purchasing a Lumia 520 and read on the spec site that it can do "Remote wipe of user data via Internet" (http://www.nokia.com/in-en/phones/phone/lumia-520/specifications/).
    Is there any special software that I need to be able to do this (like have it connected to a BlackBerry server in the case of enterprise BlackBerry devices) or is it as simple as stated on (http://www.noknok.tv/2013/05/02/how-to-find-your-lost-nokia-lumia-running-windows-phone-8/) where all you have to do is log into windowsphone.com where you can erase a linked phone?
    This phone will be used for business so in case it is lost I need the ability te remote wipe it. Our company currently has a BB server and we all have BB devices, but with BB not doing so well I was thinking of getting a Nokia.
    Thanks.
    Solved!
    Go to Solution.

    WHNOKLUM520 wrote:
    So far so good. That's great news. If I could ask one follow up question though:
    Would it matter if the same SIM is installed on the phone? Lets say the 'thief' was able to get into the phone with a different SIM (if the security was not setup correctly) - would the phone be erased based on the SIM that's installed or on the IMEI number of the device?
    Thanks
    If there's no data connection, windowsphone.com cannot access your phone to send push notifications and if push notifications fail, then it will try to send SMS to your phone.
    I just tried to ring my phone after taking out the SIM card, it was connected to wi-fi and I could ring it.
    The silence will fall

  • What happens to my local user data? -newbie question sorry

    Hi All,
    Firstly apologies if this seems a dumb question, I've scoured the forums but I require something that fits my specific situation.
    I've had a (my first) MacBook for about 9 months, built up a fairly healthy local user, setup just how I like it, MobileMe, iTunes, Chrome, iPhoto library, lots of other apps, etc etc and so forth.
    I'm setting up a Mac Mini Server, and was wondering what I can do to join the new server, but take all my settings/downloads/iTunes etc with me... I don't want it all stored on the server, but I come from a Micro$oft Windows background. With MS, when you add a PC to a domain, login with the appropriate user account, you have a fresh profile, no settings, no files, no customisations etc etc is this also the case when I hit that Join Network Account server button on my Mac? Will I get a blank fresh account on my Macbook?
    I'm guessing this must happen quite often as people start their way into Apple technology and build up a nice healthy local account before branching further into the Apple world...

    The two laptops I use everyday have access to all the servers via my network account. It is set so that my user account is listed as having "no home" So I log into the laptop with my local user account with a UID of 501 but access all the network services via the go menu and my network account of the same name but with a UID of 1034.
    For all other users in the company, if they are on a laptop, I use network accounts. The machines are managed to ask if the user wants to create a mobile account when they login. For permanently assigned laptop users, the answer is yes. This puts their home on the laptop and ties them to that machine. I use mobile account syncing to make sure their critical data is copied to the server for backup.
    By having the machine ask to create the mobile account, users can answer no and login to their network home. The use of the laptop may be needed temporarily if a regular workstation is down.
    Once in a while I will need to convert a local account to a network account. While a bit more laborious that setting it up correctly at the beginning, it can be done.
    But I never let any user account have the UID of 501. I would set that up as the local admin account I use for installing updates and performing other maintenance. If needed, I would back up the user data and erase and re-install the OS.

  • Copy Local User Data from Multiple Computers to a File Server

    Just recently acquired a new company with 20 standalone computers (desktops and laptops, Windows 7 and 8.1), that are part of a WORKGROUP, with no local server at all. This site will be getting a network upgrade, and will soon have a VPN tunnel to the Main
    Office (but not until cutover weekend, a month and a half in the future).  Now, all these computers have local user accounts, and some are shared computers, so copying data to a centralized location is going to be bothersome (especially if people keep
    modifying/creating data everyday).  Not sure what to do...
    Would anyone advise on what to do in this case?   I'd like to minimize downtime for these users while migrating them to our domain. 

    Hello Fernando Chanco,
    I can recommend you to use the User Migration State Tool as this provides a highly customizable user-profile migration experience for IT professionals.
    User State Migration Tool (USMT) Technical Reference
    https://technet.microsoft.com/en-us/library/hh825256.aspx
    USMT Requirements
    https://technet.microsoft.com/en-us/library/hh824913.aspx
    Also this is an interesting document that points to this same tool (USMT) to accomplish something similar to your goal.
    How to migrate from Workgroup network model to Domain based model?
    https://support.microsoft.com/kb/555542/en-us
    Q: 
    How to migrate from Workgroup network model to Domain based model?
    A: 
    Network base Workgroup support a few hosts without central management. 
    After you company/network grow, you will have to start to migrate to network base on Domain model.
    The followings instructions will give you a guidelines to achieve this migration in the short and safe way. The guidelines assume that you migrate single place and serve SMB (Small Medium Business) network...
    Hope this info helps to reach your goal. :D
    5ALU2 !

  • How can set a customized search results template and all users see it

    Hi all ,,,,
    I Added new costume template search result
    And when I added this template it’s added only for the user how created this template ,And I need all users see and use this template can anyone tell how I can add template for search result and all users see it or if I can do synchronies for this template.

    I wasn't able to understand what was meant by this post. Therefore, I modified the standard template HeadLine View.
    Columns for this template are defined in the include slim_search_result_table_header_setup (in std_page.htm).
    Here is the modification of the code:
    <$if customTemplateId and not (baseTemplateId like customTemplateId)$>
              <$columnsString = utGetValue("customlisttemplates/" & strLower(customTemplateId), "columns")$>          
              <!-- Modify START by Oracle-->
         <$else$>
    <!-- here add default fields -->
              <$columnsString="dDocName,dDocTitle,dInDate,dDocAuthor"$>
    <!-- here add your custom fields -->
              <$columnsString=columnsString&",xComment"$>
              <!-- Modify END by Oracle-->
         <$endif$>

  • Custom Search help in Record Working Time

    Hi,
    We have a requirement to add a custom field on RECORD Working Time ( ESS). This field has been added and custom search help is assigned to the data element of the field. The values in the F4 help should vary based on employees department.
    The related code for this requirement is written in the serach help exit. The F4 help is working as expected from backend ( ECC) but not in Portal (ESS).
    I have added the custom field in TCATS_SHLP_ITS. After maintaining this table all the values in F4 help are displaying , whereas it should only display the values under employees department in Record Working time.
    I understand the class cl_xss_cat_value_help_general is responsible for the search help in ESS is there any user exit or enhancement available for this class in order to control the serach values on ESS.
    Thanks in advance.
    regards,
    Pradeep

    note that search help of CAT2 and record working time are different!
    these are teh steps
    please modify the following in the table TCATS_SHLP_ITS as follows:
              1. Execute the T-Code SM31
              2. Enter the table name TCATS_SHLP_ITS.
    or check the class
    CL_XSS_CAT_VALUE_HELP_GENERAL
    or check
    CL_XSS_CAT_VALUE_HELP*
    take an example from Sap note 914125

  • Appending custom search help

    Hi,
    I have appended a custom search help to std collective search help C_SAKNR, which is assigned to data element SAKNR. The reason to append custom search help is when the user presses F4 on G/L account field on ME51N transaction, there should be another choice of selecting G/L account based on another custom field which we have added on custom data tab. The entries are maintained in custom table which is the selection method.
    To test search help , I executed the Collective search help C_SAKNR, three parameters are used, BUKRS, KTOPL, SAKNR , when I press F4 on SAKNR I can see my search coming up at the end and can select the G/L account value which we have maintained. Now when  try on ME51N screen, the additional custom search doesn't show up, the on screen field has same data element SAKNR.
    I created one structure with field SAKNR and data element SAKNR and used on custom screen, when I execute and press F4 on screen, my custom search comes up with all the std ones. Its not working on ME51n or ME21N screens, not able to figure out whats wrong.
    Please let me know your suggestions on this.
    Thanks

    Solved it myself. I appended my search help in another included collective search help .
    Thanks

  • UCSManager (v.2.0(1s)) - Locales and Remotely Authenticated Users (AD)

    Hello,
    We recently added LDAP authentication to our UCS Manager (v2.0(1s)) and the binding of roles works and users are able to login using their AD accounts.  However, I was wondering if anyone knows how to assign a locale to a remotely authenticated user.  The option seems greyed out on my end.  There are a handful of people that only need to see their single blade and we don't want them to see the rest of our servers.
    Thanks,

    No they weren't part of those groups.  I see where I went wrong: the mappings I made didn't include the locale, only the roles section.
    However, I noticed another issue.  Anyone that is in the base OU and below is allowed access to UCS Manager.  Even if they are NOT apart of a UCS mapping, they get read-only access and see everything.  Is there a way to deny all access unless a user is specifically apart of a group in AD that is mapped to a role in UCS Manager?
    Lets say I have a blade on chassis 1 slot 6.  I want a user in AD to only see and have access to that blade.  Nothing else.  Is that possible?
    Thank you in advance for any help.

  • How to use different (not local) user for NTLM auth in Authenticator?

    Hi All,
    I use custom authenticator to provide user / passwords to connect to .NET Web Services. I overloaded function getPasswordAuthentication() that returns right user / password combination for the requested URL. It all works perfectly for many kinds of HTTP connections: basic, ntlm, ntlm-v2, through proxy, ssl, etc.
    My problem is that during NTLM authentication from Windows computers JVM uses credentials of the currently logged in domain user instead of calling Authenticator to get other user / password provided by the user. In case when local user credentials fail to authenticate, JVM calls my Authenticator but in case authentication is successful it does uses local domain user and never calls my Authenticator. The issue is when this local domain user does not have enough permissions but authenticated correctly there is no way to supply JVM with another user to begin with.
    What can I do to force JVM to ignore local domain user and to use Authenticator to collect credentials during NTLM authentication requested by the server in case the software runs on a Windows box with currently logged in domain user?
    I am looking for the answer for a long time already but found only questions and suggestions to switch server from NTLM authentication which is not an option for me. From the developer's view it has to be pretty simple change for Sun to do in Java networking API. Is there any way to escalate it to Sun support? Maybe there is some property in some JRE patch level that allows to do this?
    Thank you very much!
    Mark

    Thank you for the reply. I have kind of an opposite problem. I can perfectly connect from Linux computers to Microsoft IIS servers using NTLM or even NTLMv2 authentication. My problem is connecting from Windows client computer joined to the same domain as IIS server with the domain user logged in to this computer. In this case this user account will be used in any HTTP connections I initiate to this IIS server instead of the one that I want to supply in my custom Authenticator.
    I have graphical interactive application that connects to IIS Server. When user runs it and connects to IIS server I want to prompt for the user/password regardless whether JRE may correctly authenticate using current user account credentials. The current user may not have enough permissions in IIS application so I want to use different user to login to IIS application.
    Thank you anyway,
    Mark

  • Windows 7 remote desktop connection cannot logoff the local user

    Windows 7 remote desktop connection cannot logoff the local user
    Remote Desktop connection:
    (This experience is from Windows 7 remote to Windows Embedded Standard 7 computer)
    I used Remote Desktop to try to log on to a Windows 7 (WES7E) computer and someone is already logged on locally (Console Session), I saw a message like this:
    "Another user is currently logged on to this computer.  If you continue, this user has to disconnect from this computer.  Do you want to continue?"
    I click on Yes.
    Then I saw "Please wait for [username] to respond".  No action from the logged-on local user, I waited for 30 seconds, then I was able to login the computer and at the same time was able to disconnect the logged-on local user. 
    Question:
    1. "Another user is currently logged on to this computer..." message doesn't show me the actual logged-on user name.  Is there any way to show the user name in this pop-up message?
    2. After waiting for 30 seconds, I was able to login the computer and the logged-on local user is disconnected, however this local user is never been logged-off.  I wanted to logoff the local user (with Console Session) when I made the connection remotely
    to the computer from remote desktop (Just like Windows XP)  Is there any group policy can change the behavior?
    The policies I have looked at are:
    Local Computer Policy | Computer Config | Admin Templates | Windows Components | Remote Desktop Services|Connections|Deny
    logoff of an administrator logged in to the console session => disabled
    Regards,
    Mei Davis

    Hi ,
    These behavior is by design. There is no way to change that. Thank you for your understanding.
    Best Regards.
    Tracy Cai
    TechNet Community Support

  • AAA and local user authentication

    Hi,
    I already have AAA authentication setup on my switch. And I can use local users to login when the AAA server is unreachable.
    But I want to know if it is possible to use local users even when the AAA server is reachable. Something like first it checks the local users databse and if the user does not exists then fallback to AAA or vice versa.
    Thanks.

    Ismail, the authentication method you define act as a service. So only when the service is not avilable the method fallback to the next methond you define.
    So in your case if the user account is not present in the local data base it will not fallback to aaa server.
    aaa authentication login default local group radius
    The same holds true if the user account is not there in the aaa server
    aaa authentication login default group radius local
    Only when the aaa server is not responding (service downe or not reachable) it will fallback to the local database.
    Hope this helps!

  • How to create custom search box will allow up to 60 alphanumericcharacters & User can input a minimum of 1 character and the system will pull back an exact match on the sequence entered.

    Hi,
    Can anyone please help me in creating the Custom Search box with below mentioned functionality
    "The search box will allow up to 60 alphanumeric characters.User can input a minimum of 1 character and the system will pull back an exact match on the sequence entered"

    Hi Pradeep,
    Find the complete JQuery AutoComplete function with along with different events in it like focus, select, open and close. You can modify this code as per your requirement.
    $("#ddlSearchTextBox").autocomplete({
    source: function (request, response) {
    var getUrl = "<site URL>";
    $.ajax({
    url: getUrl,
    type: "GET",
    contentType: "application/json; charset=utf-8",
    dataType: "json",
    data: {
    featureClass: "P",
    style: "full",
    maxRows: 10
    dataFilter: function (data, type) {
    return data.replace(/\\'/g, "'");
    success: function (data) {
    response($.map(data.d, function (result) {
    return {
    label: result.Last_Name + ", " + result.First_Name,
    value: result.id
    focus: function (event, ui) {
    $("#ddlSearchTextBox").val(ui.item.label);
    return false;
    minLength: 1,
    select: function (event, ui) {
    $("#ddlSearchTextBox").val(ui.item.label);
    return false;
    open: function () {
    $("#ddlSearchTextBox").removeClass("ui-corner-all").addClass("ui-corner-top");
    close: function () {
    $("#ddlSearchTextBox").removeClass("ui-corner-top").addClass("ui-corner-all");
    Let us know if you need any further.
    Thanks, Shakir | Please 'propose as answer' if it helped you, also 'vote helpful' if you like this reply.

  • Search for [Remote Key] and [Remote System] in Data Manager

    Hello all
    I would like to be able to search on the remote key and the remote system in the MDM Data Manager is that not possible? I thought I remembered seeing that possibility under the Free-Form Search but now I can't find it.
    I have, however, found this in the Data Manager reference guide:
    REMOTE SYSTEM AND REMOTE KEY FIELDS
    MDM uses the remote systems defined in the Remote Systems table
    within the MDM Console to store and maintain key mapping information
    for each record or text attribute. It does this using a virtual “key
    mapping” field that you never see in the MDM Client.
    This virtual key mapping field is very much like a qualified lookup field
    into a virtual key mapping qualified lookup table.
    Key Mapping information stored in virtual lookup field
    The Remote System and Remote Key fields are normally not visible;
    however, they do appear in several places in the MDM Client.
    Specifically, both fields: (1) appear in the File > Export dialogs in Record
    mode for exporting value pairs; (2) are recognized by the File > Import
    dialog in Record mode for importing value pairs; and (3) appear in the
    Edit Key Mappings dialogs in both Record mode and Taxonomy mode,
    for viewing and editing value pairs.
    Is there any way to search on the value in the remote key from the Data Manager?

    Not sure search i think not possible.
    But you can see keys as mentioned:
    Enable Key mapping in Console.
    MDM Client maens MDM Data Manager.
    They do appear in several places in the MDM Client or Data Manager. Three different methods to see in DM are given already below:
    Specifically, both fields: (1) appear in the File > Export dialogs in Record mode for exporting value pairs; (2) are recognized by the File > Import dialog in Record mode for importing value pairs; and (3) appear in the Edit Key Mappings dialogs in both Record mode and Taxonomy mode, for viewing and editing value pairs.
    BR,
    Alok

  • Remote Access VPN Users with CX Active Authentication.

    I have ASA 5515 with CX for webfiltering , also have enabled remote access vpn . All my inside users are able to get active and passive authentication correctly . But for remote access VPN users , they are redirected to ASA external ip and CX authentication port 9000 but a blank page comes in and there is no prompt for authentication. I wasnt doing split tunneling , but now i have excluded ASA WAN ip from the tunnel and still have the same issue.
    The CX version we have is 9.3.1.1

    Have you excluded the VPN traffic from being NATed when traffic is going between clients?
    Please post a full sanitised configuration of the router so we can check it for configuration issues.
    Please remember to select a correct answer and rate helpful posts

Maybe you are looking for

  • Payment term not appearing in PO print out

    Hello all, We have one PO where Payment term is not appearing in PO print out. I have checked other POs of the same type where its appearing in print out. In PO header payment term is maintained. Does this flow from Vendor mastre? Regards

  • I have 2 tab panels on my website and 1 is not working

    I have 2 tab panels on my website and 1 is not working one on a templet so it shows on all pages and one for some of the pages when I upload it to my server it brakes the ones on the pages  heres an exaple http://ol.helpmetechteam.com this is main pa

  • Switching computers my ipod is connected to

    When setting up my ipod a couple years ago i set it up to my laptop. Well my laptop is still working but something is wrong with the internet connection and i cannot access itunes store to download songs anymore. I would like to connect my ipod to a

  • Reconciliation Key

    Hi Friends How system generate Reconciliation while doing diffrent types of transactions ex Payment lot Account maintenance etc Regards Srinivas

  • Oracle Backup Misbehavior

    Hello, iam running into a strange problem while doing a backup via Oracle Enterprise Tool under Oracle 11g: 1. Login: sys as sydba 2. Backup Setting are on "Image Copy" 2.1 Keep most generally default settings 2.2 Test Disk Backup successfully 3. Sch